Live data from Hacker News

Tell HN: My kid's school installed spyware and I can't remove it

news.ycombinator.com

371–380 of 442 posts

Re: Tell HN: My kid's school installed spyware and I can't remove it

#371

I work for a school district (not CPS) with about 2000 deployed Chromebooks and you're likely running into one of two things. 1) You somehow 'enrolled' the device into the Chromebook management. This is hard to do by mistake but if you do, essentially puts the device under the control of the school district. It also uses up a license on their end. We only allow particular IT only accounts to enroll devices. 2) You're…

This response should be higher instead of the useless armchair lawyering :) With GoGuardian, though, I think device level management is common? It's BYOD but it essentially becomes the district's device (and all the other accounts disabled) until you remove the managed account. It can't happen by accident, though, it tells you very clearly you're making it a managed device. It sucks that schools are using enterprise…

Yeah seconding this both as a parent and someone who has worked in education IT (K12 and higher ed) for almost 15 years. I'm not familiar with GoGuardian but I do recall with certain 3rd party Google apps that did similarly there were ways within the admin console for said app to exclude monitoring devices (regardless if managed account that's logged in) unless they were on the district network(s) by adding CIDR blocks to a whitelist. Of course, if someone were to use the device on a BYOD network in district you could then get scooped up in that dragnet though we excluded even those networks to prevent this as all district devices should be connected to the proper LAN.

I've personally forbade my kids from logging into devices we own with their school accounts (O365). I've also gone so far as to relegate them to only connecting to a segmented guest network (internet only) with their district issued devices. I no longer work for a district but provide various levels of support for districts in my county as a state employee and let me tell you, no one really knows what they're doing. A district I used to work for uses a product called Aristotle essentially logging key strokes of every staff member and student. There are, or were, certain school admins that made it their business disciplining bored-ass students for things 99% of the time they may have said in jest to a fellow student. On the flip side it was instrumental in catching a couple staff members that were doing some pretty heinous things, one of which who is currently serving 35 years on federal charges.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#372
post #246

Earlier quoted context omitted.

Agreed, domain admins can also lock down Windows, iOS, Android, and MacOS. The school is effectively making the computer a terminal into their system. Their system, their rules. I know the OP won't like this answer but the OP should buy their kid another computer for their non-school activities. Of course they could also complain to their school/district to change the polices. Personally, I'm used to it. I have a per…

That corp computer is owned by your employer. If instead you are a consultant who does work for several clients on your own machine, then it would be unreasonable for them to lockdown your personal machine. Instead, if they want you to use a more secure solution, they should provide the computer.

No but if you add their MDM to your personal PC they can push policy to it.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#373

> I bought him a Chromebook for schoolwork, but also for other private things. When we logged in... This is why you need to pay attention to the technology choices that you make, and that your schools make. Chromebooks are designed from the ground up to be locked-down dystopian spyware once you "log in" to them with a specific Google account. For heaven's sake stop buying any more Chromebooks. The correct solution he…

> Chromebooks are designed from the ground up to be locked-down dystopian spyware once you "log in" to them with a specific Google account. Nonsense. They were designed to implement required policies when someone logs into a managed domain. Unless you're logging into something like that (where disclosures have been made and consent has been obtained) then there's no "dystopian spyware" involved. Absent any domain man…

> Chromebook are basically fancy thin clients that make efficient use of web-based services

This reminds me of Asimov's Multivac home terminals where every user, in the comfort of their home, could dial in a query on their computer terminal and the massive infrastructure which is the continental-sized Multivac computer will respond with an answer.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#374

I work for a school district (not CPS) with about 2000 deployed Chromebooks and you're likely running into one of two things. 1) You somehow 'enrolled' the device into the Chromebook management. This is hard to do by mistake but if you do, essentially puts the device under the control of the school district. It also uses up a license on their end. We only allow particular IT only accounts to enroll devices. 2) You're…

This.

Then again this site is mostly developers. They have no idea about SCCM, Intune, JAMF and other MDMs and how they work.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#375
post #134

> I bought him a Chromebook for schoolwork, but also for other private things. When we logged in... This is why you need to pay attention to the technology choices that you make, and that your schools make. Chromebooks are designed from the ground up to be locked-down dystopian spyware once you "log in" to them with a specific Google account. For heaven's sake stop buying any more Chromebooks. The correct solution he…

> Call into the school's board meeting during public comment, and make it loud and clear that the school is installing spyware on students' Chromebooks. Share your technical credentials and the method by which you found this. Just some comments on the political aspect of this, since the HN crowd tends to not be so good at that part: - Following this advice and using a tone that even resembles the tone of the comment…

> The IT department could have just as easily installed similar spyware for Windows or macOS.

Just a nitpick here, yes school IT could do a remote install of spyware if the user was privileged and agreed to it. But a privileged user could also uninstall it. Which is not the case here. In my experience with MDMs the school has to physically have the laptop to install a permanent MDM or purchase the laptop and provision through an activation portal. My experience has been Intune Autopilot and ABM.

Google Work MDMs was notorious for remotely wiping personal devices which is why I never allow work to install MDMs on my personal items.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#376
post #316

Earlier quoted context omitted.

If they thought the laptop was school property, then comparisons to wilful intrusion into someone’s house is hyperbolic, and no it wasn’t malicious. It would be more like if the cops had a valid warrant to track a suspects car, but installed the tracker in the wrong car by mistake. Best to establish the facts first.

Installing monitoring software (spyware) on a laptop that is owned by the school is legit only if you consider the student exactly that: a suspect. In that sense, your comment is spot-on. Following that logic, the act itself does not seem malicious. However, the logic of seeing students as suspects is.

No post body was provided.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#377

Earlier quoted context omitted.

Installing monitoring software (spyware) on a laptop that is owned by the school is legit only if you consider the student exactly that: a suspect. In that sense, your comment is spot-on. Following that logic, the act itself does not seem malicious. However, the logic of seeing students as suspects is.

I have a sort of extremist take on this: students are literally prisoners. The job of a high school is to keep students from harming each other, feed them, and occasionally teach them something. It’s why one of the highest offenses is to leave school grounds during school. Ditto for prison. In that light, of course students are suspects. They’re already guilty of not being adults. They’re not allowed to have jobs, or…

> students are literally prisoners

You're being downvoted, but I often felt exactly this way throughout my school years.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#378
post #370

Earlier quoted context omitted.

Installing monitoring software (spyware) on a laptop that is owned by the school is legit only if you consider the student exactly that: a suspect. In that sense, your comment is spot-on. Following that logic, the act itself does not seem malicious. However, the logic of seeing students as suspects is.

> However, the logic of seeing students as suspects is. Is it? I don’t think I know any high school student that hasn’t tried to muck with, or work around, the schools systems.

And "solving" that "problem" is not a good thing.

Re: Tell HN: My kid's school installed spyware and I can't remove it

#380

Earlier quoted context omitted.

That corp computer is owned by your employer. If instead you are a consultant who does work for several clients on your own machine, then it would be unreasonable for them to lockdown your personal machine. Instead, if they want you to use a more secure solution, they should provide the computer.

In my company setting up the office email on our personal phone is optional. But if we choose to do that, they install this entirely new 'profile' with work apps and controlling software on that in the name of security. I chose not to install it, but some would surely do it. Probably no case can be made against them as they don't force their employees to install mail on their phones.

I did that for convenience (though now I removed it), but the work profile seemed to be well compartmentalized from the personal part, and there was a strong emphasis on this fact before the installation process. If they were to wipe it, only the work profile would be affected. I fortunately never had to try it...
Post reply on HN