Live data from Hacker News

Oxford Temporarily Blocks Google Docs

blogs.oucs.ox.ac.uk

101–110 of 160 posts

Re: Oxford Temporarily Blocks Google Docs

#101
post #87

Earlier quoted context omitted.

Oxford already has rate limiting. 1000 messages per hour through their servers, it seems [0]. The next step would be to filter outbound traffic to block SMTP from compromised PCs. It seems they have an outbound firewall, but it's not obvious which ports are closed because the list of blocked ports is ... blocked[1]. [0] http://blogs.oucs.ox.ac.uk/adamweblearn/2011/12/weblearn-una... [1] http://www.oucs.ox.ac.uk/netwo…

The 1000 limit seems like a high number, why would a legit user need to send that much email out? I'd think a much smaller number like 5 per hour would be better.

5 per hour

You're a lecturer with 200 people in your class. That's 2 days. Does the lecturer have to leave their computer all the time? Is their email programme going to handle this sort of delay? What do you do if the lecturer wants to send an email about updated homework due in a few days? Some students will have a 2 day head start, is that fair? Do you have to give them extra time/marks?

You're the first year faculty advisor. There are 1,000 people in that year. That's 1 week. Same questions as above.

(And in case you think "Well let the lecturers send more", what makes you think the lecturers aren't the problem in the first place?)

Re: Oxford Temporarily Blocks Google Docs

#102

Earlier quoted context omitted.

No, their reasoning is that the continuous phishing attacks caused unacceptable trouble with their email system (e.g., Hotmail dropping all emails coming from Oxford). Due to extensive international collaborations, keeping a universities email system running is probably one of the most important tasks of the IT team. Google Docs is nice and useful, but nowhere near as important. Given that they, practically speaking,…

"no alternative way of dealing with the phishing attacks effectively" How about not using passwords? All students, staff, and faculty should have ID cards; start issuing smartcards, and start using cryptographic techniques to authenticate users. Also, digitally sign all official mail, and instruct the users to check those signatures. These are not insurmountable problems. The real issue is that the IT team is not wil…

instruct the users to check those signatures.

People fall for 419 phishing scams. What makes you think they are able to check for digital signatures.

Re: Oxford Temporarily Blocks Google Docs

#103
post #6

It's the perfect example of why security teams are often considered to be the least friendly, least approachable part of an already unapproachable department (IT). Their reasoning seems to be "Google Docs causes us (the security team) hassle, we don't use Google Docs, so we'll shut it down". They might as well of shut down the whole of the Internet, for all their nonsensical reasoning, except they'd of been affected…

No, their reasoning is that the continuous phishing attacks caused unacceptable trouble with their email system (e.g., Hotmail dropping all emails coming from Oxford). Due to extensive international collaborations, keeping a universities email system running is probably one of the most important tasks of the IT team. Google Docs is nice and useful, but nowhere near as important. Given that they, practically speaking,…

(e.g., Hotmail dropping all emails coming from Oxford)

This can be a problem for universities in specific ways. Students get emailed some change to course work, all students using hotmail don't get the email, students then have a case to appeal the (possibly) worse mark they received.

Re: Oxford Temporarily Blocks Google Docs

#104
post #97

I feel for them. I attend an IT-focused university that has both hardcore techies (computer science and such) but also a lot of non-techies (communication, UI design, etc.) We frequently (at least once per month) get a phishing e-mail asking us to reply or click a link and provide our credentials. For anyone who has attended the university more than 6 months, there will have been at least 3 e-mails from the IT-depart…

I've had 4 emails in the past month providing information about the phishing emails from my department, JCR and IT services, and despite that a number of accounts still got compromised.

Couldn't agree more about education never actually fixing the problem.

Re: Oxford Temporarily Blocks Google Docs

#105
post #79
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

Oooooooooooooooo rant coming on............. Im sorry, but that is the typical tech reply that blows normal people's minds. Blame the user. Well, the user says, sod that, lets just block the problem and get on with what we wanted to do in the first place. People, normal non tech people, want to use computers as a tool, not become experts in thwarting criminals, etc. If a user cant just go to a computer and simply use…

yes, normal people don't care about the tech details and don't want/need to be experts to handle technology. but it is responsibility of the tech experts to make that possibility.

that's the hardest nut and that's the income comes. blocking some sources is simply easy. " We found Google Docs brings more and more phishing, OK let's just block it and sorry and apologize to our users." " We found again zoho brings more and more phishing, Ok let's block it too." Well, we will find more like this situation.

