Jump to content

Recommended Posts

Posted
I have some of the same concerns, there is a big difference between locally hosted software that you have administrative control over and the system, storeage and software being totally controlled by the external provider. I always like to keep a plan B in reserve for if and when these providers decide to change what they offer or how they offer it.

 

I think the days of locally hosted are over. Even the office 2013 default behaviour is to save to the cloud. Its just too convenient for users to have a single place for everything and more so when software experiences are the same on a multitude of devices at home,at work etc.

Posted
I think the days of locally hosted are over. Even the office 2013 default behaviour is to save to the cloud. Its just too convenient for users to have a single place for everything and more so when software experiences are the same on a multitude of devices at home,at work etc.

 

Another bone to pick, the fascination and the folly of "The Cloud". so many people have bought into the idea of the cloud that those people who run the cloud services must be laughing at how easy it has been to convince you to give up your data security.

 

And just because it may be an option to save Office docs to the cloud, doesnt mean you should use it. In fact for me that would constitute a security issue.

 

Honestly the level of blind acceptance to Google stuff and The Cloud makes this about the most disturbing thread i have seen in a while.

Posted
So are you going to make Little Jimmy fully aware that his data might be subject to collection by Google when you let him use their products or hand him a chromebook. I wonder if you might want think of the possible legal ramifications of acting so blaise about this.

 

For the record, at the schools i admin, not even staff have access to webmail, because of the possible legal issues that they could expose the school to, and yet your attitude is a free for all and no questions asked....

 

And please tell me exactly how Microsoft have been data mining students data?

 

Oh enough, honestly im tired of trying to highlight issues which i thin are valid to people who would rather bury their heads in sand.

 

Office 365, skydrive , live webmail work in exactly the same ways as google albeit with fewer features. The kids only have temporary accounts anyway, its not like their 365 account is going to follow them around for the rest of their lives.

Posted
I think the days of locally hosted are over. Even the office 2013 default behaviour is to save to the cloud. Its just too convenient for users to have a single place for everything and more so when software experiences are the same on a multitude of devices at home,at work etc.

 

Oh they are trying, when everything is cloud based they have all the switches and can do whatever the hell they want and you have very little if any recourse. You can also just as easily point 2013 at your own sharepoint box which you can have globally reachable and host locally, or at least on systems you can control.

Posted
Office 365, skydrive , live webmail work in exactly the same ways as google albeit with fewer features. The kids only have temporary accounts anyway, its not like their 365 account is going to follow them around for the rest of their lives.

 

Nope, but the data stripped and mined from it will.

Posted
Another bone to pick, the fascination and the folly of "The Cloud". so many people have bought into the idea of the cloud that those people who run the cloud services must be laughing at how easy it has been to convince you to give up your data security.

 

And just because it may be an option to save Office docs to the cloud, doesnt mean you should use it. In fact for me that would constitute a security issue.

 

Honestly the level of blind acceptance to Google stuff and The Cloud makes this about the most disturbing thread i have seen in a while.

 

The cloud does provide a significant number of issues, security is one of them, and we have legislation to follow over it in the UK. As far as I've been concerned, I follow what the law says, and that's about it. If the DPA allows us to use servers in Germany, and those servers comply with the laws, then we are being perfectly safe with out data.

 

However, the issues I always have with cloud related things are more complex - availability, reliability, management etc... If you're in a city and your net connection is flawless then things are a lot simpler but if you're in a rural area with expensive and unreliable internet then you're not going to choose cloud related goods.

 

Nope, but the data stripped and mined from it will.

 

Anonymised data that bears no relation to anyone after they leave? What's the damage that'll do? Is it not worth the same as buying products in?

Posted
What exactly are they mining then, and what do you propose they're planning to do with this data?

Does it matter? Even if they just mishandle it (the searchable issue that GAPS had) that is a problem, the fact that the data is accessable. You don't print out your confidential staff records and stick them to the schools windows, or even store them in a folder in a room that contractors can wander in and out of, they usually go in a locked fileing cabinet.

