Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Tuesday, May 12, 2020

SECOND GRADER HACKS SYSTEM, SHOWS KIDS HOW TO ACCESS ANY STUDENT ACCOUNT

BOCA RATON, FL (BocaNewsNow.com) — The Palm Beach County School District is in the midst of a massive computer security crisis that draws into question the authenticity of every assignment completed by every student since “distance learning” began, after BocaNewsNow.com learned that an elementary school student hacked the school district’s password system.

We are not revealing the password convention that is used in the school district, but the second grader’s — you are reading that correctly, the second grader’s — hacking resulted in an emergency login change for “live” morning meetings in several elementary schools last week. It did not result — yet — in a district-wide reassignment of student passwords for the School District’s “Portal” which provides access to Google Classroom.
It is unclear if teachers and administrators were aware that the second grader’s hack potentially impacted the entire 176,000 student school district...

Tuesday, July 16, 2019

Maryland says confidential data must be encrypted. For 1.4 million students, it wasn’t.

“Sensitive, personally identifiable information” of more than 1.4 million students and more than 200,000 teachers was improperly stored by the Maryland State Department of Education, leaving them at risk of identity theft, according to a recent audit.
The review found that the department stored the names and Social Security numbers of students and teachers “in clear text,” even though Maryland’s information security policy calls for confidential data to be protected using encryption or some other “substantial” mitigating controls.
The personal information did not appear, as of June 2018, to be adequately protected by data-loss prevention software.
“Appropriate information system security controls need to exist to ensure that this information is safeguarded and not improperly disclosed,” said the audit, which was published earlier this month.
The report on deficiencies in the state network were released as governments and private entities are working to protect their computer networks and databases from bad actors. The state of Maryland reported earlier this month that hackers accessed the names and Social Security numbers of as many as 78,000 people from two older databases run by the state Department of Labor. The information, accessed in April, belonged to people who received unemployment benefits in 2012 or sought a general equivalency diploma in 2009, 2010 or 2014.
The July 2 audit of the education department found that the state did not have assurances that student data managed by third-party contractors was properly stored. The department also lacked a “complete information technology disaster recovery plan” or sufficient malware protection to provide “adequate assurance that its computers were properly protected,” according to the review...

Monday, June 10, 2019

The Baltimore Post Exclusive: Massive Security Flaw Detected on Baltimore County Schools’ Digital Platform, Exposing Highly Sensitive Information on Students and Staff Members

A massive security flaw has been detected that allowed unrestricted access to highly sensitive records pertaining to students, staff and internal school system data on a Baltimore County Public Schools (BCPS) public facing website.  
A tool within the system’s BCPS One portal platform, where students are able to access classes, grades and academic resources online, is the source of the breach where anyone with a password – including students, parents, and staff members – have had access to others’ personal student and staff member information, as well as some sensitive school system records.
Some records found go back to the 2008-2009 school year.
It is unknown how long the records have been open to thousands of students and employees and whether there was a larger scale breach of the data.
The Baltimore Post reached out to an information technology contact at Baltimore County schools on Wednesday night prior to publishing this story.  The contact confirmed that the error stemmed from a “share all” function on Microsoft Office 365 and a search bar that permitted any user to search for any subject – without restriction. Microsoft and the district have since fixed the error and are working to identify other areas of concern on the platform...

Wednesday, February 14, 2018

Silver Chips: Blocking usage of personal Gmail accounts limits what students can do with learning tools

As technology becomes a more essential part of our education and lives, certain security precautions taken by MCPS have begun to limit the range of what students can accomplish with the free technology they are provided at school.

In September of last year, MCPS decided to block the 'accounts.google' page on Chromebooks, preventing students from signing into any other email account other than those issued by the school. The laptops are powered by Google Chrome OS, and function only with internet access. 

The blocked page has become a hassle for many students. When they complete work at home on their personal accounts, switching from one to the other is nearly impossible to do at school.

MCPS Chief Security Officer Peter Cevenini explained that the blocking of the page was done to protect students. "We're always looking to tighten up our security. We're trying to lock things down. Your normal student email account is a closed system so that you can only email teachers and fellow students in Montgomery County and that's a protection practice,” he explained...

http://silverchips.mbhs.edu/story/13708

Monday, July 11, 2016

MoCo 911 outage another sign of growth outpacing i...

Robert Dyer @ Bethesda Row: MoCo 911 outage another sign of growth outpacing i...: The failure of Montgomery County's 911 emergency system last night and early this morning is another indication that infrastructure i...
...And a damning 2016 State of Maryland audit of Montgomery County Public Schools uncovered a staggering number of cybersecurity weaknesses, leaving student information easily accessible to hackers. Cyber intruders, the audit revealed, could access "any destination on the MCPS network." Eighty-six business partners of the school system improperly have "network-level access to the entire MCPS network." And the installed version of the database holding student information hasn't been supported by its developer since January 2012. Oh, and did I mention that 75% of the workstations tested by auditors didn't have the current security updates downloaded?...

