Dutch schools must stop using Google's email and cloud due to privacy concerns
tutanota.com
tutanota.com
Now I work at ProtonMail, so go figure.
There's the option of quarantining emails that have specific keywords. That's the likely way to catch students discussing cheating, attachments and all.
Edit: as the comment below has pointed out, this might not be true. Different editions have different tools, the one i use is not the most complete.
Email routing is also an option, although far more heavy handed.
I think there was some news in the past where some schools took this even further with webcam and mic access, though I didn't experience this.
On a school or work computer that you don't control assume someone is watching behind your shoulder at all times, and reading every word you type. Whether if that's the case or not.
And also every computer running software you don't own/control. If you really care about privacy you really need to be running Linux on personal machines.
That was a nice middle ground. I could sensibly use my favorite environment even during short 10 minute visits between lectures.
https://developers.google.com/admin-sdk/directory/v1/guides/...
As far as I can tell, adding a delegate or forward isn't even logged anywhere, and being able to see what a delegate is doing was added as a feature only a few months ago: https://workspaceupdates.googleblog.com/2022/03/gmail-delega...
There is a big difference between being able to do something and being allowed to do something.
Be it emails, databases, file servers, anything reading content from anything else but a test account/db/folder is a no go for a sysadmin/dba unless given explicit consent by the user owning that content.
FWIW in a lot of SaaS companies having read access to production data for regular workflows is absolutely unthinkable. In my opinion the users who expect that their private communication is not read have it right.
But it's absolutely understandable that an organization has administrators that are able to access data for legal or other compliance reasons, and Google provides those tools as part of the service they provide. There's nothing sketchy about this from Google's side.
The Dutch order is more concerned with whether or not data regarding students is being transferred to the US and processed in ways that it shouldn't be. --Which there's no indication that this is happening, as far as I can tell.
> Google has indicated that it plans to fix the privacy concerns by August 2023
which means that they acknowledge that the current situation is insufficient. If the data was stored and processed only in Europe, they would likely say so. Although even that would not be sufficient, because
> American authorities can access data stored in the European cloud
(by American companies), due to the CLOUD act. So the privacy issues aren't that easy to solve, which might be why they expect it to take >1 year.
Personal accounts would require a going through a process for lawful intercept. I have no idea how formal this process is today or if Google even ask for a copy of the warrant. When I set up monitoring for cell phone conversations in the cellular industry, not at google I always had a copy of the warrant.
MX gateways are also a valid option.
This applies for school staff managing student emails, startup founders managing cloud apps for staff, and Google employees... in general.
Problem with ProtonMail is its JavaScript. If we want to use e-mail with public key cryptography (perhaps we shouldn't), we need to use standards which work in any MUA, and are completely FOSS.
I believe we are better off with a protocol which has a FOSS reference spec, is federated, and from the ground up build with privacy and security in mind.
Not sure if/what other admin tools they might have
Here is why:
- No autofwd. This is essential for any business Fastmail has this. - No imap/ POP (usecase: integrating with clickup email) - no iOS calendar app - recent pricing changes - pricing on a per domain basis
Ive wanted to support proton and ive paid to so that for a while, but my understanding is that product releases are very slow.
Ive come to believe that protons cadence of releases is not sufficient for a regular business that has to move faster to keep with competition.
I was a big supporter of proton, but starting a business using the proton suite now is a poor and expensive business decision.
i hope this changes in the future.
My criticism is on the business plans. Personal may suffice for most needs. (Email search is a pain, but that is the sword you fall on, given encryption)
https://european-alternatives.eu/category/cloud-computing-pl...
It should be easy to replace most of the services.
I've had my gmail account for probably more than a decade now and have never had to worry about it going amiss, meanwhile I look at this list of barely legit sounding names (aside from Proton) and wonder if any of these will be still around in a few years.
There is no Google or Apple or Microsoft though, and accordingly a lot of the network effects and institutional knowledge is lacking.
I do very much concur that there is no European competition for US IT supremacy on the horizon any time in the next decades.
China is a different story...
A laughable statement. Who was it again that was pleading on their knees to reserve ASML capacity for them?