Posted
Does it matter? Even if they just mishandle it (the searchable issue that GAPS had) that is a problem, the fact that the data is accessable. You don't print out your confidential staff records and stick them to the schools windows, or even store them in a folder in a room that contractors can wander in and out of, they usually go in a locked fileing cabinet.

 

It would be against both Microsoft and Google's terms of service if they made data accessible, they would be sued if they divulged anything confidential.

Posted (edited)
Again, you're isolating 'IE' and 'Chrome'. IE requires Windows. IE doesn't include Flash by default, Chrome does (so that increases exploits). If you take into account Windows exploits too, IE suddenly shoots up the ranks. If you run a Chromebook, you're running on Linux. Ok, there's a massive amount of variability in Linux distros, but security vulnerabilities in the base OS are significantly less than Windows out of the box.

 

Yep, i am isolating Chrome and IE. For this simple reason, one comes as part of the OS, and one you have to manually install. And i believe thats its responsible to mitigate security issues, and by installing Chrome, as it currently stands, its counterproductive in my opinion. Why would any sane person install something thats less secure than a built in component of the OS.

 

Lets be clear, Chrome uses WebKit, which has the most exploits of any browser engine. And its used in Safari and iTunes, so if you have a Mac and run all these then good luck to you. And of course the once popular Opera has announced its moving to WebKit...bad move....sure to make it even less relevant

 

IE doesnt use WebKit, and while the underlying OS has had its share of exploits (more in the past than present), show me where the 291 exploits Chrome had last year match the 291 in Windows OS.......in fact in a sign of generosity, ill let you add the underlying OS exploits and the IE exploits together, and you'll still fall horribly a long long way short of 291

 

Arguing that you have expertise on this because you have 30 years of experience is fine, but it could also be argued that you're 'set in your ways' due to it. It also screams 'arrogance' to me personally, but hey, your experience is definitely worth listening to, but I'll balance it against my own.

 

I started out in Unix, ah the old days when you had to write your own device drivers, have worked for HP, ISP's, turned down a job at Microsoft, Government and law enforcement agencies and several Universities and schools. My first interface to the net was gopher, so i was using the Net well before the WWW.

 

So when i see that my digital footprint is nil after 20 odd years, yet people who have been on for like a week turn up in search results, then i kind of take a serious view of personal data security.

 

So if you think its arrogant of me to mention my experience, then thats your interpretation, im just mentioning merely with the intent of using it as background for what i consider an important argument.

 

Remember, everything everyone does on a computer is a balancing act between security, functionality and cost. Chromebooks do not suffer from Windows vulnerabilities, or ActiveX, etc... They don't have to worry about any Windows malware etc... This may be down to there being less of them overall, but it is still an aspect of security you can take into account when doing your risk assessment. If we all just go for plain statistics about vulnerabilities, we wouldn't be using the internet at all.

 

See my earlier point about mitigating security issues by not installing a 3rd party application that has more vulnerabilities than the equivalent program already present in the OS.

 

Why would you tell a child that a company has access to their data, outside of normal education about internet safety? Do we have to warn them when they use any software that reports back to its manufacturer? There's a helluva lot of it out there. Including Internet Explorer. You do realise that Microsoft offer such services to schools too? Office 365? Live@Edu or whatever its called now.

 

Some might see it as their right to be advised of such, i do. Its not your right to agree to submit their data on their behalf, without their knowledge.

 

You are making out that everyone is hanging their kids out to dry, and somehow implying that Microsoft are entirely innocent of it too.

 

No im not, i havent said that Microsoft doesnt do it, i have said its not their main business, whereas Googles is.

 

Not giving staff access to webmail? Well that depends on what your concerns are. Technological solutions to people problems are not solutions in my mind. They encourage places to bury their heads in the sand because they assume the technological solution will eliminate the potential issues.

 

Thats right, they have an exchange account for school business, which is all they should be using during their school day for school related communications, for which they are paid. They are not blocked from receiving email of a personal nature form outside the domain of a personal nature. But they arent allowed to email information or upload documents which may contain confidential or student related information to any web based mail service. this is to protect confidential information, student data and to legally protect the school.