Thursday, May 21, 2015

Pearson Blames 'Third Party' Attack for Disrupting Minnesota Online Tests

Minnesota halted its state assessments in science on Wednesday and Thursday due to a lack of confidence "that Pearson's system will operate smoothly," Education Commissioner Brenda Cassellius announced.
For the second time this testing season, Minnesota's assessments were disrupted by a "distributed denial-of-service attack," and Pearson, the global education company that designed and is administering the state's tests, told state officials that this was a larger and more sophisticated attack than one that occurred on April 21.
"It is simply unacceptable and unfair to subject students and teachers to this kind of uncertainty in a high-stakes testing environment," Cassellius said in a statement"I have questions about Pearson's ability to follow through on their assurances." The company holds a three-year contract, valued at $33.8 million, to administer Minnesota's reading, math and science proficiency tests. 
Pearson also released a statement, saying the company had worked throughout the day on Wednesday to mitigate what it described as malicious third-party attacks, in an effort to "minimize the disruptions and return service to normal." The company also said it is actively working to "strengthen our defenses to fend off these attacks," and assured the state that student data was not targeted, or at risk.

http://blogs.edweek.org/edweek/marketplacek12/2015/05/pearson_blames_third_party_attack_for_disrupting_minnesota_online_tests.html

Friday, December 12, 2014

5 PM on a Friday: Why do MCPS computers permit these sites to be viewed?

From: "KINGSVIEW MIDDLE SCHOOL"
Date: Dec 12, 2014 4:49 PM
Subject: December 12th Incident

A message from KINGSVIEW MIDDLE SCHOOL

Dear Parents and Guardians:

I am writing to inform you of an incident that occurred during school today. This morning multiple students reported that a substitute teacher had looked at inappropriate material on the computer while students were in class. The substitute teacher was covering Ms. XXXXXX's classes yesterday and today.

As a result of this report, we immediately removed the substitute teacher from the classroom, and we are working with the MCPS Office of Technology to investigate the situation. During the investigation, the substitute teacher will not be returning to Kingsview Middle School. I am very proud of the students who reported this information, and it underscores the importance of ensuring that our students know to tell a staff member immediately if they see or hear anything of concern.

Thank you for your continuing support. If you have any questions or concerns, please do not hesitate to contact me at 301-601-4611.

Sincerely,

Jimmy D'Andrea
Principal

Wednesday, December 8, 2010

How to Search for a Superintendent of Schools

This past Tuesday, December 7, 2010, MoCo's Board of Education hired Hazard, Young, Attea & Associates (HYA) to assist in its search for the next Superintendent of Schools.  As stated in the press release:  


 HYA was chosen from among six search firms that responded to the Board’s Request for Proposals (RFP) in September. The Board unanimously approved a contract for $35,000 plus expenses with HYA during its December 7 meeting. 

  “Hazard, Young, Attea & Associates has 20 years of experience and has participated in over 800 superintendent searches, many for large districts like ours,” said Christopher Barclay, president of the Board of Education. “They have the knowledge and experience to help us attract the strongest pool of qualified candidates and to fully engage all facets of the community in the search process.” 

. . . 
  The Board will be meeting with HYA very soon to develop a work plan for the search, including the nature and extent of community involvement and engagement.


 Would you like to participate in the process?  Here is how you can practice, right now, from the comfort of your own home.


HYA is conducting superintendent searches for the following school districts.  Click on the link and you can see the questions used in Mill Valley California.


Practice now, practice frequently, but hurry up, because the Mill Valley web states that the website will close down soon.  


You may ask, is this a good use of your time?  Absolutely, because the survey is likely to be the same one administered right here in MoCo.  How do we know?  Because the same survey was administered in  Marblehead, MA and  Chappaqua, NY - two districts also looking for Superintendents of Schools, but these surveys were closed down within the last 24 hours.  


Looks like the MoCo Board of Education really searched for the most economical and reliable firm, since $35,000 will likely be used for a recycled stakeholder questionnaire that has already gone through the validation process in other school systems.  MoCo also saves money, because the system doesn't require a password to participate.  In fact, anyone can answer any questionnaire, once it is posted, even if the responder doesn't live in the area.


Let's hope the candidates for our Superintendent selection process however, fit the requirements of our school system and not the ones rejected by the other school systems.  


What a deal for Montgomery County taxpayers.