Showing posts with label users. Show all posts
Showing posts with label users. Show all posts

Thursday, May 6, 2010

Lower Merion School District Spying Report Issued

The findings of an independent consulting company (Ballard Spahr, LLP) were released recently regarding the remote monitoring of student laptop computers by the Lower Merion School District. Already it spurs an outpouring of vitriol in comments from the smart masses who think they understand anything that is going on here. Personally I think there's a huge disconnect between the peanut gallery and their perceived intelligence.

The report, an approximately 70 page outline of everything that was leaking into the press and then some, basically said what I originally thought. The school district has a lot of idiots running it. Not in so many words and perhaps not for the reasons people would think, but they did some pretty spectacularly stupid things.

The biggest problem, of course, was the IT department hiding the presence of the tracking software. It wasn't so much that I can't relate to their desire to hide it from people in case they try to circumvent the protection; I work in IT. I know people could do that. But anyone with half a brain in IT knows that security through obscurity won't work well. The laptops, if stolen, could easily be wiped and reinstalled with a clean OS image, and the tracking software would be useless. They not only hid it was there, but apparently they tried to obscure the fact that the software was there even when rumors were swirling about its existence. That is a blatant lack of respect for the students and faculty. Whether you regard them as little vengeful monsters or not they still deserve not to be lied to.

A very close second (okay, maybe it's a tie) was the lack of an updated usage policy for taking technology home. There were no documents to disclose modified acceptable use policies for using the laptops at home versus on the school network nor was there disclosure about potential security and privacy issues in the documentation given to parents.

Everything else in the report seems to nick the school for lax and ill-codified policies, and not being fully forthright with administrators and board members.

As someone who has to work in IT, I think the two biggest sins were the lack of properly documented procedures and the hiding of the ability to monitor the laptops. The fact that administrators and board members didn't know about these things, or didn't understand it, were not the IT department's fault, unless they went out of their way to hide it.

Really...there is a point where someone needs to take responsibility for themselves. The board didn't know about it because they didn't care. Neither did the administrators. They all had a vague idea of this ability, if they've seen evidence from the "anti theft" systems. What the hell did they think it did? That this stuff runs on unicorn farts and fairy dust?

I deal with users all the time. They care about how and why their systems work about as much as you care about how your car engine works. The IT department didn't explain it to them because it was a waste of time to do so! I've dealt with users to whom I've explained a simple (to me) concept several times and they simply don't listen. I can repeat it until I'm blue in the face and it doesn't matter. So why and how would this IT department telling their school board about activating timed snapshots from a webcam and screen capture utility while logging the remote system's IP address to a central server make any fucking difference to them?

And lack of following formal policies? In most smaller businesses and schools and, I'd venture, government agencies, following strict, codified policies is a luxury. We always hold up best practices as an ideal but more often than not they're aspired to, not followed. Departments like those in public schools are under immense pressures from the powers that be to just get a task done, and if it's held together with duct tape and broken pencils then so be it. Doing it "right" takes money and time. They don't want it done right. They want it done now.

While some would say that's an excuse, it's more of an explanation for the culture that this attitude has fostered. More often than not if something works, then it's good enough, and it saves money. If it's actually bad enough to bite you in the ass later then it will be fixed then. Otherwise, good enough is good enough.

What I find interesting is that lack of citing personal responsibility by the peanut gallery. These kids were using school property and apparently treated it like their own property. It wasn't. I was floored when this story broke and people were raving about how they'd format the computers if their kid had brought one of them home; yeah, right. You can't. It's not yours. The school was extending it as part of an experiment in technology-based curriculum. And it's their computer. Not yours. Not a handout. Not your property.

I'd have trusted the laptop about as far as I could throw it. Any organization that "lends" you a thousand dollar piece of equipment, would surely have the right to inspect it for activity; porn surfing, games, inappropriate use, anything of that nature. What universe would you live in where you go to school, can't browse the web the way you want, can't play the games you want, but expect them to just hand over a thousand dollar laptop so you could surf porn at home on their dime?

Use your damn brain!

There was one report of a girl who had taken the laptop into the bathroom to listen to music while she showered, and the parent was furious because the school may have seen his little high school princess naked. Huh?!

Damp, humid room...thousand dollar laptop...electronics...water. What the hell was it doing in that environment to begin with?!

To me, there were a number of failures here. From hiding the fact that this software existed to lack of formal CYA policies to cover proper usage of the laptops at home to a lack of common sense from the students and parents, there was a systematic failure that happened here.

The sadder part in my view is the ignorance of the peanut gallery. It's simply too easy to blame the evil school district and portray them as completely at fault while completely forgetting that there was also a bit of an attitude of entitlement, that reality has slammed down hard on the community realizing that these free toys weren't free. 