For companies it's not a big deal because their users know what responsibility is. And you can fire them otherwise. Schools don't have that privilege.
Add to that that without chromeOS you've essentially got one choice: windows. So you'll be finding out all about spyware that rootkits the OS, and constant amazement at just how many different rootkits kids can get installed on a single machine. Hell, when I was in school, I wrote a custom rootkit (bo2k like) and installed it on machines. That was fun and instructive.
(I know technically you can make it work over the internet but it takes very capable admins to make that work)
And yes, I hacked the school, but that was through unsecured shared folders and seeing a teacher enter people's grades in excel, not through the rootkit. That I was caught doing (because I decided to "expose" the school by giving a friend's sister her grades 2 weeks in advance, and their parents went to management. I was in detention "for the rest of the year" and I was lucky that 2 teachers demanded I would be allowed to sit my exams because I was the best in their classes)
However, ChromeBooks will also be banned i Danish schools when the new school year starts in August. The Danish Personal Data Authority (Datatilsynet) have just told the schools that they cannot use them after the summer holidays, for more or less the same reasons and their Dutch colleagues.
The problem then becomes: Which laptops can you get in large enough numbers, at a low enough price, within three to four weeks?
Most European countries aren't so lucky, parents are the ones buying the computers, and unless you're into classes related to computing, or at university level, you're not bringing them into class (naturally covid has changed this a bit) only using them at home.
Can they install a Linux distribution on the existing ChromeBooks?
Remember, most people at work are not responsible for their computer working. In IT we are because we're doing more advanced things and we're technically able to keep it working and to fix it. However, the HR person, the sales person, etc they are not. And most countries have laws where the employer has to provide working tools, the employer is responsible for providing you with a working laptop and if it breaks it is their responsibility to fix it.
It's way beyond despicable but I'm too tired to fight it so I've caved in and bought a Windows laptop for one of my kids to use for highschool. It disgusts me that Microsoft manages to extract a tax on every kid in highschool and that schools allow themselves to be used as a part of the marketing and sales arm of a multinational company.
> I went to buy a laptop for my son's new school last week. When I heard it was required, I was expecting some list of hardware requirements but no, the list I got had exactly one specification: Windows.
Schools also do free advertising for Microsoft products, at least in all of the schools where I went to until ~5 years ago. At minimum once a year we were made aware of the fact that we could get Microsoft products like Office at steep discounts from their new online store which they were so proud of and thankful for. Benevolent microsoft letting us get used to their ecosystem for prices we could actually afford, but not free! Still gotta make that profit!
Not sure why they didn't also advertise for libreoffice which, last I checked, is even cheaper and an even better protip (better compatibility if we would just not force each other to keep using the proprietary thing). I guess they just didn't feel like the libreoffice foundation was giving them free money the way that microsoft pretends to.
It gets even more ironic if you realize that schools fall in the 'semi-government' category and thus it's legally required (not optional) to use open source software unless that's impossible, and if it's impossible then it needs to be documented why it's impossible. In practice, you can guess how much this law is followed. I never heard of any consequences for not following it.
TL;DR: legally, there is the opposite of a microsoft requirement, except many schools require both Windows and Office in practice
I had a strong affinity for computers from an early age, but all education was focused on Microsoft Access, Excel, Outlook, Word and Powerpoint
If you could get any programming (only in College) it was Visual Basic 6 or VB.NET (with Access or MSSQL)
There was no curriculum that wasn't a buy in to the microsoft ecosystem, even at the advanced levels.
This is surely amazing for microsoft, entire generations of people trained exclusively on their platform.
1) productivity suites are a poor fit generaly.
2) learning concepts over specific tools is always going to be a better investment.
3) I’m not sure there even was open office when I was learning. But there was lotus and co. // I’m mainly annoyed that they didn’t teach concepts around computers and instead focused on “Microsoft X” so my entire education was based on one company and what it was inflicting on the world.
Everyone who graduates only knowing those tools is enormous pressure for companies to use those tools, or the burden of training from scratch is on the company.
It was the other way around, at least where I live. Companies pressured schools to teach skills they actually need people to have - and that's MS Office, because even today nothing else comes close.
