‹ BackHN Continuity

Thread

Google breaks promise to provide 10 years of updates to Chromebooks

355 points · 156 comments · speckx

  1. jezzamon · · focus · HN ↗
    Discussed a lot here: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49893653">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=49893653

    Seems to be more reasonable than this title suggests?

    Some comments: &quot;So they have introduced a major change and said any older Chromebooks bought going forward will only get 8. So its not a retrospective reduction for existing customers.&quot; (Edit: actually I think this comment is wrong, if you bought a Chromebook 1 year ago, you&#x27;d only get 9 years of ChromeOS updates)

    &quot;From my understanding of the article, it sounds like ChromeOS support is getting pared back for those devices, but the devices themselves should still be supported, albeit via a (planned but not yet in existence) migration path to GooglebookOS.&quot;

    1. hedora · · focus · HN ↗
      These devices are usually bought on contract, with lots of lock in.

      In particular, there are lots of schools getting screwed over financially. Maybe they’ll switch vendors, or use the money for education. Chromebook spending has a strong negative correlation with educational performance.

      As a parent, I am supposed to have control over my kids’ personal information, but the schools firehose all the most sensitive kids’ info they have to an unlawful marketing firm that I do not trust. How do I opt out?

      1. eitally · · focus · HN ↗
        Education contracts do not allow Google to use customer data for advertising.
        1. shevy-java · · focus · HN ↗
          But they still store the data.
          1. afavour · · focus · HN ↗
            Same goes for any third party service using Google Cloud. Google technically stores the data. They still can’t use it though.
            1. Forgeties79 · · focus · HN ↗
              “Can’t”
              1. freedomben · · focus · HN ↗
                Correct, &quot;can&#x27;t&quot;. Are you suggesting they secretly violate the contract and use the data anyway?
                1. stackghost · · focus · HN ↗
                  Would anyone be shocked if they did? Tech firms seem to be immune from the law.
                2. behringer · · focus · HN ↗
                  Remind me in 10 years when the story breaks.
                  1. wafflemaker · · focus · HN ↗
                    Hey ChatGPT, set a reminder for 2036 to tell me whether Google was found not to secretly violate TOS of School Chromebooks and use the data harvested from them to create value for it&#x27;s shareholders.
                3. luckydata · · focus · HN ↗
                  they do not. I don&#x27;t work there anymore and don&#x27;t have any particular goodwill towards the employer that laid me off last year but I can guarantee that any data related to the education sector is under extremely strict controls.
                4. paimapi · · focus · HN ↗
                  surely you can take two minutes out of your day and do basic websearches for privacy class actions and settlements

                  <a href="https:&#x2F;&#x2F;www.classaction.org&#x2F;news&#x2F;microsoft-collects-massive-amounts-of-info-from-k-12-students-without-parental-consent-class-action-lawsuit-claims" rel="nofollow">https:&#x2F;&#x2F;www.classaction.org&#x2F;news&#x2F;microsoft-collects-massive-...

                  <a href="https:&#x2F;&#x2F;www.k12dive.com&#x2F;news&#x2F;week-in-review-april-6-2026&#x2F;816649&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.k12dive.com&#x2F;news&#x2F;week-in-review-april-6-2026&#x2F;816...

                  <a href="https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;12&#x2F;ftc-takes-action-against-education-technology-provider-failing-secure-students-personal-data" rel="nofollow">https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;12&#x2F;...

                  <a href="https:&#x2F;&#x2F;www.reuters.com&#x2F;legal&#x2F;government&#x2F;journalists-sue-google-allegedly-using-their-voices-ai-training-2026-05-12&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reuters.com&#x2F;legal&#x2F;government&#x2F;journalists-sue-goo...

                  <a href="https:&#x2F;&#x2F;www.courthousenews.com&#x2F;google-settles-class-action-over-data-transfers-for-135-million&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.courthousenews.com&#x2F;google-settles-class-action-o...

