Skip to content

Cybertraps for Educators Digest

Above the Fold: Another Massive Student Data Breach ~ 2. The State of K-12 Cybersecurity: Not Great ~ 3. UT Abuse Lawsuit Alleges District Policy Failures ~ 4. NJ Mandates Digital Literacy for Students ~ 5. Have You Been Dress-Coded?

Light piercing the clouds at golden hour [Frederick Lane, 2022]
Golden Hour [Frederick Lane, 2022]

By Frederick Lane ~ 6 January 2023

This C4E Digest is 1,347 words, or approximately a 6-minute read.

💾 Above the Fold: Another Massive Student Data Breach

Clouds and a Starry Sky [Frederick Lane, 2022]
Clouds and a Starry Sky [Frederick Lane, 2022]

Cloud storage is wonderful ... except when it isn't. A research team at vpnMentor, an online privacy firm, recently discovered that education publisher McGraw Hill exposed the personal data of more than 100,000 students.

  • McGraw Hill stored the data in Amazon Web Services S3 buckets, a widely-popular type of cloud storage.
  • Unfortunately, McGraw Hill misconfigured the settings of its data buckets, allowing anyone with a web browser access to more then 22 terabytes of student data and teaching materials.
  • The misconfiguration may have allowed access as early as 2015.

Slow response: In its report, vpnMentor said that it contacted McGraw Hill multiple times about the security breach before the company responded.

Implications: A possible seven-year leak of confidential student and teacher information raises a number of security concerns.

This post is for paying subscribers only

Subscribe

Already have an account? Sign In

A Newsletter for Professionals Committed to Educator Ethics

Incident reports, policy updates, and in-depth analysis on technology's impact on schools and students. Essential reading for educators, administrators, and licensing professionals.

  • ✓ Fresh Posts Every Week.
  • ✓ Curated Headline Digest.
  • ✓ Zero Noise, Pure Value.