 

 

Anyways time for me to head off, still alarmed.

Edited by stylemessiah
Posted
I'm sure MS and Google will be fascinated by their schoolwork.

 

Nope, but they will love to have their names, any date information, any personal information to be able to identify and track that person in future.

 

When you realise that employment agencies are already not only rejecting applicants by keywords and phrases in cover letters and resumes, but then submitting those on the short list to companies who do background checks using data that has already been mined, then you might take things a little more seriously.

Posted

@stylemessiah So with your wealth of experience are you now so fearful of installing anything not present in the operating system?

 

You seem to be leveling a lot of accusations against Google without any proof that they are even doing the things you suggest - which are clearly outside of their terms and conditions anyway. It wouldn't be legal for Google or Microsoft to pass on data to employment agencies, they would be sued into oblivion. Why do you think they are doing it?

Posted (edited)
@stylemessiah So with your wealth of experience are you now so fearful of installing anything not present in the operating system?

 

You seem to be leveling a lot of accusations against Google without any proof that they are even doing the things you suggest - which are clearly outside of their terms and conditions anyway. It wouldn't be legal for Google or Microsoft to pass on data to employment agencies, they would be sued into oblivion. Why do you think they are doing it?

 

Umm, if you read above, i have already stated i dont use IE...so no, im not against installing things not in the OS...cleared up.

 

What im against is installing things which are full of exploits far far above what are present in those equivalents in the OS, in the case when specifically talking about Chrome and IE. Its utter madness to do so. no admin worth his left teste would do such a thing.

 

Really, as you seem to love google, if i wanted to deal with fanboyism, i'd go over to Neowin....really really over blind faith fanboys....really

 

Youre right its illegal for them to openly disclose any information they gather of a personal nature. But then its hard to sue a company who isnt doing it openly.

 

Reminds me of the AT&T & Verizon personal disclosure terms and agreements, and how well they worked, right up until a whistleblower blew the lid on the FBI to a lesser extent, and the NSA a larger, having their own rooms at AT&T & Verizon where they spliced directly into trunk lines and had access to all users data, not just those who were subject to warrants. When the staffer blew the whistle the FBI pointed out that the companies (AT&T & Verizon) themselves were data mining their own customers and passing on their information to 3rd parties. And the story quickly died.

 

And you dont think that Google, with its huge server farms, and whose entire business is based on user data, is doing anything but whats in its terms and conditions?

 

Ummm, did someone call me naive earlier?

 

Time for me to go to sleep....

Edited by stylemessiah
Posted
Umm, if you read above, i have already stated i dont use IE...so no, im not against installing things not in the OS...cleared up.

 

What im against is installing things which are full of exploits far far above what are present in those equivalents in the OS, in the case when specifically talking about Chrome and IE. Its utter madness to do so. no admin worth his left teste would so such a thing.

 

Chrome is a much more functional browser. Ie. it has far superior HTML 5 support, better standards compliance, better performance, better Javascript support, a better UI, etc... As I said earlier; balancing act.

 

You say you don't like 3rd party applications that have security issues. That is a good attitude to have. None of us like them. However, we also have demands on us for functionality. So, we install Java. We install Flash Player. We install iTunes for our iPads. If you eliminate 3rd party programs with security holes, you eliminate a heck of a lot of the purpose that computers have. If I did that, I'd be sacked for not allowing people to actually do their jobs - teach.

 

We mitigate the security issues by having security policies. We implement things like firewalls and anti-virus. We put ACLs in on our switches to prevent propagation of malware. We keep software as up to date as possible (which some companies make difficult by releasing updates on a nearly daily basis!) We also have backups to recover from problems if and when they occur.

 

And you dont think that Google, with its huge server farms, and whose entire business is based on user data, is doing anything but whats in its terms and conditions?

 

I'd be careful if I were you, you are basically saying that Google are committing illegal acts with no evidence. That in itself is actual a crime in every country I know of.

 

I'm going to side with @CyberNerd here - you are engaging in a massive FUD campaign here, with basically no evidence to support your views.

