France says non to Office 365 and Google Workspace in school
theregister.com
theregister.com
IMHO that's the root of the problem. Why does MSFT need to process customer data? Yeah, we all know why, but I'm really getting tired of this shit!
It's not a problem paying for your product but leave my data alone, it is mine and that's it! No searching for emails, no training AIs on my code, no scanning images for "child porn", no reading my documents for "national security", etc... all the customer data you need to process is my email to send me a payment receipt or the size of the data I've saved to see if I'm over quota or whatever on that line.
And the same applies to all players in this field, not just MSFT who isn't even one of the worst offenders.
So is deletion.
And, as the processor, they are required to do as the controller (you) instructs.
That's not true, which lawyer told you this?
I'm honestly really tired of the FUD surrounding GDPR, it's not actually that complicated.
Check YOUR FUD at the door please.
IE if you send me a file and I put it on a drive and don’t give it to anyone or read it on behalf of anyone but you: it’s fine.
> Processing covers a wide range of operations performed on personal data, including by manual or automated means. It includes the collection, recording, organisation, structuring, _storage_, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of personal data.
I feel like you're intentionally missing the second section here.
Regardless, GDPR has hundreds of provisions where it excludes data as long as it's not processed, "storing is processing" in so far as it's secure and not being used by anyone except the account holder isn't going to stand up in any court on the planet, even luddite ones.
> It includes {the [(collection), (recording), (organisation), (structuring), (storage), (adaptation or alteration), (retrieval), (consultation), (use), (disclosure by {[transmission], [dissemination] or [otherwise making available]}), (alignment or combination), (restriction), (erasure) or (destruction)] of personal data}.
So there is no "second section" of the sentence, just a long list. The text of the GDPR has the exact same list [0].
There seems to be a terminology issue here, "You" would generally be the data subject, not the data controller, unless you are a company.
If you're directly using Office 365 or Google workspace, then MSFT/Google would be the data controller (the primary company who handles the private data), and any subcontractors involved would be data processors on behalf of the controller.
If you're a user in the school system, and have no direct agreement with MSFT/Google, then the school may be the data controller and MSFT/Google handling that data on behalf of the school.
The alternative is a product that is not collaborative (no online collaboration, at least) or requires customers to hire a sys admin to install on their own servers and maintain it.
This isn't some nefarious plot by big tech to steal your data, it's the product people want.
ADDED: And that's not even counting the fact that I can access my docs from multiple computers without worrying about shared network storage, etc.
‘But the web app running locally has access to your data and can phone home to its servers in the US or wherever’ - yeah, and so can a locally installed application.
Enabling collaboration doesn’t mean AI training, exposing data within an organization doesn’t require MS to be scanning it, and their servers don’t need to be in the US. It makes business sense for them to do so, but isn’t a requirement per se.
I believe both Google and Microsoft try to firewall any Enterprise or business data from their consumer lines. This means none of it will get fed into AI filters for the most part. Though I'm guessing marking things is spam still is a global thing.
There's no way around this issue while Microsoft-spawned EU companies are still part of Microsoft. I guess they could still sell open source software (to prove there are no backdoors, otherwise, after the Snowden scandal you have to assume that there are by default) that doesn't get to run on Microsoft's servers and that Microsoft doesn't provide technical support for... but how can this be a business ??
Office365 shouldn’t be some wildly different software that can’t live outside of Microsoft’s full grasp.
Most of 365 appears to be designed and architected to be a multi-tenanted SaaS solution, so I suspect it's not anywhere near as simple as just spinning up your own 365 instance.
365 is probably thousands of microservices behind the scenes which all have their own unique infrastructure requirements and will be actively managed by Microsoft. I suspect running these in your own datacentre would not be an easy feat without complete re-engineering by Microsoft.
We come to the same conclusion: Microsoft chose a different way for Office 365 where it could provide the service to more consumers while also keep way more control, in particular making it easier to justify recurring subscriptions at large.
It goes hand in hand with their cloud efforts and pushing for more services, so I understand the motivation. I also kinda wish this trend stopped.
Licencing might be one reason, but deployment complexity is probably the bigger reason.
not necessarily, if I choose a cloud product, it's to avoid having to manage the mail and data servers, not to have the content of those servers rifled through
It is though. They could design it in a way that it operates on your data but they have no access to the data outside of these strictly defined operations. If that was a priority to solve, it would be solved.
> it's the product people want.
These two things are not mutually exclusive.
Despite which, this is not true. There are no non cloud options if MS Office anymore, or of the Adobe Creative Suite. This stuff has been forced on us, often by work, and then the other options were removed. Hence the nefarious plot thing.
For Windows Home or other free/bundle solutions, it's a different situation. But not for enterprise or pro/higher-tier customers.
That is exactly what Google and Microsoft do with their enterprise products (free or not). They don't crawl your data at all.
This is impossible to prove.
Yes, ultimately Microsoft holds the keys to your encrypted data at rest but billions of dollars are riding on them managing customer keys well.
In fact, Microsoft makes that claim about Viva Topics https://learn.microsoft.com/en-us/microsoft-365/enterprise/m...