Tuesday, May 4, 2010

Thinking About the Future of Data Access, NetBook Edition

've had some occasion now to reflect on the netbook and how practical it is to use it for mobile data access, and now I've been using a full-fledged MacBook Pro (albeit the 13 inch model). I've come to some conclusions about using them. What follows is some mental rambling, not a submission for consideration of a Pulitzer, but see if you follow my ramblings to get some semblance of what the overall picture is.

Basically, computing is moving in a direction where the term "netbook" is pointless.

What you have are more or less capable computers. Parts continue to commoditize in a way that renders computers into data access portals.

What used to be a netbook was basically a computer that scaled back speed and memory and storage to a point where it was cheap in a package that was small enough to easily carry. That was definitely the state of affairs with the Asus EEE PC I tested in my "going mobile" change in digital lifestyle.

My daughter is about to head to college, so I've kept half an eye on what computers are going for in terms of what she would probably need to take to school. The answer? Computers now considered "netbooks" are practically desktop replacements for the majority of users out there.

They aren't specialized systems that will rip through animations or video games with the highest frame rates and benchmarks. But she doesn't need that, and neither does the majority of users out there. She needs email, office applications, and maybe skype or instant messaging and web browsing. These $400 netbooks today are capable of that and more, and at that price they're practically disposable (another requirement, giving a teenager a piece of equipment that they're going to treat as well as their cellphone...it's most definitely going to have a finite lifespan before Mr. Floor or Mr. Beercan introduces itself to Mr. LCD Display).

The distinction between netbooks and notebooks are a non-issue anymore. You can buy a perfectly usable $500 machine and at that price if it lasts 2 years and something dies, it's better for your time and money to get a new $500 machine at that point than invest the money in fixing it.

And for the average user it means even less because whether they're aware of it or not, access to data is the important thing, not the computer. Most people I see now are getting information via Facebook and Twitter. They want to text friends. They don't care if it's done via email or their cellphone, they simply focus on the goal, not the means. And some are adopting tools to make them even more mobile; saving documents to Google Docs or a USB thumb drive means they can edit and print work in a computer lab or their computer or whatever computer they're sitting in front of at the time. It means that when their computer, whether a $400 "netbook" or a $2000 workstation, dies or is inaccessible or is back in the dorm while they're in another building the documents or work they need can still be accessed from another convenient system.

Parts of this revelation comes at a time when Apple is trying to redefine the non-netbook with their iPad. It's a big success for Apple. But as a computer, it both sucks and is wonderful. It doesn't neatly fit the niche filled by small computers, and Apple won't say it does. But it can redefine how people work. It's almost like the PADD device on Star Trek: The Next Generation.

It neatly fits a niche for conveniently accessing information. It can be shoehorned into being a device that can write novels or, with the proper application (or if you can program the application and get it accepted to the app store) manage servers with remote access applications like secure shell or VNC. It's ideal for what most users are using the Internet for; music, social networking website, watching videos, and in many cases instant messaging and email (although for most users that is interchangeable). It's wildly popular, and by using a combination of management tools with web interfaces and applications from the app store an iPad, while not a general purpose computer, neatly fills a niche for accessing information on the go.

Smart phones can also access much of this information. My wife's phone can get directions, Google information, and reserve movie tickets. An iPad with Internet connectivity will probably have similar abilities, as can a small notebook computer at a wifi hotspot. Three different devices with similar abilities but targeted to different audiences and tailored to suit some tasks better than others by their nature.

In the end it's the goal that is important to users, not the means. Tech people like focusing on the means. We bitch about Microsoft Windows and how it's like drinking cyanide, or why MS Office is a pain and overpriced while OpenOffice is great (and vice-versa). We debate using webmail versus Outlook versus Thunderbird for reading email. But for the average end user, it doesn't matter; they just want to use the computer and write a letter and send an email, and as long as they can do it with minimum hassle, they don't care about the means used to do so. And they'll do it with an iPad, a $400 netbook, a $1,500 Macintosh or their cellphone.

All that matters is that they can get the task accomplished.

When schools and colleges and businesses have IT departments worrying about computer deployment and management, they should probably take a few minutes to step back and reframe their perspective. It's not a matter of getting computers for students or employees. It's a matter of enabling access to the information they need.

Subtle difference, but the implications are quite large once you see them.

Sunday, November 8, 2009

Documenting Configurations

I had an incident that reminded me of an aspect to system administration that we as system administrators don't often address.

It's a "dirty thought", the thing that ends up being on our minds without usually being said. An elephant in the room, if you will.

That thought is just how much of our jobs is to protect users from themselves.

I had a user call up to say their program wasn't working. I'll call it Widgetapp. She is the only one that uses Widgetapp. It's an older program (not extremely old, but about five years in age or so), and it's used to track a vital bit of data on a couple thousand of our users for HR purposes.

Since she's the only user that uses Widgetapp she is the only one with a PC that has the application installed.

I viewed her desktop and found that the program was opening a "sample database" meant for training purposes. Oh...no problem. I use File->open to open the other database with our live data.

I couldn't find it on her PC.

Hmm...this could be bad.