 

You ignore the fact that the companies you are supporting (Microsoft, for example), engage in the exact same behaviour.

 

You also state that you have all external email providers blocked because someone might send something out. That doesn't stop people distributing your data. Do you also have all memory sticks blocked? Have you got all machines locked so no-one can install any software? Do you have security checks to prevent people bringing cameras in so they can't photograph things on screens? Can people not print? All of these things can do the exact same thing - your technical measure will do absolutely nothing to prevent what is a people problem. Going back to my security policy point - this is one we include in it. Rules that disallow data to be removed from the site in an unencrypted form etc, which is backed up with training and a disciplinary procedure to support it.

  • Thanks 1
Posted
Chrome is a much more functional browser. Ie. it has far superior HTML 5 support, better standards compliance, better performance, better Javascript support, a better UI, etc... As I said earlier; balancing act.

 

You say you don't like 3rd party applications that have security issues. That is a good attitude to have. None of us like them. However, we also have demands on us for functionality. So, we install Java. We install Flash Player. We install iTunes for our iPads. If you eliminate 3rd party programs with security holes, you eliminate a heck of a lot of the purpose that computers have. If I did that, I'd be sacked for not allowing people to actually do their jobs - teach.

 

So youre advocating that admins take a reactive role to security, instead of the tried, true and prudent proactive one that has existed since the beginning of admin time?

 

Hey everyone, lets all go around and uninstall antivirus and anti malware and any other security software on all our users desktops, and while we're at it, lets take down the firewall as well. We'll worry about the damage after its occurred...wait, that doesnt sound right.....

 

Your comments re: Chrome just continue to paint you as a fanboy....and i loathe fanboys

 

We mitigate the security issues by having security policies. We implement things like firewalls and anti-virus. We put ACLs in on our switches to prevent propagation of malware. We keep software as up to date as possible (which some companies make difficult by releasing updates on a nearly daily basis!) We also have backups to recover from problems if and when they occur.

 

Oh, im confused, on one hand you want to let Chrome, java and flash to roam untamed, but now youre saying you do mitigate security issues with firewalls, AV and ACL's. Seems a little inconsistent with your earlier comment above....Im just saying....

 

But then youre back to reactive again talking about backups in case it all goes horribly wrong....

 

So i'll say what i said a dozen messages ago or so, why install a product with a demonstrated and known high number of security issues in the first place? Wouldnt that be best answer to both my proactive, and your reactive styles of admin?

 

I'd be careful if I were you, you are basically saying that Google are committing illegal acts with no evidence. That in itself is actual a crime in every country I know of.

 

Again, the comment of a fanboy defending blindly his chosen company/software

 

I wont be changing my name and fleeing to a country with no extradition with the US anytime soon.

 

I'm going to side with @CyberNerd here - you are engaging in a massive FUD campaign here, with basically no evidence to support your views.

 

Its your right to side with someone else who wants to remain a fanboy and blind to reality and easily verifiable facts ive presented, ironically you can use Google search to do this. but no, you would rather stick with your limited views and argue rather than do some research. thats fine

 

You ignore the fact that the companies you are supporting (Microsoft, for example), engage in the exact same behaviour.

 

Where have i supported any one company. I think ive said i dont use IE, that Microsoft's security used to be a joke, but has gotten better. So yeah, im not a fanboy like you. If i support any company or software, and i havent in this entire thread, its based on actual facts and personal experience (usually over many years), not the wide eyed optimism (coupled with ironically complete blindness) of a fanboy.

 

You also state that you have all external email providers blocked because someone might send something out. That doesn't stop people distributing your data. Do you also have all memory sticks blocked? Have you got all machines locked so no-one can install any software?

 

Dont you?

 

Do you have security checks to prevent people bringing cameras in so they can't photograph things on screens?

 

Nope, my responsibility doesnt extend to personal devices. and youre being silly...

 

Can people not print?

 

No they can print, but its only going to be either things they create or have access to via a whitelist on the internet. Any sensitive material is logged as its being accessed or printed. Its called security.

