psynegy
Members-
Posts
132 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by psynegy
-
You should be able to see in event viewer what is triggering the restart... Look for event ID 1074 from User32 in the System log. You could provide a shortcut to "shutdown /a" on the desktop as a very quick temporary workaround. Users would have to open the shortcut once the shutdown message appears.
-
Probably been blacklisted...... 👀 I think you have to press # after the site ID and again after contact PIN... Why? Nobody knows....
-
Two Way Radios/Walkie Talkies - Encryption
psynegy replied to psynegy's topic in Data Protection & Information Handling
It doesn’t matter what certificate you use if the encryption is prevented from being implemented properly… Have a read of the thread; it’s quite interesting. Goes above my head somewhat, but my understanding is that without the initialisation vector being randomised, any repeating patterns make it surprisingly easy to decrypt without the key. But this particular issue was magically fixed in a later firmware version. I’m also not saying this is just a China problem, I’m sure there are plenty of accidental (or not so accidental) flaws in many systems we rely on. I’m very aware that some CCTV manufacturers can generate password reset codes for their devices as they please… So we take precautions and firewall them off. Not so easy when it comes to a device that can receive a radio signal from miles away..! -
Two Way Radios/Walkie Talkies - Encryption
psynegy replied to psynegy's topic in Data Protection & Information Handling
Happily, we are already licenced as required! Those radios are indeed a tempting proposition compared to a similarly spec'd R7 at less than 1/10th the price! (R7 FKP Premium: £540 + Charger £40 + AES256 £200 = £780) However, whilst it looks like there haven't been any more recent "discoveries", the not so distant past is worrisome. -
Two Way Radios/Walkie Talkies - Encryption
psynegy replied to psynegy's topic in Data Protection & Information Handling
I didn't know you worked here... Putting that straight in the policy - verbatim. -
Two Way Radios/Walkie Talkies - Encryption
psynegy replied to psynegy's topic in Data Protection & Information Handling
They're very cute looking! Looks like a base unit is around £200 and the only price I can find for the AES-256 licence is €177. Nearly doubles the price! Still cheaper than Motorola... Sorry... No comment. -
Two Way Radios/Walkie Talkies - Encryption
psynegy replied to psynegy's topic in Data Protection & Information Handling
I'm pleased to see that I'm not just overthinking this. I think I realised I wasn't getting great advice from this two-way radio sales person when they told me that instead of AES-256, we should instead get a private frequency from Ofcom, because, you know, that's more private... Impenetrable I tell you! They even went so far as to tell me that "plenty of schools that use these radios are more than meet their privacy requirements"... Speaking of which... anyone know any good radio suppliers..? 👀 WiFi devices sound great in theory, but our site makes it... impractical... see my thread asking about solar powered WiFi AP's 🙃 -
Looking at a new two-way radio solution and the options for encryption. It is inevitable that even if we say "don't transmit any identifiable information on the radios", it will happen. There will be some emergency, or someone forgets, or it gets decided that actually, they'd very much like to be able to say names and PID over the radio. So I've been asked to look into encryption for this new suite of radios. Currently looking at Motorola R2's and R5's. They offer 8-bit (XOR), 40-bit (RC4) and for an extra unknown amount of money (around £200~) the R5's will do AES-256. Ruling out the 8-bit "encryption" straight away... RC4 has been considered "broken" for well over 10 years now. Am I right in thinking that schools are therefore required to have AES-256 encrypted radios if they should ever want to utter the name of a student?
