Friday, April 23, 2010

McAfee and the 'false positive'

Note: Thoughts expressed here are mine alone. They may echo the thoughts of others, but I'm not publishing this on behalf of or in representation of anyone else.

Nearly everyone is aware of the issues of this week surrounding a problematic McAfee update. I could link hundreds of articles and I'm not sure anything else can be said that hasn't already been said. However, I suppose writing is therapeutic to some extent and I've had a few thoughts running through my mind as our school districts work to correct thousands of affected computers.

* Kudos to our school districts. They probably don't get enough credit as it is, but it's amazing to see how districts have massed on this problem and developed plans to touch thousands of machines. Their work is to be commended. These are dedicated workers who have given away countless hours (no overtime pay in a school district) to fix these machines. In addition, many CIOs made a tough spur-of-the-moment call to shut down every machine in their district. I'm not sure I could have made that call that quickly, being fearful that a false alarm would infuriate my user base. It was a courageous call and a correct one given the circumstances. I'm proud to work alongside our area school district technology staff members.

* The Internet records everything. McAfee's initial response was delayed and was out of touch with the difficult realities facing a good portion of their user base.
...a number of customers have incurred a false positive error due to this release. Corporations who kept a feature called “Scan Processes on Enable” in McAfee VirusScan Enterprise disabled, as it is by default, were not affected...
McAfee went out of the way to point out that it was a false positive and not a virus. The end result was the same and no one I talked to was concerned about whether the problem was a virus or a false positive. Also, later reports indicate that the "Scan Processes on Enable" is not disabled by default in all cases. The language here implies that, had a customer not changed the default settings, they wouldn't be in this predicament. There's an implication that it wasn't McAfee's fault.

We are not aware of significant impact on consumers. We believe that this incident has impacted less than one half of one percent of our consumer base and enterprise accounts globally...
There may be some funny math going on here. If I had 199 consumers with a single copy of the software that weren't affected and I also had one corporate account with 1000 machines that were impacted, I suppose one could say that "one half of one percent of customers" were impacted. However, that doesn't accurately state the percentage of machines affected and it certainly downplays the significance. Again, the focus seemed to be that the incident wasn't a major concern. To affected customers, it was. Also, it's worth noting that a machine that constantly reboots and will not function is a "significant impact" and it's very hard to believe that, upon this press release, these symptoms weren't known.

To be fair, subsequent responses have a different tone and the company definitely took the matter seriously. Initial reports indicated that support information was hard to find. At this time, there is a link on the McAfee launch page. I'm not sure when that appeared. The bottom line is that effective crisis management, as exemplified in the Tylenol situation in the 80's, involves swift and wide-reaching action if there's even a chance of devastating impact to users.

* What if it were a virus? - My final thought is that, had SVCHOST.EXE truly been infected, was this the proper response? Should the file have been quarantined, rendering the machine useless and unable to communicate with the network? It's hard to say, but I'm sure this is one of the areas that will be investigated moving forward.

Tuesday, April 6, 2010

Free books and courseware

I'm continually amazed at everything that can be found on the Internet. We've had discussions in the K-12 environment about shrinking textbook funds and have rhetorically asked if textbooks are needed with the wealth of materials online. Given some of these resources that are available from the higher education community and other free resources, I think it's only a matter of time before we see more K-12 entities work to deliver instruction without traditional textbooks. A list of resources:

Project Gutenberg - One of the early entries in the 'free books' genre. You can find 30,000 free books to download here (free because their copyright has expired).

MIT Open Courseware - Want to take a course at MIT? This may not get you access to the instructor, but many of the materials used in all sorts of undergraduate and graduate MIT courses can be found at this site.

Google Scholar - Ever wished your students would find and reference 'scholarly' resources when searching Google for various projects? How about trying this beta search engine that seeks to limit your searches to scholarly literature?

Good stuff!

Monday, April 5, 2010

OnGuard Online - good educational resources

Just a quick note to make everyone aware of some good material available fron OnGuard Online. This is a partnership between many federal and commercial resources. One of the items that's been viewed very positively by my districts is a pamphlet called "Net Cetera: Chatting With Kids About Being Online". The link takes you to the entire pamphlet and you can order free copies from bulkorder.ftc.com.

The Federal Trade Commission has its own YouTube channel. One of their videos is embedded below:

Tuesday, March 30, 2010

Zenoss - Open Source IT Management

One things I've told DTC/CIOs at various times is that they need a dashboard. When I reference a "dashboard", I'm thinking of some type of visual that indicates the health of the network and critical resources. At the state level, we have a map that shows every school district and depicts different colors depending on whether the district has lost connectivity or if all services are running.

Using a tool like Zenoss, districts can create their own network dashboard. I've linked to the open source version, though there is an enterprise version as well. This software has several popular open source products behind it, including RRDTool for graphing and MySQL as a database.

Zenoss uses SNMP and WMI to discover and monitor all types of network devices. With it, you can monitor services like HTTP. For critical servers, I could monitor free disk space as well as memory and processor utilization. I could use the WMI piece to allow me to monitor critical errors on servers.

