Tag Archive for AirWatch

LA Schools iPads Hacked In A Week

– UPDATE 08-28-2014 – Just in time for the start of School reports surface LAUSD is “re-opening” bids for its controversial billion-dollar contract with Apple and Pearson to give all students, teachers, and administrators iPads.

LA iPads Hacked In A WeekThe second-largest school district in the US is spending at least $1 Billion to complete a 1:1 tablet initiative. The Las Angles Unified School District (LAUSD) plans to deploy 650,000 Apple (AAPL) iPads, one for each student in LA county. The project slated to be completed by December 2014, has had problems that may prevent if from reaching that goal.

Las Angles Unified School DistrictThe project includes 500 million dollars for iPads and 500 million dollars for Wi-Fi and related infrastructure. The initiative is funded mostly by voter-approved school construction bonds, which taxpayers typically pay off over 25 years which the LA Times says “has sparked some concerns and legal and logistical hurdles.”  (rb- I first noted the project here)

The project has run into a series of issues. The first issue focused on the 25 year payback period on a $500.00 device. A second issue emerged in September 2013 when the district recognized that it may need to buy Bluetooth keyboards for the iPads. The LA Times estimated a bill of $38 million for the oversight. The LA Times reports that the included software keyboard on the iPad might not satisfy the needs of older students writing term papers.

650,000 Apple iPads,Also, LAUSD has planned to use the iPads for testing based on new Common Core English and math learning standards. The article contends that the iPad’s touch screen could frustrate students and even obscure portions of a test item that would be visible in its entirety on a full screen. (rb- I talked to many school districts about the SBAC keyboard testing issue, who is going to configure Bluetooth on and off? What about power? Does Bluetooth decrease the battery time on the iPad? Do you have enough electrical outlets to plug in 30 iPads? How is your Wi-Fi?)

In late September 2013, the LAUSD iPad project ran into a bigger problem as they deployed the iPads to high school students. According to the LA Times, it took exactly one week for nearly 300 students at Theodore Roosevelt High School to defeat the LAUSD installed device security. Following the news that students were using the hacked tablets for personal use, district officials halted home use of the Apple tablets until further notice.

Common Core English and math learning standards.Students told the LA Times once they had the iPad home they could not do anything with the $678 device. Apparently, the students began to tinker with the security lock on the tablets and soon discovered all they had to do was delete their personal profile information. With the profile deleted, a student was free to surf, tweet like, and stream music.

The new found freedom prompted L.A. Unified School District Police Chief Steven Zipperman to suggest that the district might want to delay the distribution of the devices. The chief said in a memo obtained by the LA Times, I want to prevent a ‘runaway train‘ scenario when we may have the ability to put a hold on the roll-out.

I want to prevent a 'runaway train' scenarioAccording to a March 2013 blog post from Roosevelt HS, LAUSD chose AirWatch as the provider for the mobile device management system. And that when students first get their iPads they will have AirWatch already installed. The district posted an update on their website that indicated they have turned to AirWatch and Apple for better solutions to their iPad problem.

rb-

This really is a story of mismanagement from the top down. A billion-dollar project for consumer devices financed over 25 years – Really? Are the students of LA’s class of 2038 going to have to use the iPad’s from 2013? Where is the refresh program? How are they getting the money to buy 650,000 iPad 9’s in 5 or 6 years?

If the iPads are to be used at home? how is LAUSD addressing the digital divide in LA?

Did the big-wigs consider the equity of using iPads for high-stakes nationwide common core testing? Not only will LA students be compared against each other and the rest of California but also students in 44 other states.  It is my understanding that the current SBAC test is not optimized to display well on small screens. Will the tablet form factor handicap LA students or others across the US using tablets when competing against others using large screens and real keyboards in ergonomically proper positions? Will LAUSD show the test takers how to see the entire question, or how to easily switch between back and forth between screens to review a passage and then write a response.

Call me cynical after working in K-12 and living in the Detroit area, but a public $1 Billion dollar government project seems like a magnet for mismanagement, fraud, waste, and pay-to-play scams. It already seems to be at least $20 million over budget to buy keyboards even at K-12 discounts. Hopefully, the iOS and AirWatch updates are already included in the existing contracts.

While the headline-grabbing hacking story may be resolved in Apple’s iOS7. AFAIK Apple does not let anybody into its BIOS or whatever chip it is on an iPad. That is why students can easily delete the AirWatch agent. LAUSD still has a task on its hands to get all the deployed devices up to iOS 7.

LAUSD is missing 71 iPadsIn more signs of mismanagement, The LA Times reports that LAUSD is missing 71 iPads. They deployed 69 of the missing iPads last year at the Valley Academy of Arts and Science. PadGadget reports that after the fact, the District ramped up its tracking efforts by adding stronger safeguards. Global positioning can now be activated for every tablet. Plus, an electronic inventory system registers who is now responsible for a particular device, and District officials can remotely shut down iPads reported stolen.  Lt. Jose Santome of the school district’s Police Department stated, “We know what’s going out and deployed on every campus.”

Related articles

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.

BYOD Love Affair Waning?

BYOD Love Affair Waning?Tom Kaneshige at CIO.com warns that the “Bring Your Own Device” love affair is coming to an abrupt and bitter end, and the lawyers are circling. He argues that in the early days of BYOD, say, last year, employees, especially Millennials, fell madly in love with the idea of using their own Apple (AAPL) iPhones, Google (GOOG) Android smartphones, and newfangled tablets for work. Finally, they could finally ditch corporate-issued BlackBerrys (BBRY).

