Posts

Showing posts with the label Security

Understanding Security settings in Google Meet

Image
Google Meet has undergone a number of changes recently to the way video calls can be made more secure for teachers and students. This video is a thorough guide to making sure your Meets are as safe as possible, by explaining everything you need to know, from the necessary admin-level settings, to the in-call settings like Host Controls and Quick Access settings. It goes into a fair bit of detail, including the important changes that need to be made in the admin console in order for the other settings to be effective.

The 3 - 2 - 1 Principle for keeping your data safe

Image
I was cleaning out a drawer in my home office this morning and found this collection of old USB memory sticks dating back quite a few years. Remember those days when you thought you were so cool because you had this little storage drive full of all your stuff in your pocket? I recall working in a school back in those days where we actually mandated that every student had to have a "USB"*, such was the apparent importance of these things. The intention was for students to keep their personal data safe and secure, but we used to constantly find them left behind in the USB ports of the classroom computers after a lesson. Or they would sometimes mysteriously just stop working. Or the kids would lose them. USBs may have been cool, portable and handy, but they were about the most insecure method for managing data I can think of. *(Side note: Calling them simply a "USB" seems stupid to me, because USB - or Universal Serial Bus - is a data interface standard, not a name fo...

Something you know, Something you have

I read an article today in an educational newsletter about keeping your accounts safe with a strong password.  It suggested a range of sensible things like having at least 8 characters, using a mix of uppercase, lowercase, numbers and special characters, and not reusing old passwords.  All pretty good advice. I hear a lot of people expressing concern about the security of "the cloud".  They worry that their data could be compromised if kept on a server they don't own themselves, or a server that is located somewhere else, possibly even in another country.  They express concerns about data breaches from hackers, security breaches of data centres, or even data being accessed by foreign powers during a government uprising. Is any of this possible?  I suppose so. Anything is possible. Unlikely perhaps, but possible. If it's true that anything is possible, and we want our data to have zero risk, then we need to not keep data anywhere. The only sure way to have no ris...

Should I Trust The Cloud?

I received an email recently from a colleague asking about data sovereignty, and in particular asking about how schools deal with the  need to store all personal data on Australian servers to be compliant with the law. This was my reply... When deciding whether to do a thing - any thing - you need to assess the relative risk. There is NOTHING that can have it's risk mitigated to zero. So while we can have debates about the security of the cloud, the fact is that ANY service is generally only as safe as the password that protects it. It's far simpler to socially engineer your way into a system than to hack it, and it's easier to follow someone through an open doorway before the door shuts than to crack the lock. There are security risks involved with every system. What makes you think that data saved on a server that happens to be geographically located on Australian soil is any safer than data on a server located on the other side of some imaginary geographical dividing l...

Getting out of Password Hell

A while ago I realised that my online life was in password hell. I was using literally hundreds of sites and services that required passwords, but they were held together with a confusing mess of old passwords that I'd mostly forgotten, numerous passwords which were being used on more than one site,  passwords that didn't meet the usual complexity rules usually required across the Internet, and so on. I often found myself having to do a password reset just to access a site, and of course that new password became yet another one I had to remember. Or forget. I felt things were a little bit out of hand so I finally took a few steps to clean up my digital life. First, using the same password for everything is an exceptionally stupid idea. Instead, I came up with my own system that helped me create hard-to-guess, but easy-to-remember passwords that I could apply to any site.  Having a clear system for this meant that when I signed up for some new online service I could quickly come...

In Second Factor We Trust

You hear of so many security compromises and hacks these days. There are major security breaches happening, with millions of passwords being stolen and used to steal or damage your stuff. So what can you do about it? With so much of our lives now being lived in online spaces, losing a password, losing an account, having someone get into your stuff online,  would be a nightmare. What would happen if someone got into your Google account? Your Facebook? Your bank account? I lost my original Twitter account (betchaboy) last year after a password breach and have never been able to get it back. These security breaches DO happen. The best thing you can do to protect yourself is to turn on Two Factor authentication. Sounds complicated? Its not. It basically means that there are two passwords required to get into your account instead of the usual one... there is the normal password that you usually use, plus a second one that changes every 30 seconds or so. Even if the bad guys were to get your...

