Live data from Hacker News

Privacy for Students: Surveillance Self-Defense

ssd.eff.org

31–40 of 95 posts

Re: Privacy for Students: Surveillance Self-Defense

#31

> “If authority figures for youth say constant surveillance is OK, what happens when a romantic partner wants access to every message on their phone? Or an employer wants your social media password? Invasive monitoring isn’t acceptable, no matter who tries to do it, and personal privacy matters.” I think that it is even worse than that. In a decade or two, we are going to learn the many cases of sexual abuse that thi…

Certainly already happening: > Over the next 15 days, the school district captured at least 210 webcam photos and 218 screenshots. They included photos inside his home of Robbins sleeping and of him partially undressed, as well as photos of his father. The district also snapped images of Robbins' instant messages and video chats with his friends, and sent them to its servers. https://en.wikipedia.org/wiki/Robbins_v._…

Wow... they are one (or two) horny kid(s) away from a child porn charge and the confiscation of their servers.

Re: Privacy for Students: Surveillance Self-Defense

#32
post #24
post #10

My schools tried to require school owned apple equipment that both restricted actions (couldn’t message with parents or email) and monitored all activity, even when used from home. I forced my own equipment and they tried to install and reinstall various spyware throughout the year. It seems like rather than proposing a basic system of assignments and material and grades, they are trying to treat as a wholly owned ec…

Surprising that schools are requiring additional certs to be added a a device for internet access. This enables "keybridging" mitm attacks on any TLS connection that trusts the cert. Best load a 3rd-party browser and install it locally, rather than compromise the whole device. https://nakedsecurity.sophos.com/2013/01/08/the-turktrust-ss...

It's not really surprising.

Breaking PKI by installing fake CA certs so that IT can MITM every connection is now an Enterprise Best Practice (tm).

In case the sarcasm isn't evident, please read the above as sarcastic. I detest admins who do this.

Re: Privacy for Students: Surveillance Self-Defense

#33
post #10

My schools tried to require school owned apple equipment that both restricted actions (couldn’t message with parents or email) and monitored all activity, even when used from home. I forced my own equipment and they tried to install and reinstall various spyware throughout the year. It seems like rather than proposing a basic system of assignments and material and grades, they are trying to treat as a wholly owned ec…

I was the kid in school who told people about rebooting to single-user mode and creating hidden root user accounts :-D Some people got in trouble for having learned about it and misusing it though >_<

I am the kid in school who tells people about jailbreaking their ipads and overriding dns records :-)

Re: Privacy for Students: Surveillance Self-Defense

#34
post #30
post #29

Spying off hours is unacceptable, but during class teachers should be able to see what students are doing on district-provided equipment.

Why? Like seriously - grade them on their work and tests and who cares what they do else wise

That only works for some students. Others will simply fail. Fifth grade is far too young to condemn a student just because they’re too young to understand the consequences of their inaction and come from a shitty household incapable of teaching that lesson.

That being said, it’s only acceptable IMO when:

1. It’s only on school-issued equipment.

2. It’s only during hours when the school is responsible for the pupil.

3. What’s being monitored and recorded is stated explicitly in and limited to a document that is distributed to students and parents when the equipment is issued.

4. When screen grabbers or Remote Desktop are used, the student is given some kind of obvious on-screen warning that they are being surveiled in real time.

Re: Privacy for Students: Surveillance Self-Defense

#35

Spying on kids outrageous. The sad state of things is that the most valuable tool kids could learn now is that it's not strangers but authorities who are predatory and self interested, and you need to learn how to manage authorities and rules, which means, how do you extract value from them without being pulled in and subordinated to or hustled by them. Respect does not mean obedience, it means maintaining clear boun…

Schools and districts serve the bureaucracy more than the students, teachers, or parents, it seems to me. Not sure when the transition happened. Probably generations ago.

Re: Privacy for Students: Surveillance Self-Defense

#36
post #20

What makes this even scarier is the amount of technological incompetence the people have who are monitoring these things. As far as I know, there’s no legal equivalent to HIPAA(which itself only scratches the surface of things) for ensuring the data and logs of these invasive systems stays under tight supervision. Now add in the fact that the people monitoring these systems may have an infinite amount of their own se…

FERPA is the regulatory framework that governs how student records are handled. To the best of my knowledge it's similar to HIPAA but not as strong as it only applies to public schools. There may be additional state laws about it as well.

https://en.wikipedia.org/wiki/Family_Educational_Rights_and_...

Re: Privacy for Students: Surveillance Self-Defense

#37
post #24
post #10

My schools tried to require school owned apple equipment that both restricted actions (couldn’t message with parents or email) and monitored all activity, even when used from home. I forced my own equipment and they tried to install and reinstall various spyware throughout the year. It seems like rather than proposing a basic system of assignments and material and grades, they are trying to treat as a wholly owned ec…

Surprising that schools are requiring additional certs to be added a a device for internet access. This enables "keybridging" mitm attacks on any TLS connection that trusts the cert. Best load a 3rd-party browser and install it locally, rather than compromise the whole device. https://nakedsecurity.sophos.com/2013/01/08/the-turktrust-ss...

Of course, that means you can’t use the school’s Wi-Fi since now every site with https won’t let you pass.

Just install the cert on one device (either school issued or Firefox on a BYOD device since it keeps its own cert store that doesn’t affect the rest of the system) and use that for browsing on school Wi-Fi if your paranoid. In my experience, school IT has other things to do than to watch what your browsing without cause.

(Yes, this practice sucks. But it’s the only way for them to implement the legally mandated filtering in a way they can guarantee it is working.)

Re: Privacy for Students: Surveillance Self-Defense

#39
post #20

What makes this even scarier is the amount of technological incompetence the people have who are monitoring these things. As far as I know, there’s no legal equivalent to HIPAA(which itself only scratches the surface of things) for ensuring the data and logs of these invasive systems stays under tight supervision. Now add in the fact that the people monitoring these systems may have an infinite amount of their own se…

In the United States one of the HIPAA correlates in the Education space is FERPA (Federal Educational Records Protection Act), but it doesn’t have the same teeth that HIPAA does.

Re: Privacy for Students: Surveillance Self-Defense

#40

Earlier quoted context omitted.

I was the kid in school who told people about rebooting to single-user mode and creating hidden root user accounts :-D Some people got in trouble for having learned about it and misusing it though >_<

Your school used Linux computers?

I would say more likely apple. I did this when I was younger as well
Post reply on HN