Google's threat model surely differs in some way from a school, but the specific threats you named seem like threats equally applicable to the surfaces identifiable in the threat model of a school.
Google's threat model surely differs in some way from a school, but the specific threats you named seem like threats equally applicable to the surfaces identifiable in the threat model of a school.
Google's threat model actually does include state level attack (And specifically by China) to steal IP or access confidential user data.
Not if the school actually cares about the future of its students.
From a blog post[0] we published at NuCypher a while back:
> If we fail to take action now, we risk a world in which unsavory actors - domestic and foreign - have built rich, comprehensive profiles for every one of our children, following the trajectories of their education, home life, consumer habits, health, and on and on. These profiles will then be used to manipulate their behavior not only as consumers, but as voters and participants in all those corners of society which, in order for freedom and justice to prevail, require instead that these kids mature into functional, free-thinking adults.
0: https://blog.nucypher.com/todays-kids-need-end-to-end-encryp...
Indeed - they're no better.
It's like the old 5G debate in Europe: who do you want to have a backdoor: Cisco+USA or Huawei+PRC? (Hint for Americans: some/many see China as less malevolent).
"Someone", sure, but not the Chinese Government! That's a completely different threat model!
The Chinese government is the last entity I'd be worried about with this kind of information (unless, of course, you live in China). Certain criminals in your own country are a much bigger concern.
This is similar to the concern some of us had over giving local government departments access to our full Opal card public transport travel histories here in Australia. Not all government employees are up to no good, but some are. Don't give them more than they need.
See their push into universities.
Because China=bad, Google or Facebook or Microsoft (which all provide data to) or NSA =good
There is no specific evidence for this, but it is a possibility. Balancing remote possibilities and accepting some that are beyond our control is what separates the sane from the tinfoil hat crowd. Personally, I would try to stick to apps by companies headquartered in your home country. This is difficult outside of the USA and probably impossible outside of the next 5 top software hub countries.
I like it! I'd totally give that TV series a try!
Of course they are. That's why they are happy to work with NSA which get everything that is routed through frankfurt.
>The subdivision HVA inside the Stasi would be the equivalent to the BND, while the larger and infamous internal surveillance of the Stasi is now in the responsibility of the Verfassungsschutz.
Why is that? It seems like the opposite would be the best advice: make sure to use something from a company not headquartered in your country. Most people probably have more to worry about from their own government than anyone else.
If yes: do not use Zoom right now. If no: do what you want.
But I wouldn't use it for work meetings.
But you made me look into this. Apparently Zoom does "accidentally" (accidents like this don't really happen) send data to China. [1] It's very normal for companies to completely divide up their Chinese servers and non-Chinese servers, so the rerouting makes me suspicious.
Zoom is of course just one vector for this, but the threat model of "it's just schoolwork at risk" is wrong. It's actually integrity of tje computing environment.
For those that use Zoom - consider spending at least a few minutes to make a mental threat model about Zoom. Who might go after you? What features does Zoom have that might be exploitable? What's the worst thing that can happen? The worst case for Google is not the same as the worst case for a professor or elementary school.
Maybe Zoom doesn't work for your use case - fine!
Maybe Zoom is good for your use case - fine!
Lots of people will be using it either way, so it's good to have Alex help lock it down.
- kicking out their colleagues
- muting the teacher
- posting memes in the chat room
It looks like you can't prevent them from muting/kicking out each other. There's a larger threat surface of mean pre-adolescents, than a hacker trying to steal their info.
Better education regarding these tools is required for sure.