In None We Trust

I wonder how many teachers would be prepared to gather all their students together at a school assembly sometime and say the following to them ... "Look, we just need you all to know that we do NOT trust you. We've talked about it, and we think that given the opportunity, you will all get up to no good and make poor decisions. Because of this, we plan to closely monitor your every move and to make sure that you don't get away with anything, ever. We plan to prevent you from doing common tasks that are probably perfectly fine and safe. However, since we are, after all, assuming that you won't be able to make your own good decisions about those things, we have taken the liberty of making those decisions for you. Essentially, we think you are all a bunch of thieves, cheats and liars with no sense of morals or ethics, and you probably spend all your time looking at pornography anyway. We have no intentions of assuming anything other than the worst... as I said, we real...

Dirty Rotten Scoundrels

Image
If there's one thing I hate it's when people assume I'm an idiot and try to rip me off. So when I got home today I opened the mailbox (yes, the real one!) to find this letter from a company called the Domain Renewal Group .  Their letter - which looked very much like an invoice -  was addressed to me as the owner of the domain betchablog.com and kindly informed me that this domain was due for renewal soon and that I should pay this as soon as possible.  The wording on the letter said that " the domain name registration is due to expire in the next few months "... and that... " Failure to renew your domain name by the expiration date may result in a loss of your online identity ." All of that is true.  Betchablog.com IS coming up for renewal, and I DO need to renew it. The problem is that Domain Renewal Group are NOT my domain registrar, and they never have been.  I happen to have all of my various domains registered with GoDaddy , and I've never eve...

A Policy of Trust and Respect

I'm a huge believer in the notion of trust and respect as the primary drivers in the relationship between student and teacher. People have occasionally told me that I'm just incredibly naive about this, but all I can talk from is my own experience, and in my own experience, building relationships of trust, respect and genuine care between student and teacher is the foundation upon which all "policy" rests on in my  classroom. I realise that school administrators will feel a need for something a little more concrete than this, but any policies, AUPs or guidelines that aren't based on this first rule are  simply not sustainable in my view. Take blocking and filtering for example. While school boards have the best of intentions for protecting students when they block access to web 2.0 tools and other social technologies, such policies fail the trust and respect test, because they start with an assumption that bestows upon the students neither trust nor respect. Or wh...

No Clean Feed!

Image
I spent today, pretty much by accident, at a forum-style discussion of the issues surrounding the Australian government's proposal to filter the Internet access of all Australian citizens .  I say "by accident" because the invitation to attend an " Internet Filtering and Censorship Forum " appeared in my email a couple of weeks ago, and without reading it too carefully, I thought it was going to be an educationally focused discussion about the filtering issues that schools face.  That would have been useful and interesting, but I didn't realise that the discussion would actually be centred on the bigger issue of the Australian government's proposed Internet filtering scheme.  I'm glad I went. Look, there is no argument from me that we need to keep our children safe online.  We absolutely need to protect them from the things that are clearly inappropriate, obscene or undesirable.  I remember the first time I realised my son had seen things online that...

Building my Wild Self

Image
Having taught high school for basically all of my teaching career, I've just started working with the little kids in a R-12 school. (The R stands for Reception, and is the grade before Kindergarten) It's great working with the littlies, they are so cute! I team taught with another teacher today for the Grade 2 computer lesson and although they only did some pretty basic word processing stuff today I was impressed with just how capable some of these young students are with technology. I even had one of the students, a delightful young lady all of about seven years old, solve a password problem that had me, the teacher and the IT Director stumped. She remembered the login name and an arcane 6 character password which had not been used since before the Christmas holidays - about seven weeks ago. Pretty clever I thought. (Don't even get me started on why our kinder age kids are required to have a strong, secure password that changes every 90 days... they play Kidpix and...

The Road Less Travelled

Image
On one of the several mailing lists I subscribe to, I saw a question from a network manager in another school asking for advice in dealing with some mistreatment of computer equipment by students. His proposed solution was to install webcams in the computer rooms and to stream their output to a server where it could be recorder and monitored. This person was asking for suggestions or advice from anyone else who had gone down this path. It's not a path I particularly like... I don't mean for this reply to become a lengthy diatribe (or worse yet, a cranky rant), but I think this approach is totally going down the wrong path and it's something I feel strongly about. I see many in school IT management who seem to be taking the path of constant surveillance and security over the harder-to-do but better-in-the-long-run approach of teaching students appropriate behaviour with technology in the first place. I see it happening with the way school lockdown their computers with com...