Live data from Hacker News

Oxford Temporarily Blocks Google Docs

blogs.oucs.ox.ac.uk

111–120 of 160 posts

Re: Oxford Temporarily Blocks Google Docs

#111
post #96

User education is not the way to solve these sorts of problems. The proper way to solve the problem is through automation -- use of a "forcing function." An example of a forcing function is not allowing an automobile driver to shift into reverse until the they have their foot on the brake pedal. This is a far superior solution to educating drivers to not shift into reverse until they have their foot on the brake peda…

Can you give an example of how it would work? (online for forms, not offline/IRL)

I haven't thought about it at all as to how Google would fix their problem. Still, they've introduced a component into the Internet ecosystem that has been found to be abusable and they are accountable to install the forcing functions to prevent that abuse. To depend upon user education is simply irresponsible.

The idea of forcing functions is well known in organizational/system theory.

Another way to think about this is the recent notices that Java (and at other times Adobe Flash) has recently introduced a security flaw where people using their computer can have it hacked into (Apple suggests removing Java unless you really need it).

Just as we would expect Java/Oracle and Adobe/Flash to fix their security flaws so should Google fix theirs.

Re: Oxford Temporarily Blocks Google Docs

#112

I currently work for the web communications part of a small-to-medium size university. We have around 2000 employees and 8000 students. We embrace all google products on campus. We actually use gmail for our primary email system. We use google forms to collect data throughout our website (not perfect by a long shot, but makes data collection approachable and accessible to end users). We would never shut down google f…

> Our solution is simple. If you want to send out an email to everyone, send it to a central authority that can approve the sending. It sounds like all you are doing is regulating access to some sort of all@university mailing list. How does this solve the much bigger problem of spammers using compromised accounts to spam Gmail/Hotmail addresses, which then end up getting the university blocked? And even ignoring that…

You are mostly correct. We are primarily regulating access to a all@university mailing list, but we also have restrictions that prevent mass emails being sent via gmail (though I'm not the authority on this). You are correct, nothing prevents a compromised account, that I know of, from sending out emails one at a time to an list of users, though we do have control over all email accounts and can disable a compromised accounts. If the traffic is internal we have other ways of preventing it. I'm not saying our solution is an absolute substitute for all combinations of possibilities. Just that if we were to be blocked we'd have to deal with it in some other way then to disable google forms. We just couldn't get away with it, and according to some of the comments, Oxford couldn't get away with it very long either.

Re: Oxford Temporarily Blocks Google Docs

#114
Sometimes I wonder what the world would be like if it were illegal for institutions to block sites. It shouldn't be too hard to imagine. No one can block postal mail or telephone calls (except as a user). And, the FCC has banned wireless jamming. In spite of those guarantees of service we manage to survive and, on the whole, protect ourselves from fraudsters.

I think it is too late now to guarantee service through legislation, but the upsides do outweigh the downsides.

Re: Oxford Temporarily Blocks Google Docs

#115
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

"We recently felt it necessary to take, temporarily, extreme action for the majority of University users: we blocked Google Docs."

Re: Oxford Temporarily Blocks Google Docs

#117
post #79
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

Oooooooooooooooo rant coming on............. Im sorry, but that is the typical tech reply that blows normal people's minds. Blame the user. Well, the user says, sod that, lets just block the problem and get on with what we wanted to do in the first place. People, normal non tech people, want to use computers as a tool, not become experts in thwarting criminals, etc. If a user cant just go to a computer and simply use…

I thought one point of the Web was accessing tools like Google Docs, and now they blocked it.

No solution is perfect, but GP's are certainly better.

Re: Oxford Temporarily Blocks Google Docs

#118
post #27

They're attacking the wrong part of the problem. If misleading messages ("phishing") are leading their users to enter credentials onto forms which are then used to send out spam, then the solution is not to block access to one of the sites that supports forms. There are an unlimited number of sites that support forms. There are LOTS of better ways to solve this problem. Here are a few: * Train your users where it is…

> Train your users where it is and isn't safe to enter credentials. This demonstrably doesn't work. It reduces but cannot eliminate all instances of phishing. > Don't give your users credentials. Have some alternate way to authenticate them like a login token. Better, but scrounging up a few million pounds for dongles, plus the non-stop cost and effort of replacing lost and stolen dongles, is not easy for a universit…

Does two-factor auth have to be that expensive to implement these days? I've experimented with building it against Google Authenticator (free, runs on any modern smart phone) and it's ridiculously easy to get up and running - it's a few lines of Python https://github.com/tadeck/onetimepass/blob/master/onetimepas...

Doesn't solve the problem of users without smart phones though, which I imagine is still not ignorable at most universities.

Re: Oxford Temporarily Blocks Google Docs

#119
post #106

Earlier quoted context omitted.

I disagree. At best the users who don't care will continue not to care. At worst it will train users to think "oh, it's another drill, ho hum". Somewhere in the middle is some deeply embarrassed Deputy Vice Chancellor who decides to make those horrid computer people his personal enemies.

> At worst it will train users to think "oh, it's another drill, ho hum". How is that a bad outcome? Whether they think it's phishing or a drill, the important thing is that they don't enter their credentials.

It's bad if users are trained to only recognize _your_ phishing attempts :-)

I'm not sure I understand which users jacques_chester is talking about. There are users that can recognize phishing, and they are entitled not to care about your teaching. And then there are those that can't recognize phishing - or perhaps don't even know about it - but I'm pretty sure any user would start caring when they find out someone else can gain access to their email/bank/facebook/whatever online service they use if they aren't careful.

To avoid training users into thinking it's another drill, perhaps it's a good idea to 'attack' them at random intervals, and wait a few months before repeating (thus giving you enough time to prepare the new attack; giving the users enough time to forget about the threat, and to account for new arrivals).

I'd rather be embarrassed by the local BOFH, rather than be a real victim

Re: Oxford Temporarily Blocks Google Docs

#120
post #80

Earlier quoted context omitted.

Maybe you should do some more reading. There are certainly supported configurations for two factor authentication.

oh yes of course they can set-up 2-factor authentication themselves, but it's not supported ''out-of-the-box'' is it? This is what I mean: http://www.neowin.net/news/microsoft-explains-why-outlookcom... With Google Apps you just turn it on... and can force users to use it.

Right, but your article is talking about outlook.com.

Office 365 and stand alone (ie: private) exchange installs certainly support it.

Comparing outlook.com to 'Microsoft Exchange' (whether you're talking about Office 365 which is MS's 'cloud' solution, or private Exchange servers) is not exactly fair. One is designed as a free email hosting solution for personal use (essentially replacing Hotmail), the other is designed for business/organizational use and costs money.

Post reply on HN