-
Thank you for responding Anthony, it's very much appreciated. Yes, we've been told this, but have also been told that it's not supported by Paxton and can cause issues with detecting new hardware. Running a Windows VM in Azure also has fairly significant overhead and therefore cost associated with it. According to your Net2 compatibility table, it looks like it's not recommended for any users to be using a higher version than 6.7 SR3? For Server 2022 you only recommended to use 6.6 SR1 (3+ years old), but Windows 8.1 should use 6.7 SR3?? No support for Server 2025 at all? It's been out for over a year now... Yes, that's very useful indeed, and we use the API ourselves to achieve things that are not built into the product. API access would be a key feature of any system we would look to implement. Personally, I don't agree that the most recent update being 6 months ago lends any credence to the software being updated regularly... Similarly, I reported a bug in 2023 which was acknowledged, and despite multiple (ignored) follow up emails, the bug is still present today. To be honest, we didn't really see what the purpose of Paxton10 was as a product. I think when we started with Net2, P10 was still quite limited, I'm sure it's probably come a long way since, but it didn't make sense to us. I think it's caused a lot of people concern that all their Net2 gear is going to become obsolete, especially with no (apparent) upgrade path from one to the other. Honestly, if you we were going to replace each reader with a third party solution that we'd have to manage separately - replacing the access control unit at the same time (so at least it's all in one system) makes more sense to me. I also imagine the BLE device would still just be stored with an 8 digit number in the database? So was asbestos and RAAC - now look where we are! Reader 2FA isn't what I would call a solution at all... Slow, cumbersome, requires reader replacements, more for users to remember... Anti pass-back isn't helpful here either unless the person's card they've cloned happens to be walking in behind them, and also adds reliance on server availability. HID SEOS requires replacing all readers and cards, and even then doesn't work with your intercoms/handles without falling back to UID. What's also really concerning is that there doesn't seem to be any rate limiting on the controllers or readers for trying new cards... I was easily able to emulate 3x cards per second on a P50 reader for several minutes... Granted, that's still around 9 hours if you assume 1000 tokens in the database giving you a 1 in 10k chance per random UID, but I bet with some refinement (like UID generation based on known cards, or attacking multiple readers at once, or possibly just speeding up the rate of attempts), that could be made quicker. "but no student is going to try this" - well, I'm here to tell you they will, and they have, and we've seen it. Being able to apply a rate limit would improve the situation immensely. Net2 encrypted tokens (Hitag2) would certainly also be an improvement, but they too will likely be as easy to clone in a year or two as Mifare is today. How to copy, read and write Paxton fobs and cards with an RFIDler | Badcfe.org - Some info on Paxton RFID tags Question - when using the Hitag2 tokens - can you prevent Mifare or EM tokens from being read? If not, the system is still just as vulnerable to brute forcing. Couldn't see an option for this - only HID+Wiegand activation seems to block them, but that also blocks the Paxton Hitag2 tokens... It could not be easier to clone a MiFare UID. A student with a Flipper Zero in their pocket can do this in seconds. I agree that there are other issues with security, and we take those seriously too, we have alarms that sound when a door is propped open too long for example, but just saying 'there are other holes' in a sinking ship doesn't mean we shouldn't try and block up any of the holes... Granted, no access control system is going to fix security culture - but it could fix this problem. It's not even just that the cost is high - it's how hard is is to get hold of the equipment. Most, if not all of the official resellers won't deal with end users, and if we do manage to buy the kit from a "naughty" reseller, then Paxton says "no warranty for you!". Going through this reseller model also means the idea of any education discount tends to go out the window. I assume the free training (and therefore warranty entitlement) doesn't extend to school IT staff based on the "specifically for installation engineers" and for on-site training: "Training is offered to professional security installation companies currently, or wishing to begin, providing Paxton equipment or services as part of their portfolio." terms, but I'd be very happy to be told otherwise!
-
We have a number of Paxton Net2 controllers, but are about to embark on replacing nearly 20 old standalone access controlled doors, so we want to make sure we're doing the right thing sticking with Net2. Net2 doesn't seem to have any prospect of becoming cloud hosted, the existence of Paxton10 confirms that. I fear that Net2 will become legacy once P10 reaches maturity. I know some people would prefer to keep things on-site - that's just not the direction we're heading at the moment. I also have serious reservations about the security of Net2's use of MiFare UIDs as a means of identification - we've already had ID collisions and a kid with a Flipper Zero is probably not going to need long to clone a staff card or fuzz their way through a door. Don't even get me started on how bad the PoE implementation seems to be on the Net2 controllers... I've been doing a bit of looking into the UniFi option - which whilst it relies on a "cloud gateway" - we'd have to have some sort of router on site anyway, it might as well do that too. If it means we can unify (ha-ha) our WiFi and network authentication too, that's a plus. It would also give staff the option to use other devices for opening doors, where Net2 (pre P10) does not support BLE. Cost wise, BroadbandBuyer puts a UniFi Mini Door hub at ~£85 and a reader at ~£83 (£100 for the newer model). Last I saw a Net2 PoE Controller and reader were £300 and £90 respectively... I believe the intercoms are circa 10x cheaper also, though do not look as "rugged" - as we've found with our Net2 intercoms - nothing is "vandal proof". I suspect we would find it hard to find an installer for Unifi, how necessary that is - I'm not sure. Interested to hear peoples thoughts and experiences with other products!
-
Bromcom have said they have identified an issue with SSO logins. It does seem to be working better here now. I'm sure any moment now, they'll update their status page. Any. Moment. Now...
-
Is it just us having problems logging into Bromcom this morning? Support seemed unaware... Status page says nothing...
