Monday, May 12, 2014

Especially for seniors- How to take your Google Apps data with you

As this year's Senior class prepares to graduate and move on to bigger and better things, we want to make sure that they can take all their hard work with them to college or work. Most student data is stored in Google Apps for Education in the oregonsd.net domain. If you have documents or files stored on the network server, you can copy it directly to Google Drive.

Students can export their data directly from Google Drive (directions here), but there are also tools to automatically move all the contents of a Google Apps account to another Google account. For example, a student could move their documents, gmail, calendar items, and websites from student.sample@oregonsd.net  to a new personal account such as mynewaccount@gmail.com, or to their new university email address.


Another is Google Takeout from the Data Liberation Front.

We (the OSD IT department) don't own these tools, so we really can't support them, but wanted to let you know they exist. Best wishes to the Seniors!

Tuesday, April 29, 2014

Don't use Internet Explorer

Microsoft Security Advisory 2963983 (CVE-2014-1776) is a serious Vulnerability in the Internet Explorer web browser that could Allow Remote Code Execution. Microsoft is aware of limited, targeted attacks that attempt to exploit a vulnerability in Internet Explorer 6, Internet Explorer 7, Internet Explorer 8, Internet Explorer 9, Internet Explorer 10, and Internet Explorer 11.
The vulnerability is a remote code execution vulnerability. The vulnerability exists in the way that Internet Explorer accesses an object in memory that has been deleted or has not been properly allocated. The vulnerability may corrupt memory in a way that could allow an attacker to execute arbitrary code in the context of the current user within Internet Explorer. An attacker could host a specially-crafted website that is designed to exploit this vulnerability through Internet Explorer and then convince a user to view the website.
For more information on Microsoft Security Vulnerability 2963983, please visit:
https://technet.microsoft.com/en-us/library/security/2963983.aspx

Skyward and other vendors are recommending that everyone use an alternate web browser until Microsoft releases a patch. 

Monday, April 21, 2014

Heartbleed issue: What you need to do

You may have heard news of the "Heartbleed" Internet security breach or gotten an email about it from friends. This email tells you what you need to do, which is, unfortunately, not as easy as just "change your passwords." It's organized in the ever-popular "Q&A" format.

Q: Is my school email safe?
A: Probably. We use Google Apps, and it was a Google researcher who found the flaw, and Google patched its systems very quickly. But you should change your OSD password just to be safe. 

Q: Is Infinite Campus safe?
A: OSD's IC server appears to be unaffected or fixed. Regardless, your IC password should be the same as your OSD email/network password, so you don't need to do anything specifically regarding IC.

Q: How about Skyward?
A: Skyward was never vulnerable due to the version of SSL it used, so your personal and HR information is not at risk.

Q: What do I need to do?
A: This is a two step process: 
  1. Check to see if a site has been fixed. (Check the top 100 web sites here.)
  2. AFTER a site has been fixed, then change your password for that site.
Q: Why not just change all my passwords right away?
A: Until a site has been patched, if you change your password, then the attacker can potentially get your new password as well. So wait until the site is patched before changing your password. More info here.

Q: What about sites that aren't in the top 100 list, like my bank?

Q: Why is this such a big deal?
A: It potentially affects half of secure sites on the web, has been around for two years, and was only recently reported. More info here.

Tuesday, April 8, 2014

wireless network down for upgrades between 4-5 PM today (4/8/2014)

The district's wireless network will be down today for about 20 minutes sometime between 4:00 - 5:00 PM so that we can upgrade the wireless LAN controllers. You should plan to use a computer with a wired network connection during this time. 

I apologize for the short notice.

Thursday, March 13, 2014

Update on delayed email delivery

Google has released some information regarding the delayed email deliver that occurred last week.
The problem with Postini Services should be resolved. We apologize for the inconvenience and thank you for your patience and continued support.A copy of the quarantined messages will start to be reprocessed in the next hour. Engineers will start to redeliver messages in small batches. It's then expected that it will take several hours until all messages are reprocessed. Messages unaffected by the original issue and already properly classified as spam will also be reprocessed. A new copy of the affected messages will go through a full regular Postini scan using proper customer configuration settings and filters, as present at the re-delivery time. Reprocessed messages that are still considered as spam will be placed in quarantine again, creating a duplicate entry in the quarantine. The process will not clear out the Postini quarantine of affected message copies; message copies already quarantined will remain quarantined.
Based on this, it appears that in addition to email messages which were intentionally quarantined due to virus or spam, some (many) messages that should not have been quarantined were being incorrectly quarantined.

You can read more about this particular incident at http://www.google.com/appsstatus#hl=en&v=issue&sid=11&iid=f4d40ff81521acea4e58014d7a83ffeb

Although this was the result of what Google considers an error, we still get notifications on a daily basis of virus and spam outbreaks which Google stops from being delivered. These can also cause delayed delivery because Google blocks the offending IP address, and that IP address may be the source of legitimate emails as well. In fact, it's possible that email messages from OSD staff are originating from the offending IP address, due to the globally distributed nature of Gmail's infrastructure.

Action: block '550 mailbox unavailable'
Source: 113.162.75.147
Time: 2014/03/13 10:01:21 GMT

As always, if you have more questions you can contact the IT department.

Sunday, March 9, 2014

Infinite Campus updated to version 1410.2

Upgrade complete
Version: E.1410.2
DB Refresh: No
Requested Date: 2014-03-09 17:00
Scheduled Date: 2014-03-09 17:00

Resolution: 
Automated update complete.

Friday, March 7, 2014

Delayed email delivery

Some users (myself included) have experienced delayed email delivery, ranging from hours to days. It appears this is due to a number of spam attacks aimed at our domain. When this happens, Google temporarily suspends email originating from the attacking IP address until the attack is stopped. 

As a brief historical context, email was never designed to be an instant form of communication. By design, mail servers are set to try to deliver email, and if they cannot, try again hours later, until a certain amount of time (the old default was two days) before giving up and sending a failure notice back to the sender. So although we have become accustomed to instantaneous delivery, it is not really designed that way.

I'll post other updates on this topic to this blog.

========
Updates: SPAM attacks

Action: block '571 spam source blocked'
Source: 182.72.181.33
Time: 2014/03/11 06:41:15 GMT

Action: block '571 spam source blocked'
Source: 186.118.195.40
Time: 2014/03/08 01:04:44 GMT