Her desktop doesn't have a backup agent of any sort on it; users are instructed to save all data to their home directories and the servers are then backed up regularly (when the backup server is double checked that it is working properly, that is). I looked at what kind of file the database was and started searching her PC for similar files. Nothing.

At this point I was getting irritated; I couldn't imagine why, if I've worked with this application before (it rarely needed fixing or alterations made) and the application allows you to specify a location for the database file, I wouldn't have stuck it onto the server.

I started looking for a backup of the database on the server used for her department. I hoped that there would be a database that was at most a few weeks old.

Instead I found an oddly named folder that had an uncompressed database file. I created a new folder just above that with a more obvious name (Widgetapp_database) and copied the suspicious contents to that folder then pointed the program to that database and opened it and then had the user check the database; her most recent entries were there!

From what I could piece together my suspicion that I had pointed the program to a database on the server (where it would be backed up regularly) was indeed what I had done. At some point when the company made an upgrade to Widgetapp they moved the folder (still on the server) to another location.

The user probably had a network issue or some other problem where she ended up pointing the program to a default "training" database on her local hard disk. She had no idea that data was actually residing on a shared folder so it was up to us to know this...and we didn't.

Lessons?

A) Keep application data centralized. Programs that don't allow you to point to network shares or UNC's or IP's of application servers are crap. Centralizing the data allows you to centralize your backup management.
B) Document your applications. Document your changes. Document your configurations. Document everything.
C) Users won't have a freakin' clue what you're talking about.

Our organization doesn't do a lot of documentation. We don't have the manpower to properly handle it, and it's a situation that isn't going to change in the near future.

We expect users with specialized software needs to keep track of certain things with those applications. Again, we're extremely shorthanded in our duties and so we make an unreasonable assumption that the user will take responsibility for applications they insist they need. In the end they don't. I consider this another elephant in the room...we know we're doing wrong by it but do it anyway. What normally ends up happening is we end up spinning our wheels for a time because we're re-learning how to use the application or figuring out how something was configured instead of having an up to date reference that spells it out. Then we end up sometimes creating a new method to work around the issue or fix the problem that counters what one of our coworkers initially did. Hilarity ensues if that other coworker is the next one called in to fix the next mess.


I guess the biggest fail here is lack of documentation. We are shorthanded so we take shortcuts. This means we don't keep track of changes made to systems, we're just starting to document procedures, and no work has gone into properly making documentation available (not just available as in collected in some tome on a shelf; available means being able to actually find the information you need, and that means leveraging a wiki or issue tracking database for the troubleshooters to use for getting user and system history and tracking configuration issues).

In this case there was a happy ending. The user's database was found and the application worked once again. The user was happy. And I re-discovered how the application was set up, so I managed to solve my puzzle of the day. The next time I may not be so lucky.

Thursday, November 5, 2009

Why Ask "Are You Sure?"

Joel Spolsky mentioned the question of why programmers bother having applications ask for confirmation from users before performing some task. He said that it seems to serve only one purpose; to make the user feel guilty.

The reasoning as I remember was that users, not being "computer people", don't know what to do when confronted with a confirmation. They don't care to know. They trust in the programmer...the "computer techie people"...to know what's best, so they just go ahead and confirm whatever it is that pops up.

So he said that the only reason to do it was to make them feel stupid. This way they confirm whatever it was that pops up, then find out it deleted something or did something they didn't mean to do, then know that they had the confirmation warning them not to do it and they said to do it anyway.

"Oh! I'm an idiot! I should have chosen something else!"

Personally I'm not sure that users feel stupid about making a mistake. They just blame the application, programmer, or "stupid computer". Maybe some feel like idiots, but I'm thinking they're not in the majority.

I hate those stupid confirmations. Users don't read confirmations or licenses or any of the "user friendly" crap that is thrown into Windows (do any tech people use the "friendly" control panel? I immediately switched to the old style while using XP).

I prefer having a straightforward set of tools that do what I want. Clear labeling for buttons, straightforward questions and queries that leave no ambiguity about what happens when you select yes or no (OS X is famous for eliminating a lot of the ambiguity from their selection dialogs), having a simple way to navigate the interface instead of five ways to accomplish one task...those are hallmarks of good design. Any roadblock you throw up in a workflow is a bad thing; users tend to not read them anyway! Even if they did, they claim they didn't understand it. So they just trust that the programmer selected sane defaults and click right through them.

I think this is what Mark Shuttleworth calls a papercut...little things that aren't bugs, per se, but added up create a bad user experience. It's a waste of bits and annoying as hell when you just want to get something done. I truly wish that there was a way to have an operating system that possessed an interface that doesn't try whatever it can do to get in your way with inane and worthless dialog boxes.

Is there any reason to have an "are you sure?" dialog box or other cutesy abstractions to the system? Maybe for things that are blatantly destructive (About to format volume C: in 10 seconds...), but other things...I'm not so sure. Anyone have experiences or opinions to share?