There's a tutorial video on their community page. As with any monitoring tool, I'm sure that this would take some effort upon initial setup to get everything set for your particular devices and thresholds of interest. However, once you have it set up, this could be a very powerful management aid.

Note that it's Linux-based, so the pre-packaged downloads are for various flavors of Linux. If you have to run this via Windows, there is a VMWare virtual appliance that you could use in conjunction with VMWare Player to perhaps make it work for you.

Wednesday, March 24, 2010

Humorous PSAs on texting, feat. James Lipton

I've been doing some work on Digital Citizenship lately and, along the way, I've been searching online for useful public service announcements related to technology topics. Some are very professionally done, some are created by amateurs and there's a whole subculture of faux PSAs that are humorous for completely different reasons.

Today, I stumbled across this series of PSAs involving James Lipton. He hosts Inside the Actors Studio and I've seen him lampooned on Saturday Night Live. Mr. Lipton is probably most recognizable for his beard and his speech. He has used his most famous qualities in a series of public service announcements asking kids to "give it a ponder" before texting.

You may find these useful and, if not, I'd say you'll get at least one laugh.






Monday, March 22, 2010

Privacy and user rights - a few 'horror stories'

As our group discussed Acceptable Use Policies last week, someone suggested that it might be useful to have a few of the 'horror stories' to share with others. Sadly, they're very easy to find and I thought I'd take a moment to highlight three that I've heard about. Each of these highlight certain 'gray areas' surrounding a staff member's desire to gain some information. Students were put in precarious positions and, in each of these cases, lawsuits resulted. Some (if not all) of these cases are ongoing and any comments are not meant to pass judgment on any parties involved; rather, I'm simply highlighting the circumstances surrounding the situation and pointing out that today's use of technology requires us all to be knowledgeable and respectful of the rights of others...

* Quite recently, the Lower Merion School District in Pennsylvania was sued over the remote enabling of a webcam on a district-issued laptop computer. The case alleges that a student was disciplined at school with a webcam-based photograph (taken while the student was at home with the laptop) being used as evidence for the discipline. Privacy issues are being cited and there's some debate over who knew about the potential to remotely activate the webcams, how was this feature used, etc.

* A few years ago, cheerleaders at a high school in Pearl, MS were asked to relinquish their Facebook passwords to their cheering coach. One student did so and her private Facebook email was accessed. This information was shared with others in the district and the student was disciplined for some of the contents found. A lawsuit has been filed and this case will help determine whether school administrators have the right to request access to these private conversations.

* Closer to (my) home, a school district has been sued over the review of contents of a confiscated student cell phone. According to the suit, the phone slipped out of the student's pocket. Administrators read the content of text messages on the phone and the student was expelled. The lawsuit claims that this was an illegal search of private property.

Those are a few examples and I'm sure you can cite others as well. This shows the need we have as technology leaders to become more aware of district policies and lead be learning and educating our own staffs about what can and cannot be done as it pertains to these new technology devices and tools.

Thursday, March 18, 2010

Acceptable Use Policies - Broad or Specific

Our regional association of DTC/CIOs had an interesting discussion yesterday regarding Acceptable Use Policies. With the growing popularity of social networking sites such as Facebook and the increasing number of personally owned electronic computing devices (smartphones as well as more traditional computers), many districts feel the need to revisit their acceptable use policies. Let's spend a moment on this and, in particular, focus on the need for a broad policy versus a very specific one.

This is a Kentucky school district example of a broad policy. You won't find specific mentions of Facebook or personal computing devices in this AUP. That doesn't mean that the district doesn't deal with these issues. I suppose that's really the point I want to make - an Acceptable Use Policy is just that... a policy... and this district likely deals with any number of technology-related behavior issues via other behavior policies rather than specific technology policies.

This policy specifically says that there will be other procedures and guidelines. To quote various areas of the linked document:
shall develop and implement appropriate procedures to provide guidance for access to electronic media. Guidelines shall address teacher supervision of student computer use, ethical use of electronic media (including, but not limited to, the Internet, e-mail, and other District technological resources), and issues of privacy versus administrative review of electronic files and communications. In addition, guidelines shall prohibit utilization of networks for prohibited or illegal activities...
In our discussion, it was pointed out that most Kentucky school districts already have policy that addresses disruption of the educational process. One such policy is linked here. There are several areas of note, but students are subject to displinary action in these specific instances:
Conduct that materially or substantially interferes with another student’s access to educational opportunities or programs, including the ability to attend, participate in and benefit from instructional and extracurricular activities; or

Conduct that materially or substantially disrupts the delivery of instructional services or interferes with the orderly administration of the school and school-related activities or district operations.
If someone posts something offensive to a web site and it "materially or substantially interferes" as stated above, the school district has some latitude to deal with it. If a personal phone is "substantially disrupting the delivery of instructional services", then the district would have some latitude to deal with it. Certainly, these are sticky areas and I don't mean to minimize the potential for concern or the proper care that needs to be taken when dealing with issues related to technology-based behavior. My point here is that districts often have existing policy that can be applied to many of these situations. Often, we spend too much time trying to document and label the method of misbehavior when the better course may be to apply existing rules and regulations.