What’s stored in a school Google Drive account?
web.archive.org
web.archive.org
If it's possible to get voice recordings out of the iMessage app from a separate app (shouldn't be possible from an iMessage app either) this would be a major security hole and Apple would be pissed at google for doing it.
This is almost certainly a misunderstanding of what's actually going on.
If you enable it, it can keep a history of what you have said tied to your account.
Many of these claims are outright false because they’re technologically infeasible and would require the exploitation of security vulnerabilities. Companies like Google are constantly having their apps inspected by hobbyists and professionals alike; there’s no way that’d go unnoticed for any length of time, plus it’s nearly impossible to begin with.
In short: a parent has just discovered the internet. They’re scared, paranoid, and confused. This is, unfortunately, quite normal.
There are legitimate privacy concerns regarding Google’s collection of data, but none of them are raised in this article. It’s a misunderstanding at best and outright propaganda at worst.
Auto-syncing of passwords is a core feature of every modern browser. Safari does it, Firefox does it, Vivaldi does it, Edge does it, Opera does it, and, of course, Chrome does it.
Want control over your child's account? Google has something for that: https://families.google.com/familylink/
Want the school to manage it for you? That's exactly what G Suite is.
Edit: The problem here is ignorance. It's easy to demonstrate that it's possible to control all the data about which this parent is concerned. Sure, there's data they can't easily control, but they make no mention of that. Your interests, demographics, everything else Google infers about you... you can't fully control that, and that's what parents should be worried about--not password syncing.
And then they talk about saving voice recordings and transcriptions from their phone messages... I can only guess they did something like configured WhatsApp to store backups on Drive and forgot they had?
EDU accounts should be treated like work accounts: use them only for EDU- or work-related things. Don't visit your bank's website and save the password to Chrome when logged into syncing to your daughter's school account.
On the other hand, asking students, parents, and faculty to fully understand the Chrome login-and-sync model, and how it differs from website logins, may be asking too much. And it can be hard to tell the difference between Chrome sign-in and Apps sign-in, or to realize that signing out of one won't necessarily sign you out of the other.
It does not address what pressing "link data" will _actually_ do and what pressing "cancel" will _actually_ do.
This has to be something where the admins changed some default setting to change the default security on everything in G Suite, so that all other school accounts could have access to it.
Maybe someone intended to set it up so that all google sheets and docs were shared among everyone on the plan, but didn't realize the change they made applied to other things that got synced to G Suite, like Chrome sync passwords?
However, GSuite for Education may very well introduce a loophole whereby the onus is put on someone else to get that consent. I'm getting that vibe from this knowledge base article:
https://support.google.com/a/answer/6356509?hl=en
In any case, interesting. This story seems like something Google would be smart to respond to/clarify.
How does Google do that? By having a 13 year old agree to Terms and Conditions/EULA (a legal contract), that the child has no legal authority to enter, which states the child obtained legal consent from the parents?
Minors don’t have legal authority to enter into contracts, Google can’t claim (at least it’s not a legal defense) they were defrauded by a minor for agreeing to their contract that expressly states the minor will get their parents consent or permission. The burden is on Google.
Google would be liable for collecting data on the minor in violation of law, notwithstanding any agreement the minor agreed to, because that agreement isn’t legally enforceable.
You’re covered by COPPA if:
- Your website or online service is directed to children under 13 and collects personal information from them;
- Your website or online service is directed to a general audience, but you have “actual knowledge” you’re collecting personal information from a child under 13; or
- You run a third-party service like an ad network or plug-in and you’re collecting information from users of a site or service directed to children under 13.
and
Although the Rule doesn’t define the term, the FTC has said that an operator has actual knowledge of a user’s age if the site or service asks for – and receives – information from the user that allows it to determine the person’s age. For example, an operator who asks for a date of birth on a site’s registration page has actual knowledge as defined by COPPA if a user responds with a year that suggests they’re under 13. An operator also may have actual knowledge based on answers to “age identifying” questions like “What grade are you in?” or “What type of school do you go to? (a) elementary; (b) middle; (c) high school; (d) college.”
Note the "if a user responds with a year that suggests they’re under 13" part. If they don't, that would mean that there's no "actual knowledge" that the data being collected is associated with a child under 13. So "they lied to me" does appear to be a valid defense.
COPPA also requires “verifiable” consent of the minor’s parents...is a check box really verifiable consent? How can Even Google claim they verified who checked the consent box?
Google is the master of information. It would strike me if any company knew or should have known a user signing up for their service is a minor it should be them. Google literally makes it available to minors to agree to these contracts, so when you say google doesn’t allow them to...what do you really mean?
But you are wrong it’s not impossible to verify users age, and Google doesn’t have to delete user accounts...they can simply stop collecting user data of minors 13 and younger ;)
Edit: another loosely related example (dealing with age verification) is Girls Gone Wild where they paid underage girls to reveal themselves on camera, those minors signed the GGW contracts and provided fake IDs...yet GGW was liable.
As you acknowledge Google is paying some expensive in-house and outside counsel, I disagree with you that they wouldn’t agree with me. I’m sure in an attempt to minimize legal risks and potential liability they would have offered the exact solutions I have, but executives (as they often do) ignore counsel, thinking they know better, and expose themselves to the legal risks in order to collect data on children 13 and under to monetize them.
Anyway if you can show me your input, or support any of your claims (show me a lawyer with “more school” than me, or a lawyer who disagrees) that would be at least something more than trolling.
When I have chrome; it always asks me if I want to save passwords....
To one extent, this is a hard lesson to the parents; Check the security settings on any computer you are using; Check the "features" of every app you install.
To another end, it's a good lesson for the parents and children that school and work supplies are for school and work.
To yet another end, those passwords, if auto generated, are likely much more secure than other ways of storing passwords.
I am a bit curious about some of the claims about sync on iPhone. I don't have one, but is it even possible for another app to reach the internals of Safari? I would think that is locked down. Or are they logged into their google account in the browser? As for google getting the voice and text from a messaging app, how would that be possible unless its an actual google app?
I basically had to do a full reinstall of the browser to stop it. It wasn't a case where she didn't log out.
I mean maybe it's not as clear as it should be, and maybe it should remove that cookie if you log out (ehhh...), and it should probably be easier to get rid of all of that... but we're hardly talking the conspiracy of the decade here.
(Not sure if there is a legitimate reason this has been taken out)