Virus Eats School District's Homework
theodp writes "Forget about 'snow days' — the kids in the Lake Washington School District could probably use a few 'virus days.' Laptops issued to each student in grades 6-12 were supposed to accelerate learning ('Schools that piloted the laptops found that students stayed engaged nad [sic] organized whiel [sic] boosting creativity,' according to the district's Success Stories), but GeekWire reports that a computer virus caused havoc for the district as it worked its way through the Windows 7 computers, disrupting class and costing the district money — five temporary IT staff members were hired to help contain the virus. Among the reasons cited for the school district's choice of PCs over Macs were the proximity to Microsoft HQ (Redmond is in the district), Microsoft's involvement in supporting local and national education, and last but not least, cost. In the past, the Lake Washington School District served as a Poster Child of sorts for Microsoft's Trustworthy Computing Group."
Looks like the school district leaned a valuable lesson ... oh wait!
There once was this thing, the "trustworty computing" pledge.
What happened to that?
Help stamp out iliturcy.
Among the reasons cited for the school district's choice of PCs over Mac's were (...) cost.
And yet Linux was never an option? Avoided Apple to reduce the cost and ended up hiring 5 people to contain the damage that came as a consequence of their choice... way to go!
...and last but not least, cost.
Wait...Windows 7-Ready hardware, Windows 7 Licensing Costs AND 5 additional IT-employees and they choose Microsoft because "it costs less"?! I seriously need to get a job in the public sector, seems like they can jack off all day or something.
Just imagine how many new IT jobs this would create.
http://en.wikipedia.org/wiki/Sic
Among other things, TFA implies that this is because they were using 'PCs instead of Macs' [sic].
While it's true that OSX has way less malware than Windows, the main cause of malware infections is the users who click anything that's offered to them without thinking.
You can hide behind less popular operating systems, but the sad truth is that the average computer user simply can't handle the freedom of being able to do whatever they want, without messing things up.
So the solution is better tech education or--the cheaper way--locking things down. Both MS and Apple are doing it in their mobile OSs and they're starting to implement this in their desktop OSs as well.
Of course, the IT could also have locked Windows down with Group Policy and SRP, so that it would be pretty much impossible to install anything (unless reinstalling the OS).
Instead, they relied on some crappy antivirus (Sophos) and I wouldn't be surprised if the users were given admin rights as well.
I'm not a Microsoft fan at all (and they might have played dirty to get the school to use Windows), but the real story here is IT staff incompetence and the poor education of the average computer user.
Viruses are easy to take out of the system, but that doesn't stop the same behavior that puts the virus there in the first place.
Example: A friend of mine I end up fixing his laptop for viruses usually gets them because his kids are looking for TV shows and gets sent to sites that want them to download something. Boom, infected. Looking for a youtube/Disney/Hulu video downloading, boom! Infected.
I don't care too much because I get paid. And getting rid of the viruses/whatever is as easy as taking the harddrive out of the computer and hooking it to an already running computer (via usb-ide/sata adaptor), and run a few programs. Takes a few hours, or more depending on the size of the harddrive and how much space is taken up. But very, very easy to fix.
Be seeing you...
Hire COMPETENT IT staff to begin with? Honestly, what kind of amateur hour school is this? having to hire temp IT staff to deal with it, really? how about actually staffing your departments properly and with competent staff?
Do not look at laser with remaining good eye.
There used to be this expression "no-one ever got fired for buying IBM". Buy IBM, and you're safe; if it still breaks you can always say "well I went with what everybody does, what is generally considered a good choice, so I did the best I could". By buying some no-name brand, or brandless hardware, you don't have this excuse. Then it's instantly your responsibility.
Same for Microsoft vs Linux. Linux is "that hacker platform" while Windows is "what all businesses use". It's the safe choice - from a job security pov. We know Linux is statistically more stable and secure than Windows, but if it goes wrong, it's the fault of the guy going for the alternative, off the beaten track, and insisting of going against what the rest of the world does.