“Machine Learning ("ML") models are trained on public web data, and as such do not contain any customer data from your tenant. In the future it's possible we will use customer data to improve accuracy of the ML models, in which case the data handling of ML models will follow the same policies as any other customer content (including data residency, retention, access control, sensitivity).”
Are they perfect? No
Failing these audits would be more expensive than just following the law.
That's thankfully not true. For example:
https://www.microsoft.com/en-US/microsoft-365/p/office-profe...
This is wrong.
https://www.microsoft.com/en-US/microsoft-365/p/office-home-...
Additionally, if you're a business There are various non-cloud volume licensing options available.
Most people will pick the latter for cost. It would take a full two years of payments for O365 to equate the price.
Also, 2 years to make back the cost really isn't that bad. I have a 2007 Office dvd and it still works fine on W10, so if you keep this new version of office for 16 years, you made back your money 8 times over.
If you’re thinking of end to end encryption, that doesn’t discharge from GDPR. When person-related data is processed outside of the EU, even just to store encrypted bits, it must comply with all aspects of GDPR.
The genie is out of the bottle, cloud cooperation is a given for modern software. The question has moved on to how to regulate those clouds in ways that prevent the harmful sides. GDPR is one attempt to do that.
I picked up electrical engineering as a hobby because I want a smart home but there isn't a single IoT device on the market that I can trust won't phone home to sell my data. On the bright side I've found soldering isn't too hard and prototype size batches of PCBs are cheaper than ever.
It was done so to be a data farming monster. There is absolutely no justification why word processor needs to be a "cloud product"
I've worked on plugin software for a super common enterprise ticketing application. The fact that we need to make sure one person can't see another person's data mean we need to record the user names or a unique identifier number of some sort. But these numbers can be related back to a living breathing human being, so that's processing personal data according to European law and makes selling to Europe seem almost insurmountable if you aren't venture capital funded happy to burn very large piles of cash.
Afaik exchanging business cards in Europe technically involves violating the GDPR if you pass them on to someone else at work without explicit permission. But contacting the person for permission also isn't allowed, Honda got HUGE fines for that iirc
A bit off topic, but...I would have thought it depends on how you got that card. If someone hands me their card in a private meeting I wouldn't share it anyway. I would offer to do an introduction.
If someone had cards in a display stand on their public front desk it is really advertising, and I am quite sure you could share it. Sounds like a GDPR scare story.
Instead, if you are used to doing whatever you want with the data you store it takes years to build an European service since many parts of your process need to be reviewed and maybe even rebuilt.
It was about time for those laws to finally kick in and we started to see a change.
"Tech" companies never ask users what they want. The company decides what it wants, sets the direction that is most profitable and users follow along (after all, what choice do they have). Then "tech" company employees and spokespersons claim this is what people want. Ex post facto. Bullshit!
IMHO, HN commenters can speak for themselves. However there is no reason to believe they can speak on behalf of users.
As a consequence, Windows has to check all of the files under its management if they are still the same as in the original installation or if they got touched by one of the dozens of Windows Update packages somewhen along the path, and if yes by which update package, and what that means for the compatibility between updates, and what effects that has in turn on the update installation order. Then it has to check for each potential update candidate if there is a localized version available, do a final check again if it actually can apply each update because some of these have conditional checks... oh, and some of the updates depend on Windows components being installed, so this has to be checked as well, oh and then it needs to trawl through the hot mess that is the database of drivers installed on the system and the hardware it has encountered, and to check if there are updates available for that. And at least the last time I looked (Win7 era) it also was possible to integrate MS Office and Visual Studio updates into the MS Update process, not sure if that's still the case today, but back then that also added to the discovery process.
Windows is a hot mess of a lot of legacy garbage. Some of it got cleaned up a bit (e.g. refactoring stuff into components), but it's still nowhere near what almost all flavors of Linux sans buildroot offer.
Still, much better than locking up your entire computer for a long ass time followed by a mandatory reboot.
I call BS if we are talking "latest-gen" hardware. I have few laptops and desktops and it runs very snappy.
This is not to diminish Linux in any way. I use it every day and very happy with it as well.
Excel might be the worst here, but that is an UX problem. When you open it, it will first have you make it editable, then you need to allow connections, and finally if you want to mess around with something like powerquery it will lazy load .net each time before the UI is showing.
It really depends on the type of applications you use though.
I have frequently wondered why .net is just not preloaded somewhere on system launch and kept in memory. At least that is how it feels to me not being familiar with the .net technicals.
I do have one exception - some tiny very slim laptop from ASUS. It is used strictly to play Netflix, youtube and music to entertain me when I am on rowing machine. It does that just fine but it does not run anything but browser and music player.
Does your right hardware have a battery?
I was recommended Lenovo x220 as the best laptop and Linux-friendly one. Now I have it and I noticed that if web-browser has some moderately heavy pages opened like 20 tabs with Youtube, and dozens of light ones like HN - in Windows+Chrome this scenario eats slightly more energy then reading a e-book while in Linux+FF this halves battery time. Now my country suffers from shifting blackouts, so I installed Windows 7 on all my laptops with battery, and I have a significant benefit in mobility time.
