Earlier quoted context omitted.
A few minutes of Googling showed me this upcoming meeting https://www.cpsboe.org/meetings/details/2329 on April 27th, 2022. It seems to be a Chicago Board of Education meeting, and seems to have options for public participation. Do I have this wrong? I'm not from Chicago or Illinois, so that's quite possible.
Quoted post unavailable.
Tell HN: My kid's school installed spyware and I can't remove it
171–180 of 442 posts
Re: Tell HN: My kid's school installed spyware and I can't remove it
#172You are going to spend a lot of time and money to address this. Better solution is to buy a second Chromebook only for school or personal use snd explain to your kid that their government hates them.
Re: Tell HN: My kid's school installed spyware and I can't remove it
#173> I bought him a Chromebook for schoolwork, but also for other private things. When we logged in... This is why you need to pay attention to the technology choices that you make, and that your schools make. Chromebooks are designed from the ground up to be locked-down dystopian spyware once you "log in" to them with a specific Google account. For heaven's sake stop buying any more Chromebooks. The correct solution he…
Nonsense. They were designed to implement required policies when someone logs into a managed domain. Unless you're logging into something like that (where disclosures have been made and consent has been obtained) then there's no "dystopian spyware" involved. Absent any domain management policies, Chromebook are basically fancy thin clients that make efficient use of web-based services.
That having been said, the OP either conspicuously failed to mention that such disclosures were made, or (and this I find to be much more likely) the school was dumb enough to think they don't need to disclose anything because like a lot of school systems, they have gotten the curious idea that they basically own the kids and that the kids have no rights whatsoever. Should that be the case I hope a judge spanks them soundly for it because yeah, they absolutely do need to disclose this stuff to the students or the first time there's a serious problem due to abuse of the monitoring system the school is likely to get very, very pantsed for facilitating child abuse.
Re: Tell HN: My kid's school installed spyware and I can't remove it
#174Earlier quoted context omitted.
That doesn't really make sense to me. User accounts, whether managed remotely or locally, should be subordinate to administrator accounts. That administrator-level privileges are insufficient to undo a change made with user-level privileges breaks this relationship.
OP didn't mention that the child's account is a secondary account. AFAIK if you log-in with an account the first time on a fresh(ly reset) chromebook, it becomes the "administrator" account - and at the same time if its in an organization (i.e. the school) the orgs policies are applied. No clue how that interacts if you do attempt to login such account as a second account, it's possible the org can require an account…
[0] https://support.google.com/chromebook/thread/117916330/how-t...
Re: Tell HN: My kid's school installed spyware and I can't remove it
#175Earlier quoted context omitted.
CPS does not really have a traditional school board and it’s not elected either (appointed by one of several mayors who ran on an elected school board and then reneged). OP can shout their complaints out over Lake Michigan for the same effect.
The next step would be to approach a local news station and have OP report what he found, again emphasizing his own credentials. Spyware and children in the same sentence easily bring up unpleasant thoughts.
https://www.computerworld.com/article/2521075/pennsylvania-s...
https://abcnews.go.com/GMA/Parenting/pennsylvania-school-fbi...
Re: Tell HN: My kid's school installed spyware and I can't remove it
#176Earlier quoted context omitted.
A few minutes of Googling showed me this upcoming meeting https://www.cpsboe.org/meetings/details/2329 on April 27th, 2022. It seems to be a Chicago Board of Education meeting, and seems to have options for public participation. Do I have this wrong? I'm not from Chicago or Illinois, so that's quite possible.
Quoted post unavailable.
Re: Tell HN: My kid's school installed spyware and I can't remove it
#177Earlier quoted context omitted.
Can the managed account actually access files from the unmanaged account or control which processes are active while the unmanaged account runs? Because, if yes, this absolutely does sound like a security hole: 1) Set up an organisation and add a managed account. Set up policies that install a backdoor on first login. 2) Get hold of victim's Chromebook. 3) Log into the Chromebook using the account from (1) 4) Chromeb…
Does a chromebook allow you to have more than one user account? It sounds like a factory reset was necessary to allow enrollment
Re: Tell HN: My kid's school installed spyware and I can't remove it
#178> I bought him a Chromebook for schoolwork, but also for other private things. When we logged in... This is why you need to pay attention to the technology choices that you make, and that your schools make. Chromebooks are designed from the ground up to be locked-down dystopian spyware once you "log in" to them with a specific Google account. For heaven's sake stop buying any more Chromebooks. The correct solution he…
> Call into the school's board meeting during public comment, and make it loud and clear that the school is installing spyware on students' Chromebooks. Share your technical credentials and the method by which you found this. Just some comments on the political aspect of this, since the HN crowd tends to not be so good at that part: - Following this advice and using a tone that even resembles the tone of the comment…
Re: Tell HN: My kid's school installed spyware and I can't remove it
#179Earlier quoted context omitted.
The ending of that post (trimmed above) is also important: > So you can boot into your personal account and do your personal business and then reboot into your business acount and do your business' business, but never the twain shall meet.
Not a chomeOS user, so maybe I'm not familiar with the terminology, but what is the difference between "log into" an account and "boot into" one? Are there different ways how you can add multiple accounts to a Chromebook and the OP just used the wrong one?
Re: Tell HN: My kid's school installed spyware and I can't remove it
#180> I bought him a Chromebook for schoolwork, but also for other private things. When we logged in... This is why you need to pay attention to the technology choices that you make, and that your schools make. Chromebooks are designed from the ground up to be locked-down dystopian spyware once you "log in" to them with a specific Google account. For heaven's sake stop buying any more Chromebooks. The correct solution he…
> Call into the school's board meeting during public comment, and make it loud and clear that the school is installing spyware on students' Chromebooks. Share your technical credentials and the method by which you found this. Emphasize stories of previous data breaches involving educational companies [1], This is some bad advice. No need to escalate the situation. Simply contact the sons school and find out who the t…
What is not reasonable is the very real possibility that they might have overstepped and made these policies active for all logins on the device, or that they failed to properly disclose what exactly happens when the user uses the domain login. That would then make what's been installed very worthy of the term "spyware" and would probably make both GoGuardian and Google upset with them because it's unnecessarily heavy-handed and pretty much guaranteed to bring bad press.
Part of the reason these things are so locked down is so that management policies can be applied to ONLY the logins that require them without impacting the entire device all the time. If someone tries to sidestep that by grabbing root access and messing with the trusted environment, when the user logs into the managed domain the machine is going to report that its environment has been tampered with and that should pretty immediately bring use of any domain-managed accounts to a halt. You wind up actually jumping through the same hoops (although more discretely and without involving logging/reporting of browser history) when you use your bank's banking app or have Microsoft Teams/Outlook installed on your phone. Both of these things absolutely require their data be kept separate from the rest of the user's data, and very carefully protected from the other apps on the device.