 

All of these things can do the exact same thing - your technical measure will do absolutely nothing to prevent what is a people problem. Going back to my security policy point - this is one we include in it. Rules that disallow data to be removed from the site in an unencrypted form etc, which is backed up with training and a disciplinary procedure to support it.

 

Actually youre wrong. You can mitigate almost any point youve raised pretty easily. ive explained how and why already.

 

Im glad to hear you at least have a policy to require data leaving the site to be encrypted. its just a shame youre willing to open up the possibility of it leaking via insecure software, via the internet, which is a much more likely path in this day and age.

 

Really am over this thread. Whoever ventures in here and agrees with the title "Chrome will bring about the ICT revolution in schools" is entering a fools paradise.

 

Im out.

Posted

Really am over this thread. Whoever ventures in here and agrees with the title "Chrome will bring about the ICT revolution in schools" is entering a fools paradise.

 

Im out.

 

 

It was just an anti Google bitchfest...

Posted
It was just an anti Google bitchfest...

 

Actually i think you will find it was about security, and mitigating security issues, of which Chrome had the highest of any software last year.

 

But youve just confirmed youre nothign but a fanboy with that comment....wow, thanks for making my point for me.

Posted (edited)
Chrome had the highest of any software last year.

You're right, but Firefox wasn't that far behind at 257. Apart from the fact that browsers (and browser plug-ins) are the most common targets, do you think Google's Vulnerability Reward Program and Mozilla's Bug Bounty Program could partly explain why their numbers are so high? People are more likely to report vulnerabilities (or sell them on the black market) if there is a cash incentive. Microsoft doesn't have an equivalent program.

 

Since this thread is mainly about devices that run Chrome OS, it's probably worth pointing out that Chrome OS had just 30 vulnerabilities during the same period (2011-2012).

 

The following table lists the programs in the Top-50 software portfolio together with the type of program (MS: Microsoft, TP: third-party), market share as of December 2012 and the number of vulnerabilities (CVEs) affecting the program in 2011 and 2012.

 

The ranking and market share is derived from anonymous scans of the Secunia PSI in December 2012. Note that the sum of the vulnerabilities in this table does not reflect the total number of vulnerabilities in the portfolio as many products share vulnerabilities.

 

For example Adobe Flash Player (#5), Adobe Reader (#8), and Adobe AIR (#20) share code components and thereby also share numerous vulnerabilities. For each program the unique number of CVEs of this given program in the given year is listed.

 

Source: Secunia Vulnerability Review 2013

 

http://i.imgur.com/G5CKFKK.png

Edited by Arthur
Posted (edited)
You're right, but Firefox wasn't that far behind at 257. Apart from the fact that browsers (and browser plug-ins) are the most common targets, do you think Google's Vulnerability Reward Program and Mozilla's Bug Bounty Program could partly explain why their numbers are so high? People are more likely to report vulnerabilities (or sell them on the black market) if there is a cash incentive. Microsoft doesn't have an equivalent program.

 

Since this thread is mainly about devices that run Chrome OS, it's probably worth pointing out that Chrome OS had just 30 vulnerabilities during the same period (2011-2012).

 

 

 

Source: Secunia Vulnerability Review 2013

 

http://i.imgur.com/G5CKFKK.png

 

 

I assume that Chrome OS runs the Chrome browser...so thats 30 + 291 = 321

 

How does that refute my argument? One would think it only serves to strengthen it.

 

Again, as i posted earlier, for me its about mitigating security vulnerabilities, and i argued that when you install software (Chrome) that has far far more vulnerabilities than the equivalent software already present in the OS, youre going against best security

practice. To further push the point i offered to let people add up the underlying Os vulnerabilities along with the IE ones and suggest that it came close to the number in chrome.

 

Honestly, i am truly leaving this thread and unsubscribing from the thread to stop the email updates for good as this is just like shooting fish in a barrel. People keep making my point for me.