Oh, it's scary! Let's just block the internet and turn on our TV...

Re: Oxford Temporarily Blocks Google Docs

#106

Earlier quoted context omitted.

"phish your own users" Now that's the best idea I've heard all morning. You should be running Oxford's IT dept!

I disagree. At best the users who don't care will continue not to care. At worst it will train users to think "oh, it's another drill, ho hum". Somewhere in the middle is some deeply embarrassed Deputy Vice Chancellor who decides to make those horrid computer people his personal enemies.

> At worst it will train users to think "oh, it's another drill, ho hum".

How is that a bad outcome? Whether they think it's phishing or a drill, the important thing is that they don't enter their credentials.

Re: Oxford Temporarily Blocks Google Docs

#107
post #80

Earlier quoted context omitted.

unfortunately most of the University runs on Microsoft Exchange I believe, and they do not support 2-factor authentication.

Maybe you should do some more reading. There are certainly supported configurations for two factor authentication.

oh yes of course they can set-up 2-factor authentication themselves, but it's not supported ''out-of-the-box'' is it?

This is what I mean: http://www.neowin.net/news/microsoft-explains-why-outlookcom...

With Google Apps you just turn it on... and can force users to use it.

Re: Oxford Temporarily Blocks Google Docs

#108
post #79
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

Oooooooooooooooo rant coming on............. Im sorry, but that is the typical tech reply that blows normal people's minds. Blame the user. Well, the user says, sod that, lets just block the problem and get on with what we wanted to do in the first place. People, normal non tech people, want to use computers as a tool, not become experts in thwarting criminals, etc. If a user cant just go to a computer and simply use…

> "train the users" is for me a 30 year mantra that no one out side of geekdom wants to hear

Perhaps a better approach to "training the users" might be for the University to actively attempt to phish its own users on a regular basis.

Those who fall for the phishing could be contacted directly, or have email access limited for some period of time (for example, a reduced sending rate limit).

Making self-phishing a regular occurrence (say, weekly) would train users to recognise and ignore it.

Re: Oxford Temporarily Blocks Google Docs

#109
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

> Train your users where it is and isn't safe to enter credentials. This demonstrably doesn't work. It reduces but cannot eliminate all instances of phishing. > Don't give your users credentials. Have some alternate way to authenticate them like a login token. Better, but scrounging up a few million pounds for dongles, plus the non-stop cost and effort of replacing lost and stolen dongles, is not easy for a universit…

Verisign "dongles" can come on smartphones of all types, and on many operating systems. I even believe they have browser plugins, meaning even linux would be supported. That is, if you think two-factor is necessary for university systems.

As far as email, there are several things to consider: One, that I would think it a rarity for a student, or even a teacher! to need to send a single email to more than a handful of /external/ email addresses at a time. Put an email firewall in place between your internal and external systems, and have IT security monitor that system for peaks in traffic. Single users sending outbound mail a lot. Obviously, there should be a spam filter going in AND out.

And yes, spam email does trickle in sometimes, and from different SMTP servers, but from the bit I've dealt with them, there are definite patterns that a person can pick up on when they're watching for it.

Re: Oxford Temporarily Blocks Google Docs

#110
post #84
post #79

Earlier quoted context omitted.

Oooooooooooooooo rant coming on............. Im sorry, but that is the typical tech reply that blows normal people's minds. Blame the user. Well, the user says, sod that, lets just block the problem and get on with what we wanted to do in the first place. People, normal non tech people, want to use computers as a tool, not become experts in thwarting criminals, etc. If a user cant just go to a computer and simply use…

I'd like to use my car like a tool. Why do manufacturers make them so difficult to safely operate, I shouldn't require any additional training to operate it, I should be able to just hop in at location A and hop out at location B. Regardless of what some folks in the "User Friendly" movement would like to think, most tools require basic instruction in order to be safely used. We can't code away all individual respons…

Spotting a phishing form only seems like "basic instruction" to you because you're highly computer-literate. It's not; it involves understanding at least some of DNS and the difference between hosts, domains and TLDs, URLs, HTTPS, and not to mention certificates and their validity.

In your analogy, it's like saying "people shouldn't be allowed to use cars unless they can verify the hydraulic pressure in the master brake cylinder"

Which is wrong: manufacturers should (and did) install brakes warning lights. And we need to come up with better warnings for users. Blaming them for these sorts of problems is unacceptable.

Post reply on HN