HN user

edtechstrats

351 karma

@douglevin @k12cybermap @k12six

Posts40
Comments16
View on HN
www.wfaa.com 4y ago

The masterminds behind last year’s Dallas ISD breach: it’s not who you think

edtechstrats
2pts0
themarkup.org 4y ago

Help [the MarkUp] Investigate the Ed Tech Industry

edtechstrats
1pts0
www.governor.ny.gov 5y ago

NY Enacts Law Suspending Use, Directing Study of Facial Recognition in Schools

edtechstrats
2pts0
stpp.fordschool.umich.edu 5y ago

Cameras in the Classroom: Facial Recognition Technology in Schools (2020)

edtechstrats
1pts0
www.consumerreports.org 5y ago

The College Board Is Sharing Student Data Once Again

edtechstrats
1pts0
medium.com 6y ago

Backlash forces UCLA to abandon plans for facial recognition on campus

edtechstrats
2pts0
www.lockportjournal.com 6y ago

In fight over facial recognition, district pleads its case on Today Show

edtechstrats
1pts2
www.propublica.org 6y ago

Insurance Companies Are Fueling a Rise in Ransomware Attacks

edtechstrats
1pts0
k12cybersecure.com 6y ago

LA Governor Declares 'State of Emergency' Due to School Cyber Incidents

edtechstrats
1pts0
www.washingtonpost.com 7y ago

Cyberattacks inflict deep harm at technology-rich schools

edtechstrats
1pts0
apnews.com 7y ago

Wi-Fi helped ID teens who drew racist, anti-Semitic graffiti

edtechstrats
15pts2
www.buzzfeednews.com 7y ago

A NY School District Defies State, Plans To Proceed With Facial Recognition Test

edtechstrats
98pts57
www.edweek.org 7y ago

Schools Are Deploying Digital Surveillance Systems

edtechstrats
2pts1
wjla.com 7y ago

Uber, Lyft drivers manipulate fares at DCA causing artificial price surges

edtechstrats
252pts290
creativecommons.org 7y ago

Creative Commons statement on shared images in facial recognition AI

edtechstrats
3pts0
www.edsurge.com 7y ago

A New Cybersecurity Incident Strikes K-12 Schools Nearly Every 3 Days

edtechstrats
2pts0
www.insidehighered.com 7y ago

A Class Registration Bot Backfires

edtechstrats
1pts0
www.edweek.org 7y ago

They Hacked Their School District When They Were 12

edtechstrats
5pts0
www.nytimes.com 7y ago

Google Is Teaching Children How to Act Online. Is It the Best Role Model?

edtechstrats
6pts0
thenextweb.com 7y ago

Florida is testing driverless school shuttles – what could go wrong?

edtechstrats
2pts0
www.edsurge.com 7y ago

When 12-Year-Olds Can Breach School IT Systems, Who’s Responsible?

edtechstrats
2pts0
k12cybersecure.com 7y ago

Like Moths to a Flame: Students Hacking Their Schools

edtechstrats
2pts0
www.nytimes.com 7y ago

The Information on School Websites Is Not as Safe as You Think

edtechstrats
1pts0
www.nyclu.org 8y ago

Facial Recognition Cameras Do Not Belong in Schools

edtechstrats
171pts107
www.edtechstrategies.com 8y ago

Scholastic Makes Misleading Privacy/Security Claims in Svcs Directed to Children

edtechstrats
2pts0
www.edweek.org 8y ago

Student Hackings Highlight Weak K-12 Cybersecurity

edtechstrats
3pts0
www.edweek.org 8y ago

How (and Why) Ed-Tech Companies Are Tracking Students' Feelings

edtechstrats
2pts1
www.scmagazine.com 8y ago

Cyberattack map shows impacted U.S. school districts

edtechstrats
2pts0
blogs.edweek.org 8y ago

Without prior consent, Pearson tested social-psychological messages on students

edtechstrats
2pts0
www.edtechstrategies.com 8y ago

School Websites Are Bad, Just Not How You Think

edtechstrats
1pts0

I track US public school cybersecurity incidents and this represents a change in tack for ransomware attackers vis-a-vis schools. Clark County (Las Vegas) is only 1 of 3 school districts since the start of the school year compromised with ransomware alongside the exfilitration of student/employee data. The others include Fairfax County (VA) and Haywood County (NC). Overall, I count 35 instances of ransomware (K-12 districts) for all of 2020; 15 of those publicly disclosed since August 1, 2020.

https://k12cybersecure.com/map

PS The latest incident, with commentary from the district superintendent: "Got to work this morning, powered up my computer and the first message I got was you’ve been encrypted. Basically, you know, the same old thing…you’ll have to pay us in bitcoin, we’re holding your data ransom, you need to contact this email address."

https://www.kalb.com/2020/10/02/cyber-incident-affects-avoye...

They left Wi-Fi enabled on their cell phones, which automatically connected to the school network when within range. IT staff then associated the log-ins with individual students - allowing them to be identified and caught. Original article (via Washington Post): "A black principal, four white teens and the ‘senior prank’ that became a hate crime"

URL: https://www.washingtonpost.com/graphics/2019/local/teen-graf...

They boys are clearly tech-savvy to a degree (they build their own PCs, mined crypto, understood Windows user permissions, etc.), but I seriously doubt that they would or could have broken into the district's systems without two things: 1/ an admin password left on a sticky note and 2/ clear text storage of other user passwords in an excel file published in a shared folder on the first machine they accessed (a public machine in the middle school library!). Other issues: old user accounts left still active; no review of access logs or logs of server usage (which would have spotted Monero mining). Note: the boys reported that passwords on sticky notes was routine throughout the district (and how they got access to the security cameras, too).

Unlike how other instructional materials are adopted by schools, educational software operates in secrecy - it remains essentially a black box to educators, parents, and students. There is no mechanism for independent reviews/audits of content or code, no insight into the instructional approach, checks for factual accuracy, or evaluations of potential bias.

The money quote (for me): “That sounds like a low bar [that their apps did not harm students’ educational results],” Ms. Woolley-Wilson said. “But with the history of education technology, it is not.”

So, some of this is about mode, input. But, a big factor in Chromebook adoption in schools has to do with the ease of enterprise deployment and management. Apple is far behind the curve here, and the amount of work to manage a school/class deployment (esp in the early days) was huge.

It is important that we address the need for changes to student data privacy/security policy and practice based on rigorous, replicable analysis and methods. The analysis underlying EFF's latest report, however, may not meet that standard. Important that the question has been called by EFF; more work clearly needs to be done to sort out the school technology ecosystem.

In many cases, these are minors. A criminal record will be a black cloud over their future educational and employment opportunities - and could negatively effect their life course. Perhaps they fully understand the consequences of their actions? Perhaps schools and law enforcement have the capacity to be nuanced in their actions? Based on my work on these issues, I question both premises.