User reporting should still work even for ephemeral users |
|||||||||||
Issue descriptionReport is that user reporting is disabled for ephemeral users - this is not intentional and we should make this work. +kay in case she knows of some privacy-related reason why this behavior would be intentional.
,
Nov 7 2016
Sorry - I don't quite understand what this means "user reporting is disabled for ephemeral users." Can you help?
,
Nov 7 2016
When reporting is turned on, Chrome OS reports the last 10 users to sign in to the device, providing their email address if they are affiliated with the device owner, otherwise omitting their email address. But if the device owner has turned on the "ephemeral user" device policy, we currently don't send up any information about user logins.
,
Nov 7 2016
,
Nov 7 2016
,
Nov 7 2016
I don't know of any historical reasons. Will probably does but he doesn't work on this anymore. Tagging Dominic to see if he knows. And Greg to see if he has any input about whether this will be OK.
,
Nov 7 2016
Is the proposal that if "ephemeral user" device policy is enabled, 1) you send logins about email addresses that are affiliated with the device owner? 2) you send logins about anybody who walks up to the device and signs in? I'd be fine with 1.
,
Nov 8 2016
Proposal is #1 - so basically reporting behavior is identical (only report email addresses for affiliated users) regardless of whether ephemeral mode is active or not. Sounds like we're good to implement, then. Thanks!
,
Nov 15 2016
,
Nov 30 2016
,
Jan 2 2017
BTW, it seems that at least concerning the device policy, the behavior was known/intended: Currently, the Admin Interface section Device management > Chrome > Device Settings >..> Device User Tracking says: "Note: Users will not be tracked if the device is configured to erase all local user data." A similar remark is buried in https://support.google.com/chrome/a/answer/1375678?hl=en#devicestatereporting .
,
Jan 9 2017
OK, this is a feature request - handing off to David to track and decide if we ever want to move on this.
,
Mar 2 2017
,
May 17 2017
Can this please be re-visited? Our Chromebooks are used in a cart scenario (not 1:1), and if we have a device damaged, we have no way of knowing who logged into it because we cannot track user data. We cannot track user data because we have the setting to erase data after logout turned on. We have that feature turned on because in a cart setting, leaving that option turned off quickly fills the little 16 GB hard drive with user profiles. We're in a nasty catch-22 where the scenario where we would most need to track user data is the one where we explicitly cannot. It's maddening.
,
May 18 2017
Re comment #14, you can disable ephemeral mode and rely no Chrome OS automatic disk cleanup which is a much better user experience and admin experience. Ephemeral mode should only be used sparingly for very selective use cases. Can you please elaborate on why the default non-ephemeral behavior w/ disk cleanup does not work for you?
,
May 18 2017
When was the automatic disk cleanup implemented? When we first started using Chromebooks in late 2013, if we didn't have what you call "ephemeral mode" turned on, our Chromebooks turned into useless bricks after a couple of days because their disks were full of user profiles, so I'm guessing they didn't have an automatic disk cleanup mode at that time. We were unaware of any such feature having been implemented, so we never revisited the issue.
,
May 18 2017
Can you please turn off ephemeral and run through some scenarios in your school (e.g. start with a single cart) and confirm that the default behavior with auto-disk cleanup is working for you?
,
Nov 2 2017
,
Feb 14 2018
Hi dskaram@, just wanted to check if we have any time frame for this feature? We have quite a few customers who would want to have user reporting with ephemeral mode.
,
Feb 14 2018
+poromov@ FYI
,
Feb 14 2018
I believe that not reporting ephemeral users is very important for privacy reasons. Currently there are no other information about an ephemeral user that persists after user is signed out. Reporting the user will significantly change this guarantees. The ephemeral mode is built for the cases when privacy is important. If it's however important to know which users used the device, most likely ephemeral mode is misused in that case. So, the feature request is still on PM side to discuss with privacy team and customers and decide whether to move forward or close as WAI.
,
Feb 16 2018
From customers perspective, the problems is that users data have to persist on the device if they want to collect login information. Often, admin just need to know who last logged into a device, but do not necessarily want to retain the user's data on the device. It would extremely helpful if we can store Recent Users information and still delete local user data, especially for EDU customers.
,
Feb 19 2018
I don't see any issues with reporting user sessions. As mentioned comment #22, data privacy in ephemeral use is largely about local data security. Sergey, how much work would it be to ensure this data is reported for ephemeral users? Is this something we explictly block and can relax the restriction easily, or would this require a large change on the client? Will the server pick it up directly if the client supports it?
,
Aug 3
This bug has an owner, thus, it's been triaged. Changing status to "assigned".
,
Aug 23
|
|||||||||||
►
Sign in to add a comment |
|||||||||||
Comment 1 by atwilson@chromium.org
, Nov 4 2016Components: Privacy Enterprise
Owner: pmarko@chromium.org