Education is a prime target for rent-seekers for two reasons. First, you can use the same product and marketing on thousands of schools. Second, your marks are young and impressionable.
[1] german only: https://www.golem.de/news/bedenken-zu-microsoft-365-datensch...
This applies to other free offerings like Google Workspace for Education. Paid versions of these cloud services might be an option if they hadn't already been disallowed based on worries about data safety.
Generally speaking current law in the EU does not allow the use of US cloud services. That’s the basic outcome of the cited Schrems 2 ruling.
The various entities that use cloud services either cease to use them or get around the ruling by making their users agree to their data being processed in the US.
Currently we haven't had a clear ruling but at one point there might be a Schrems 3 ruling disallowing any accept by click-wrap license.
This will result in basically raising two types of kids. The technically inclined that see through this charade and will go on to leverage their knowledge in any jurisdiction that they do not associate with french legacy IT. And on the other hand, those who will not and forever associate the French IT systems and government with archaic computer systems that are completely removed from their other experiences in the cyberspace.
As a real world example, China wouldn’t have many of its mega corps if it was favoriting the established US equivalent until something rises to the same level. I hate to say this, but in this field, provided an entity has enough resources, protectionism basically works.
Pretty much any other chat app is better quality than Microsoft Teams. And TeX, which is much better than Microsoft Office, was written by a single persnn.
I am an h1b from India, working for one of those Indian contracting companies as a contractor to an US company. For my work, I use my employer provided laptop to remote login to client's Azure AVD remote desktop.
____
The incident:
One day, I was talking to a colleague about the 100 year wait period for greencards through client's MS teams. I shared him some twitter links (where people say they would be 115 when they get greencard and such) through Whatsapp. While I was talking about it, Teams got disconnected. Didn't think anything about it, thought it was just a network issue.
Same day, I was talking to another colleague, mentioned the same greencard thing, and shared the twitter links over Whatsapp. Again, MS teams got disconnected. I thought it was an odd coincidence that it got disconnected twice when I talked about this subject.
Same day, at around 9.30 pm, I get an email from Twitter saying they blocked a suspicious login from a city in US. So, someone knew my user name & password.
____
Regarding how someone would know my Twitter username & password: While applying for US visa, we need to give our social media user names in the DS160 form, which my employer will also see. I have used this password else where, so some data breach may have leaked it.
I don't know if one of the employees whom I talked to snitched me to my employer or my client was monitoring my Teams conversation (or Teams is looking for trigger words) and decided to investigate further where I am getting these info from Twitter.
____
This was the Twitter alert I got:
Suspicious login alert
There was an attempt to log in to your account @accountname that seems suspicious.
Suspicious login
Device: Unknown
Location: Springfield, MA, USA
When: date & time (11 minutes ago)
*Location is approximate based on the login's IP address.
If this was you
- There is no need to take any action right now. Just to be safe, you'll need to answer some security questions the next time you login to this account.
If this wasn't you
- Change your password now to protect your account. You'll be logged out of all your active Twitter sessions except the one you're using this time.
In the US, you should never expect privacy on company owned devices or services. The company may even be decrypting SSL sessions, revealing passwords in the clear (though they shouldn’t…).
[0] https://en.wikipedia.org/wiki/Tabloid_journalism#Red_tops
MS had a German cloud region operated in a way that was designed to look independent of the US Headquarter but somehow that got rolled back into the global azure operations structure after a few years. And while there is talk about trying something similar again but nobody can tell if that will be accepted as separate enough or how long it will be before those boundaries are crossed anyway.
For public funded institutions depending on any kind of user accept as a prereq for any service is extremely problematic so none of the workaround that have been used by businesses to bypass the lack of a valid "safe harbour agreement" so any solution put in place have to be designed in a way that don't require any "consent to data transfer"
In that case why not move everything to FOSS?
The problem is with the cloud integration not necessarily with the Microsoft part so if Microsoft wanted to they could sell an version of office to the school with the cloud functionally disabled or changed to point to an on-prem SharePoint installation but this is the smallest part of why school administrators like o365 and google apps.
The problem is that when you look into the email/groupware market and particularly how to manage devices/accounts, something both o365 and google apps(with Chromebooks) offer as a part of the cloud subscription, so now your kind of dealing with implementing authentication, file hosting, email, chat and a whole lot of associated problems based on picking individual solutions for each part of the puzzle.
What the regulators expect will happen is that smaller local companies will start selling integration services to the schools because that's how it worked when IT was introduced to the marketplace. But that market have been decimated over the last few decades so it's not obvious who in the local markets can still do it as the big vendors have been positioning their training offerings and best practice guides towards less locally controlled infrastructure.
Airplanes are a good example on just how utterly bad this can become - we have a lot of issues there. Both the EU and US sued each other over unfair subsidies, both Boeing and Airbus have massive structural issues because they are also expected to distribute pork over election districts...
At the core, the problem is anti-competition laws. Governments have enough firepower to simply muscle every free market competition to its knees - the private competitors would simply sue any too effective effort by the government away, and I cannot even claim that this would be without reason.