-
Smoothwall - Maiden, update 33 hard lock
psynegy replied to robintech's topic in Internet Related/Filtering/Firewall
Not seen this here. -
Starlink is definitely a consideration, and I imagine more likely to come "pre-packaged" like this... interesting indeed... Very power hungry though - I think 80-100W just for the dish... Seems like it could be challenging from a pole mounted array... Sadly not... We do some business with them, but it would be quite a thing to get an AP installed on the outside of the building connected back to our network... Though maybe it doesn't need to be back to our network if it's internet access only... Hmm...
-
The 5G signal isn’t brilliant at ground level, I would want to put a decent directional antenna up high which should get us “over the hump” as it were… I think we have around 10 PE staff that would be using it…
-
We need to provide WiFi to our PE staff out on our playing fields, but... We have a strange site... Our playing fields are separated from the main school by a massive concrete building - and our playing fields can't be trenched because they're home to a roman mosaic... Which leaves us with not a lot of options for getting WiFi out there! I think we're probably going to have to install a pole mounted solar panel and battery with a WiFi AP and 5G modem. Has anyone ever done something similar? What or who did you use? How has it behaved since installation? I'm very open to other suggestions - unfortunately there's no line of sight to our buildings, so I think 5G is going to be our only way to get connectivity there without having Openreach drop a line (which is potentially possible). The SunMax product from Ubiquiti looks quite appealing, but they don't seem to be available anywhere. Just had thought that it'll probably need planning permission! Sigh...
-
We too are struggling here with it intermittently throwing errors or not loading.
-
Did anyone find out about the SLA? I will do a little write up on this once I've got it figured out! I think the best way to do this I've found so far is to set up a scheduled "Blank Register" report for each period separately (so you have a separate file per period). You will note that the blank registers don't have the room on them, so I'm just trying to find a report that maps classes to rooms. Might end up being easier to do a custom report for the whole thing... We'll see!
-
InTune/Entra login issues
psynegy replied to MatthewShaw's topic in Internet Related/Filtering/Firewall
This. We’ve had a similar issue with an ISP before having a badly configured MTU somewhere along the lines. Run lots of MTU tests, bet that’s where your issue is! Hopefully yours is resolved faster than ours. Ours was many, many months before they believed us enough to actually look into it. Oh boy did we ever get a big apology… -
Well of course! You wouldn't want to accidentally (accurately) report downtime when you can just pretend it didn't happen if you fix it fast enough...
-
Interesting to note that the partner API is still fully operational with access to school data... That would imply to me that the database is online...
-
We were looking at a schedule to send the days registers to an email address each morning as a failsafe. Naturally there was an issue setting that up, but I believe they said they resolved that - so I should try again...
-
InTune/Entra login issues
psynegy replied to MatthewShaw's topic in Internet Related/Filtering/Firewall
You're running on-prem Smoothwall filtering instead of using the Smoothwall Cloud browser extension? If you're using the extension, then the devices shouldn't really be filtered by your Smoothwall box (double filtering). Assuming that you're just using the extension, there wouldn't be much to blame on Smoothwall if there's no filtering happening outside of the browser... As kierans said, taking a device out of the Smoothwall network will be an easy way to check for it's involvement (assuming no DirectAccess or similar VPN involvement!) -
Very similar configuration to what we had. We've downsized somewhat, but it seems you've still got a lot of on-prem with 22 VM's... We were basically forced to replace our kit as it was out of the 5 year warranty, which we even extended by an additional year. Our solution was to buy a single node capable of running our now much reduced VM load - which only really has a couple of "critical" systems on it. We decided to keep one of the old servers alive as a Hyper-V replica, and the 2nd just for spares. Personally, my idea was to keep S2D running on the two old nodes, and have the new server as the replica, but I was overruled. Technically we've lost HA, but it's still pretty close. I'd look to see what VM's you can whittle down or at least are planning to in the not so distant future, to see if you can make any savings there before making purchasing decisions. It seems inevitable that things are going to continue moving cloudwards, at least for the near future.
-
What’s the biggest barrier to upgrading switches/networking?
psynegy replied to TP-Link_Gary's topic in Wired Networks
I wish that was our experience. We've had more problems with the switches that are brand new and 4x the cost. Had a good few dead ports on our 2930F's for sure. Say what you will for those old Netgear switches, but I think we've only RMA'd 1 in 15 years... Lifetime warranty too, so, I think when we did do that, they sent us out a far newer model as the returnee was no longer available. Not many manufacturers doing lifetime warranty any more, eh...? Not a mistake you make twice... 👀 It's not even that I don't think, it's just that unless you're lucky enough to have 1-2-1 for staff and students, the requirement for multi-gig is currently pretty negligible at the edge, so the actual real-world benefit to end users is practically nothing.