And children with aptitude for computers, who don't need office suites but would like programming - that's less than 1%. If you want public schools, you're not going to have specialized teaching for small groups - nobody pays more for that.
I’d prefer a real education about how computers work, not to learn any particular single tool or ecosystem.
Religious education does not only teach Christianity. It’s wild that computer education only teaches (or taught) Microsoft (a non-European proprietary corporation).
> even today nothing else comes close.
Close to what though?
Close to replicating MS office? Sure, but that’s like judging an apartment building on the merits of a house.
Your implication that productivity tools compared to MS office are lacking. That’s extremely dubious, perhaps some features are lacking (google sheets doesn’t support GANT charts for example) but there’s other things that you can do which are impossible in office (google sheets can do raw SQL and attach to big query); I’m specifically comparing google to MS here but it’s mainly to give an idea that things don’t map 1:1 across productivity suites.
And yes: The world runs on excel, but I find it hard to believe that’s because excel is the pinnacle of software. It’s probably more to do with that it’s “good enough” and fairly flexible- and crucially, everyone knows it and it’s pitfalls.
You can be productive with other software.
No, that is not why Excel runs the world.
Those capabilities are not used even slightly in the companies I’ve worked at.
If you use VSCode don't forget telemetry is enabled by default.
Here is how to disable it: https://code.visualstudio.com/docs/getstarted/telemetry
I refuse to touch any Windows 10 machine that did not go through this:
https://github.com/W4RH4WK/Debloat-Windows-10
https://gist.github.com/gvlx/b4d4c5681900ca965276fc5c16fe852...
(Warning: Use at your own risk)
Here is a great experiment you can do. Use an app like for example Netbalancer that can show you bandwidth use per app. Launch your locally installed PowerPoint. Note I am not talking about Office 365 but a locally installed Office component. Start some internal presentation to your fellow workers, just presenting, no editing or creating a new presentation. Amaze yourself at it sends data to Microsoft at the rate of 4 to 5 MB/s. Yeah...just try it.
Amazing is too small a term. Unacceptable is more like it. Wow. Why do companies that spend a significant amount of money on securing their infrastructure fall for this?
"Google Chromebook outlawed in Danish public schools"
https://news.ycombinator.com/item?id=32142927
(77 points, 73 comments)
If you're Google sure throw a 100 people at a project that might get pivoted or axed. It won't matter. But a Government IT initiative? They have to be more efficient.
This is simply false. A lot of fields use specialized software that is only available on Windows and sometimes macOS. For instance, my wife works in neurolinguistics where most standard software for doing things like analyzing EEGs is for Windows.
However, I agree that this may be true in other branches of education. E.g. in our daughter's primary school they use Chromebooks. They are used as glorified 'web terminals'. I can see why a mutable Linux distribution would be awful from a maintenance perspective, but an immutable Linux system like Fedora Silverblue would probably work as well as ChromeOS.
This is also a failing of the Dutch government and the EU, leaving things to the market, rather than taking initiative and making a standardized education platform.
Problem is, after three months of work, I wasn't able to reliably deploy the OS to a room of computers and connect it to the school network - even though I worked as a Linux server admin before that. Every single computer (all the same, with serial number one after the other) had a different set of issues that made it completely unusable. Many of ones I got kinda working got broken after a few rounds of updates.
Windows just worked right after installation. The year of Linux desktop is still not there.
Those machines ran without fault for multiple years until I had to add some additional support for caching the NFS mounts because we had added so many clients after the initial installation that we were overloading our NAS.
No hardware errors for sure. But these were desktops (not of uniform origin).
Windows machines on the other hand were a bit more painful, every single one had to be hand enrolled to the sambav4 “AD” (we didn’t have AD) and the instructions never worked the same way twice.
So annoying.
Yeah I can imagine that not having AD makes things more complicated, but once you have it, it works very well on Windows.
Not being able to reliably connect to AD was one of the failures I had with this classroom.
Especially because that Microsoft product (AD) is usually the hardest thing to integrate with from other operating systems; and is contingent on owning all user accounts (and usually means you have to use their email systems and file sharing systems).
Quite a lot of lock-in for a base level of user experience.