                  1. eitally · · focus · HN ↗
                    None of those have anything to do with Google for Education contracts, and I hope you realize that.
                    1. [deleted] · · focus · HN ↗

                      [deleted]

                    2. Forgeties79 · · focus · HN ↗
                      I really do not understand how anyone can give Google the benefit of the doubt in 2026. They literally make the law. They only adhere to the law when it makes financial sense.
                5. 63stack · · focus · HN ↗
                  Yes
                6. arcanemachiner · · focus · HN ↗
                  After PRISM and Room 641A, anything is possible.
                  1. afavour · · focus · HN ↗
                    Right but stuff like PRISM is the government getting data. In this scenario “the government shouldn’t trust Google with data because it might end up in the hands of the government” doesn’t really make a lot of sense.
              2. afavour · · focus · HN ↗
                Legally they cannot, no. And sure, they could violate contracts and break data protection laws. But they’d be trading an enormous hit on their reputation, who knows how many hundreds of millions in educational contracts for, what, some basic demographic data on kids? Data they’ll almost certainly be able to get via other means once the kid becomes an adult?

                I don’t like Google’s involvement in education. I don’t like Google much at all. But we should still be able to examine this stuff rationally without devolving into conspiracy theories that don’t make logical sense.

                1. behringer · · focus · HN ↗
                  &quot;reputation&quot;
                  1. sulam · · focus · HN ↗
                    Honestly reputation isn&#x27;t the main concern if you&#x27;re in leadership there, although it is absolutely a concern. The main concern is having to do another consent decree with either the EU or the US government. Those are a complete pain in the ass.
              3. thebytefairy · · focus · HN ↗
                What is the point this comment is trying to make? We can say this for every SaaS company on the planet.
                1. Forgeties79 · · focus · HN ↗
                  No, because not every SaaS company is Google.
          2. seb1204 · · focus · HN ↗
            Until they turn 16 or 18.
          3. freedomben · · focus · HN ↗
            How do you propose they offer the contracted services like MDM, GSuite (email, Drive, etc) without storing any of the data?
            1. eitally · · focus · HN ↗
              That isn&#x27;t what the OP was alleging. Of course they store data -- encrypted both in transit and at rest, and you can even activate client side encryption (<a href="https:&#x2F;&#x2F;knowledge.workspace.google.com&#x2F;admin&#x2F;security&#x2F;about-client-side-encryption" rel="nofollow">https:&#x2F;&#x2F;knowledge.workspace.google.com&#x2F;admin&#x2F;security&#x2F;about-...) -- but that doesn&#x27;t mean they exfiltrate, use or share your data for their own purposes.

              They don&#x27;t, they never have, and they won&#x27;t (unless there is a blatant, illegal policy violation and lapse of controls internally). This is very similar to the controls and policies in place governing FedRAMP contracts or the control of PCI&#x2F;financial or HIPAA&#x2F;healthcare data.

        2. Scubabear68 · · focus · HN ↗
          Do you really think the engineering teams pour over those contracts when implementing new features?

          Every single time? I sincerely doubt it.

          Whatever logical business firewalls Google has between orgs for this kind of purpose seems pretty frail and thin from what I have seen reported.

          1. sulam · · focus · HN ↗
            This absolutely happens, there&#x27;s a set of teams whose job it is to make sure it happens every time a system is going to be handling customer data. It&#x27;s not left to the engineers to remember to do so.
          2. altmanaltman · · focus · HN ↗
            They don&#x27;t even need to know how to read the contract. But its not like engineers can ship whatever they want at a company the size of google.

            So my question is, what have you seen reported and what makes you doubt it?

          3. hn_go_brrrrr · · focus · HN ↗
            Tell me you&#x27;ve never worked at Google without telling me you&#x27;ve never worked at Google.

            There are a lot of complaints you can legitimately levy, but &quot;Google doesn&#x27;t have enough of a compliance org to ensure eng behaves.&quot; is not one of them.

          4. redwall_hp · · focus · HN ↗
            Yes, absolutely. Every microservice where I work is architecturally scrutinized by multiple groups over things like PCI, GDPR and SOX, with major features requiring review. And then third party auditors get to review stuff occasionally. PII is radioactive and PCI data is hard siloed.

            If you work at a company that deals with education or HIPAA stuff, there&#x27;s going to be even more of that.

            Presumably Google aren&#x27;t morons or criminals.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.