This certainly seems like a direct attack on something like JAMF, which Apple has basically blessed to be the Enterprise management tool for Apple Devices. (Ok I guess since it's less than 500 users, maybe not quite in the same ballpark as JAMF, but I'm JAMF has plenty of customers with less than 500 installed devices, and this service offers more than just management)
Business Essentials
151–160 of 316 posts
Re: Business Essentials
#152Earlier quoted context omitted.
Can screen readers not figure out that a 1px x 1px element with a clip-path: inset(0px 0px 99.9% 99.9%) is invisible?
The trouble is, I think, that typefaces vary so much that some could appear to have a strike through when they don't. Or take for example the number 0 which sometimes has a fairly horizontal slash through it. Do you program the screen reader to check if the struck letter is a 0, and if so, consider it not to be struck? But... What if it actually is, and that typeface doesn't have a slashed 0? Do you only check perfec…
Re: Business Essentials
#1531. Apple Business Manager refuses to work in Firefox due to an arbitrary user agent block, and they apparently still haven't fixed this.
2. "If accepted, your existing Apple Business Manager account will be upgraded with additional functionality that cannot be undone." - This is a really good way to ensure we don't try this. What if it causes our organization new problems? Why would your beta product be impossible to roll back out of?
Re: Business Essentials
#154Smart play to focus on businesses with fewer than 500 employees, as those are the most likely to grow in the next 3-7 years into larger accounts, and they don't have the 12-18mo sales cycle and shennanigans of an enterprise. It's a strategic departure from being a consumer luxury product company, and the shift to enterprise suggests they're out of ideas, but at the rate they're losing consumer growth I'd say they've…
Didnt they already try this and it was a huge failure
Re: Business Essentials
#155Earlier quoted context omitted.
Whitelists. It's kind of a pain, but might help reign in the teachers that send kids everywhere on the internet without much thought about the surveillance dangers.
MS and HS students are expected to be able to independently browse the internet to do research-- this doesn't work with whitelisting. (And in elementary, there's good human supervision of technology use).
Re: Business Essentials
#156Slightly off topic, check out the HTML code next to the "Onsite repairs" box; the formatting uses strikethrough, but there is a hidden element with "Not" text before each crossed out line. I assume this is for accessibility or copy-paste compatibility; as a result the raw text still reads: > Onsite repairs: Not someday Not next week Not soon ASAP. I find this kind of attention to detail very cool. (Too bad "ASAP" is…
Re: Business Essentials
#157Slightly off topic, check out the HTML code next to the "Onsite repairs" box; the formatting uses strikethrough, but there is a hidden element with "Not" text before each crossed out line. I assume this is for accessibility or copy-paste compatibility; as a result the raw text still reads: > Onsite repairs: Not someday Not next week Not soon ASAP. I find this kind of attention to detail very cool. (Too bad "ASAP" is…
Slightly tangential but don't soon and ASAP mean the same with the difference of an urgency qualifier?
Re: Business Essentials
#158Earlier quoted context omitted.
I figured, when my kids were a certain age, that if I took that route, they'd ALWAYS get around whatever control I put in front of them. Either at home, or at school or at a friends house. Told them there was stuff on the internet that could harm them, that there was stuff they could NOT unsee. They're 18 now, the results of the science experiment are still out, but they seem to have turned out okay.
This is the right way to go. Teach, don't block. You fuck up your relationship to your kids if you force them to keep secrets from you and constantly "fight" against you. Because trust me, that's how it'll end up.
As they get older I'll remove it in stages: blacklist, logging only, then direct access with no proxy. The opening up will be done when it seems appropriate and in full discussion with them. I don't have a schedule for it.
When they're old enough to have phones I can initially give them managed devices with always-on wireguard and the same transparent proxy. (I've tested this setup and it's not circumventible without wiping the device.)
The claims often made on hn about this stuff, that:
* Kids will resent any attempt to limit their access, and
* Kids are NSA-level hackers who will circumvent any attempt at limiting their access.
are empirically false, at least in my experience so far. I expect they become more true in the teenage years but that's when things can start to open up.
Even if the restrictions have to be entirely dropped or become irrelevant the second they enter senior school, they've already benefited a lot from this over the years.
The other argument, that other kids will have phones etc so there's no point, is just an abdication of responsibility. I feel like I should do my best here, whatever everyone else is doing.
The one thing that is true is that it's quite technically demanding. A managed phone with an always-on wireguard connection to a network with a transparent ssl-bump mitm proxy and a domain-based whitelist with an admin UI to browse logs and block/unblock domains is not an easy thing to set up.
It's possible, though, and it has value. It should be much easier.
Re: Business Essentials
#159Smart play to focus on businesses with fewer than 500 employees, as those are the most likely to grow in the next 3-7 years into larger accounts, and they don't have the 12-18mo sales cycle and shennanigans of an enterprise. It's a strategic departure from being a consumer luxury product company, and the shift to enterprise suggests they're out of ideas, but at the rate they're losing consumer growth I'd say they've…
These aren't Microsoft specific issues but vendor specific. My partner's last two employers have used Dell machines and they've each had serious problems with audio drivers. I've seen Dell bios updates completely mess up full disk encryption by losing keys and more recently switching SSDs from ACHI to ATA mode.
At the same time I've had comparatively few issues using my work issued Lenovo laptop. However I completely re-imaged my work issued Macbook because the Trend Micro software installed on it made it $3000 brick.