But I guess that’s OK if you are a shareholder. :)
I definitely wouldn't discount the amount of effort that Apple has put into that.
Try doing it with linux or with OSX Mountain Lion.
The thing is, people (admin and users) are quite happy with the MS stuff - it's not perfect and costs a lot, but it mostly works without too much setup work.
Nah. I’ll pass.
I detest ecosystem lock-in like this. :)
Especially from foreign entities.
When it came to whitelabelling our product for a big multinational customer, they really liked that we were hosted on GCP and not AWS because they considered Amazon a competitor and couldn't justify paying AWS as a result.
Privacy concerns aside (which I believe are overblown for GCP, strong walls around customer workloads), competition concerns are big for many companies, and Amazon is out there trying to compete with almost everyone in retail and services now. I can only imagine this is going to get worse.
Disclaimer, I now work at Google but not on any of this stuff, this is my personal opinion.
Are you sure that's a technical reason?
Whilst I do get some nonsensical response, that big tech have great security, it does feel really lainful that there is basically no alternative. I really want there to be, but there just isn't a viable alternative.
There isn't? My Eastern European highschool had self hosted email since as far as I can remember hosted on some pentium PCs.
The issue isn't that there's no alternative, the issue is that, schools are unable or unwilling to bother doing things themselves and instead just go with Apple, Google, Microsoft, because it's easy and almost free.
In reality, the concern seems to be the law will not legally allow them to continue operating unless Google clarifies where the data is processed.
It's not "clarify where the data is processed" but rather "make sure it's not processed by an US-owned corp" (not to say that any other country is fine, their laws must be compatible with GDPR).
The major issue is that it's so centralised already that everything outside of the oligopoly is considered untrusted, but it doesnt take long to get trusted- even if you run marketing campaigns over email like I did for years in the mid 2010's.
I'm not sure if we're all collectively incompetent or if we're completely overblowing how difficult it is.
granted; while I managed email systems of various sizes... yeah I outsource it now myself; but that's MAINLY because I'm lazy, I don't want to deal with it and I don't have an obligation on those emails to preserve privacy or anything like that.
if it was my job to do that because there is a risk to the company; sure, not a big deal, sanitise some IPs slowly over time, configure your PTR records, DMARC/DKIM and SPF everything, ensure you're not an open relay and you probably have to look at it once a month for an hour or two to make sure you're not on a blacklist. -- people do this all the time (or used to) with active directory.
Yeah, its stateful and your deliverability is affected by idiots sending spam-like things, but it's not "hard".
Collective (learned) helplessness here is really going to fuck us over, we already forgot how to run servers it seems, now we're not even able to host services.. soon we won't know how to write code, I'm sure.
I agree with this 100%. It's bad and I think partially because at least as far as I know, there is no standard definition of how you'd need to setup your email server to guarantee some arbitrary email delivery success rate. And so it ends up being a combination of arcane knowledge together with slow feedback loop for debugging.
btw, if you have any good resources recommendations for successful configuration, I'd love to take a look at that.
The real fun starts after things are set up, as you start wrestling with deliverability issues, trying to get recipients to mark your mails as not spam, trying to avoid recipients to mark properly delivered mails as spam, while simultaneously making sure you prevent your systems from sending spam through hijacked accounts and loopholes.
But giving up? No, definitely not. It's quite doable, but not as straightforward as it ought to be.
Sure, it's definitely easier when you have _users_ sending mail. When you have _customers_, it gets a tad more complicated. Sure, you can be a good kid and keep IP's warmed up, set up authentication and make sure DNS is configured properly. None of those help when some spammers decide they like your hosting service and start purchasing accounts with stolen credit cards, nor when you have customers re-using passwords, refusing to use 2FA and so on, and their accounts inevitably get hijacked.
Office 365 and Gmail silently dropping mails doesn't make things easier.
Why can't the state build a data center and host some Matrix, Nextcloud and Moodle instances? To me that would seem like tax money being used as intended by the taxpayer.
Switching from a cloud run by professionals to a self-hosted Nextcloud would be a massive downgrade in information privacy.