Or for the obligatory car analogy: Linux is the self-driving car that reacts faster, is more alert, won't speed, stops for red lights, and has a perfect accident record, while Windows is the human driven car. When one of the human drivers has yet another accident, that's too bad, humans aren't perfect. When the self-driving car has an accident, that's a disaster, totally unacceptable and why isn't there a human at the wheel paying attention to correct those mistakes.
Before we blame the IT staff, let me give this some perspective. (I have nine years experience as a teacher & tech director in a public K-12 US school.)
First, I'm reasonably confident in saying that, if proper Group Policy was implemented and user restrictions put in place, this never would have happened. Second, this is a HUGE school district with over 50 schools. They can certainly afford a public liaison (who was speaking on behalf of the district in the local broadcast), and I'm sure they have a large IT staff...I'm guessing in the neighborhood of 20-30 employees. Though public school districts would pay less than Microsoft right next door, given the sheer numbers there must be at least a few people on that staff that know how to accomplish this and as well of its value in preventing this sort of mess from happening.
With that in mind, here's what I've concluded: There is likely someone with leadership authority who told IT staff to let students manage their own laptops and have admin privileges. Given the size of the district, the directive either came from the district technology committee, or directly from the superintendent, school board, or both. All it would take is a number of parents to ignorantly complain to a "friend on the board" that "Johnny's laptop is broken - he can't install the programs he needs to do his homework" for the school board to direct the superintendent to "fix the issue." Likely this was a top-down order; I simply cannot imagine a tech staff that large to be that incompetent on their own.
What bothers me about this is how they're going about trying to fix the problem. If I had a worst-case mass-deployment of a virus at my school, I would just recall all the equipment, reimage everything, and redeploy a week later. I would issue a directive to all the staff that the equipment is down for one week to be cleaned, and make due without it. It's either one week of downtime or months of unreliability. If teachers would know that they have the option of either the problem being fixed in a week or the problem being "managed" over months, they would all take the week's downtime in a heartbeat.
One other question I have for those here: have you ever encountered a Windows virus that, as they claim, just "spreads on the network" without user initiation of the virus by clicking on an executable, script, or loading an infected webpage? I think the much more likely scenario is that this virus is being spread through usb flash disks, but I'm not sure whether that explanation was too technical for staff to understand.
Keep your voice down and we can have a conversation.
Issue #1: The user should be taught how to keep their system clean. Doesn't matter whether it is Linux, Windows or OSX. So they handed out devices without any restriction imposed on the user, the user who is a kid, and is supposed to be restricted they have enough knowledge to be responsible for their own computer-like devices. For the same reason, people having a driver instructor while driving for a while, pass an exam, and only after that they are allowed to drive their own, or other people's car.
Issue #2: All major existing operating system today is capable to restrict the user's actions if they are set up correctly. Now the commercial OSes, like Windows and OSX are advertised as an out-of-the-box solution, and thus people think that they are ready to be deployed in virtually any situations. In practice however, it turns out that when it comes to managing a bunch of devices for predefined goals apart from having fun with personal computing at home, you need a competent administrator or administrator team to handle the set up and the maintenance. Customer support just doesn't cut it for this reason. They off site, and slowly responding, and they don't really know what are the exact requirements for their installation. CS could be handy perhaps in individual cases, where the user works within its competence, but any organization working with computers regularly (as I deduced from the article, the whole point of giving out laptops is to get the education system computerized) need competent maintainer.
Windows isn't really more vulnerable to viruses than OSX in a competent hand, and Linux is just as much stable as any of the commercial operating systems if maintained by skilled administrator. And an competent system administrator would be completely aware of the fact that children are not the most trustworthy users when it comes to downloading and executing software from unknown sources.
So, in my opinion what the school board/administration did is cuting corners on their computer staff, or hired incompetent, unskilled cheap labour for the position. Either way, it isn't really the OS that really matters, it is the person who keeps it running.
You were the last compentent person to touch their system. The only one who knew how to make changes. They know they changed nothing. How could this problem exist, it requires a change to have been made?
Computer Voo Doo. It has to be the change you made 2 years ago that caused the virus today.
Ah, Voo Doo, I know thee well. Many of my customers have claimed I have practiced the art.
vi +