Edited by stylemessiah
Posted (edited)
I assume that Chrome OS runs the Chrome browser...so thats 30 + 291 = 321

 

 

That does depend on how they have implemented it, chrome is Googles second attempt to make their own OS and running it without a virtualisation container has to make it more than a little of a mess, just like Java. All of these browsers are little mini Cesers trying to eat their hosts and become an OS in their own right, ChromeOS, Firefox for mobile. By trying to make a document format into a programming language they have attempted to switch the power base. It's funny because in their quest they have always gone with the universality of access and now there is all of these sites that 'only' work on Chrome or Firefox. They are worming their way in with the exact same practices that everyone got pissed at Windows for but suprisingly are all for this new order of the same thing perpitrated less efficiently by their favorite companies.

Edited by SYNACK
Posted (edited)
I assume that Chrome OS runs the Chrome browser...so that's 30 + 291 = 321

It does, but some of the Chrome OS vulnerabilities also apply to the Chrome browser so it won't add up to 321. :)

 

What you fail to take into account however, is the type of vulnerability. You are just looking at the numbers, which doesn't paint the whole picture.

 

As you can see from the stats below, the majority of Chrome vulnerabilities are classed as denial of service, whereas most of the vulnerabilities for Firefox, Internet Explorer and Opera are code execution. I would think the latter is worse, wouldn't you? :confused:

 

http://i.imgur.com/9N17wkm.png

 

http://i.imgur.com/5usHBNH.png

 

 

 

 

http://i.imgur.com/YOP4mc1.png

 

http://i.imgur.com/eb7c8EX.png

 

 

 

 

http://i.imgur.com/BxK45nr.png

 

http://i.imgur.com/F2mgn9n.png

 

 

 

 

http://i.imgur.com/IpIOv8a.png

 

http://i.imgur.com/2arl2vD.png

 

 

 

 

http://i.imgur.com/k5Nh4To.png

 

http://i.imgur.com/wpaG05N.png

 

 

 

 

http://i.imgur.com/mwtwOiR.png

 

http://i.imgur.com/b7RYtGS.png

Edited by Arthur
Posted (edited)
Nope, but they will love to have their names, any date information, any personal information to be able to identify and track that person in future.

 

When you realise that employment agencies are already not only rejecting applicants by keywords and phrases in cover letters and resumes, but then submitting those on the short list to companies who do background checks using data that has already been mined, then you might take things a little more seriously.

 

Your comments attacking Google on privacy, are rather hypocritical to say the least. One thing Google does not do is sell private or any other kinds of information to third parties - all Google does with any information it may come across is the dastardly crime of occasionally targeting an advert at the user based on possible things that may be of interest to them. It makes no sense whatsoever for Google to sell any information on to others - after all Google makes its revenue from advertising, and if Google sells its information on, then it undermines its own business. The same is not true of Facebook or Microsoft, who do not have the same means of generating revenue from advertising internally, and for whom it makes sense to sell on personal information for profit - and it is these types of businesses that do sell on personal information. When information is held internally, then the terms of use can be held to account legally. When it is sold on, then there is absolutely no control over what happens to it nor any jurisdiction that the data can be confined to.

 

Interestingly, while Google resists state requests for information where unenforceable, and even pulled out of China to protect its users against government intrusion into private and personal information, Microsoft seems to be to giving away personal information to governments when asked in most cases - and not just the US government, after all they want to sell Windows and Bing in Sudan, China, and other locations. This article says Microsoft provided personal information on 80% of government request worldwide.

 

Microsoft discloses requests from law enforcement agenies worldwide - Business - The Boston Globe

 

The privacy issue is a current FUD push by Microsoft to try to stifle Google's rapid ascendancy in education.

Student Privacy Should Not Be for Sale - Microsoft on the Issues - Site Home - TechNet Blogs

 

However it is complete and total hypocrisy. Unlike Google which does not sell private, personal or other data onto others, that is exactly what the Gates Foundation is doing with student personal data it has collected - in partnership with Rupert Murdoch, that other paragon of virtue when it comes to privacy issues.

K-12 student database jazzes tech startups, spooks parents | Reuters

Edited by SPM

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...