Bring your own deviceBYOD ushered in a new era of consumer tech in the enterprise, one that promised employees and employers will live happily ever after. But the BYOD romance has suddenly turned sour. Employees are questioning corporate intrusion on their personal devices. Did IT turn their beloved smartphone into a spy that tracks their whereabouts? The article says employees are beginning to sense companies taking advantage of BYOD by intruding on personal time to get free work time.

Now they’re thinking about suing. John Marshall, CEO at AirWatch, an enterprise mobile device management (MDM) vendor with 6,500 customers, told CIO, I anticipate a bunch of little [lawsuits], then something big will happen that’ll be a class action and become headline news.

Air Watch logoCEO Marshall reports that the suits have already started. A federal case in Chicago is winding its way through the courts which claims that the city owes some 200 police officers millions of dollars in overtime back pay. The case centers on allegations that the city pressured officers into answering work-related calls and emails over department-issued BlackBerrys during off-hours.

There’s no question BYOD blurs the line even more between work life and personal life. The Airwatch CEO not surprisingly recommends a Mobile Device Management (MDM) application to control email delivery to BYOD devices. This way an employer can set a business rule that won’t allow delivery of corporate email to a subset of users during off-hours. Or a CIO can address this issue in the BYOD terms-of-use agreement. (rb– Both would be best)

Smashed BYODThe CIO article offers up another legal nightmare scenario: Lacking MDM tools to block out what can and cannot be seen on a BYOD smartphone, a help desk technician notices that an employee’s device has a lot of personal apps about a health problem—and mentions his concern to the employee in the cafeteria.

The employee can say, ‘How in the world did you know that?‘” Mr. Marshall says. “All of a sudden, something that’s very benign and innocuous turns into something that’s blown out of proportion.” (rb- Help Net Security cites recent U.S. DHSS seven-figure settlements from healthcare institutions that failed to protect patients’ health information under HIPAA regs.)

terms-of-use agreementMr. Marshall recommends a comprehensive BYOD terms-of-use agreement, along with transparency about the capabilities and limitations of the technology, will help ward off such scenarios. The IT staff also needs to be educated about their role in a BYOD environment.

However, this doesn’t mean problems won’t crop up. Part of the problem, the article indicates, is that BYOD often puts business unit managers who aren’t well-versed in technical user agreements in a leadership position with mobile apps. They’re likely to give the green light to rogue mobile apps that violate such agreements.

location-based servicesFor instance, employees are chiefly concerned about privacy and especially location-based services with BYOD, and so many user agreements stipulate that apps will not collect location-based information. But someone who wants to be helpful, builds a map app for the corporate campus that allows employees to schedule conference rooms and find safety information, such as where to go if there’s a tornado. Airwatch’s Marshall explains:

Maybe there’s also a button on there that says where you are in the campus … All of a sudden people wake up and realize that every single device using that app is collecting location-based information—that’s an issue. These are really plausible scenarios … There’s so much copy and paste and reuse of all these components that these things can happen very innocently.

remote wipeThen there’s the dreaded remote wipe, which can land a company in some legal hot water according to the article. Help Net Security says there is little to no case law in this area. CIO.com reports that just last year, CIOs said they felt comfortable with BYOD because they held security’s holy grail: remote wipe, a scorched-earth capability for wiping all data on a mobile device.

But employees weren’t happy with the idea that the company can wipe personal data on their personal device. Some employees refused to take part in the BYOD program for this reason. Others waited days or weeks before reporting a lost or stolen device so that IT wouldn’t wipe it.

waited days or weeks before reporting a lost or stolen deviceMDM software advanced quickly and seemed to come up with a fix. Now companies can wipe only corporate apps from a BYOD smartphone or tablet, leaving personal apps untouched. In fact, AirWatch won’t even allow a full device wipe anymore for legal reasons. While this helps tremendously, it doesn’t completely solve the problem.

Mr. Marshall proposed a scenario where a company buys the popular productivity app, Evernote, for employees to put on their BYOD smartphones. Since the company paid for the app, the company can remove it at any time. The note-taking app collects company data but also might store personal data, too. An employee can use Evernote to create a shopping list, recipes, vacation plans, or perhaps something more critical to their job.

Finger pointingGuess what happens to this personal data when the employee leaves the company? The app, along with all the data, is wiped from the device and account. If the BYOD terms-of-use agreement about Evernote wasn’t spelled out clearly, who is liable for the lost data?

The bloom is off the BYOD rose, and so companies had better add protections against employee lawsuits in the BYOD terms-of-use agreement and leverage MDM to make sure the agreement is followed.

Truth is, employees tend to get a bit emotional when their privacy is violated or their location is tracked via a mobile device that they personally own. They don’t like their personal data to be wiped, either. When these things happen, companies can expect the wrath of a scorned employee. “That’s where it gets tricky,” Mr. Marshall told CIO.com.

Tony Busseri, CEO of Canadian digital security firm Route1, told Help Net Security:

Angry BossAlong with security concerns, BYOD has brought the potential of major legal issues for the Enterprise … Many current BYOD corporate policies leave enterprise data unprotected in the event of a security breach and during an employee’s exit from the company. The policy of tracking and wiping an employee’s personal device opens the enterprise up to the potential for mass litigation.

rb-

Misco in the UK reported that the majority of employees will not cooperate with employers’ BYOD efforts. According to the data:

  • 82% of the survey participants viewed their employer’s ability to track their location as an invasion of privacy;
  • 82% are concerned or extremely concerned about having their browsing history monitored;
  • 76% stated that they would not allow their company to view the applications installed on their personal mobile devices;
  • 75% said they would not go along with an installation made by their employer;
  • Only 15% had no concerns about employers tracking activities.

 

Ralph Bach has been in IT long enough to know better and has blogged from his Bach Seat about IT, careers, and anything else that catches his attention since 2005. You can follow him on LinkedInFacebook, and Twitter. Email the Bach Seat here.