We already know google, microsoft and apple have unfettered access to your data too. With self hosting, at least I have a chance of knowing when my data's being monitored & I can choose increasingly severe security around that system. The big players can only offer promises with little to no way for us to verify the truth of any one of their statements.
So, unless the big players offer e2ee as a default, it's best to assume the worst from them. With nextcloud it's far less necessary if you're rolling your own (but it supports a form of encryption anyhow)
C'mon really. The whole central point of this euro scaremongering is that Google will turn over your data to intelligence agencies when U.S. court orders it to do so. Now imagine that for whatever fanciful and obviously highly unlikely reason the C.I.A. wants your PDFs. You are claiming this will be visible to you, that you will be able to defend yourself against hardware supply chain attacks, attacks on the media you downloaded to install CrapNux on your servers, attacks against your NextCloud auto-updates, attacks against the whole rest of your software supply chain, social engineering attacks against your sysadmins, attacks against your hard disk drive waste stream, and all the rest of it? And you will be able to achieve this on the budget on a Dutch primary school?
Look, I think it would be cool if nation-sized bureaucracies had the doctrines and practices that allowed them to be actually safer than the cloud, but as it stands they do not.
I am sure, Google has ways to abuse data that do not include any courts.
Euro scaremongering? [0] [1]
Particularly that court mention is weird, considering how the FISA court is very much just a rubberstamp formality.
> Now imagine that for whatever fanciful and obviously highly unlikely reason the C.I.A. wants your PDFs.
That "fanciful reason" could be that my company developed a breakthrough technology/medication/chemical.
Which is exactly the kind of stuff the NSA is very interested in, so it can "patent subsidize" US industries with them [2]
[0] https://www.theguardian.com/world/2013/jun/06/us-tech-giants...
[1] https://qz.com/1145669/googles-true-origin-partly-lies-in-ci...
[2] https://en.wikipedia.org/wiki/ECHELON#Examples_of_industrial...
> U.S. court order
If only it worked like that.
IMHO Europe should just do something like create an https://www.inria.fr/en for writing sane software that acknowledges and handles the complexities of governance. Can't image that paying tons of grad students good money to design and hack something in Ocaml/Haskell that actually works is more expensive than the status quo.
They can afford professionals.
https://www.dataport.de/pressemitteilung/dataport-stellt-ope...
That all seems solveable to me with enough money and time. What if a billion Euro gets invested into infrastructure and hardening of these tools? I think everything that you describe is a result of underinvestment. Extorting our kids data to Google cannot be better.
We aren't also outsourcing the military to Blackwater and the secret service to Facebook, just because they can run it more efficiently.
It’s a Brexit benefit or something.
https://ico.org.uk/for-organisations/dp-at-the-end-of-the-tr...
That's not how it worked. The GDPR is a regulation which means that it applies as-is in all EU member states without being incorporated in to national laws. It is only directives that need to be incorporated in to national law (a process known as "transposition").
As far as the UK goes, because the GDPR was in force at the time of Brexit it continued to apply (the same with almost all EU law), although it was amended so that it didn't reference EU institutions any more (like removing the bits that talked about the EDPB or collaboration with other EU supervisory authorities, replacing references to the Commission with the Secretary of State and other things like that).
However, the Data Protection Act 2018 [1] does complement and supplement the GDPR in UK national law, including certain data not covered by GDPR, and more specifically apparently "implements those parts of the GDPR which 'are to be determined by Member State law'". This was before Brexit took place, and it was later amended to reflect non-EU status at the start of 2021.
For the GDPR specifically, the UK basically forked it and has what's known as the "UK GDPR". They basically just gave the powers that lie with the Commission to the Secretary of State and deleted the bits that dealt with cross-border collaboration between DPAs.
Not on GSuite accounts.
It doesn't even have to be malicious, it can happen accidentally. If the entire company is based on advertising and privacy violations then it's hard to truly have "private" data without building an entirely separate system in parallel, otherwise you could put your data in a place you think it's private, not realizing some other component of the system will use that for ad targeting.
https://www.nytimes.com/2017/06/23/technology/gmail-ads.html
If you have any highly specific claims about this please point to news articles in reputable journals which have not already been repudiated.