Welcome


This blog is dedicated to the topics of Course materials, Innovation, and Technology in Education. it is intended as an information source for the college store industry, or anyone interested in how course materials are changing. Suggestions for discussion topics or news stories are welcome.

The site uses Google's cookies to provide services and analyze traffic. Your IP address and user agent are shared with Google, along with performance and security statistics to ensure service quality, generate usage statistics, detect abuse and take action.
Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Friday, June 15, 2018

Digital Student IDs Are Here

It was just a matter of time before colleges and universities started offering students the choice of digital identification cards. Apple is taking a big step to move the process forward, rolling out a digital student ID initiative to begin in the fall at Duke University, the University of Alabama, and the University of Oklahoma, and at Johns Hopkins University, Santa Clara University, and Temple University by the end of the calendar year.

The ID cards will use the same near-field communications chip used for Apple Pay and will be available on newer iPhones and the Apple Watch. Phil Hill, an edtech consultant and blogger, views digital student IDs as a way for schools to better serve their students and for Apple to sell more watches.

“The bigger play here for Apple is about the watch, with the iPhone thrown in as a backwards compatibility and ensuring a usable program for students who have far more iPhones than watches,” Hill told EdSurge.

Some worry the initiative might be seen as discriminatory since students who don’t have an Apple device won’t be able to participate. Colleges and universities will also need to create guidelines for tracking the information the IDs will collect on students.

“This fits into [the] overall trend of ‘Trojan Horse’ technology that is designed for one purpose, but has data collection as part of its platform,” said Avi Chelsa, founder and CEO of empow cybersecurity. “Universities are becoming more and more data-driven, using data to track behaviors and derive insights in the same way that hotels, airports, and other institutions are.”

Monday, February 20, 2017

Hacking Worries Slow IoT Adoption

The Internet of Things (IoT)—a network of computing devices embedded in everyday objects and connected to the Internet—can encompass everything from vending machines to light posts to entire building automation systems.

And that interconnection is growing, with the number of such devices forecast to surge from 13.5 billion units now to 38.5 billion by 2020. It’s already spreading into schools and across college and university campuses via online portals, digital textbooks, classroom devices, wearables, and other connections. Although such adoption of IoT has been slower at educational institutions than in the consumer market, experts predict that will begin changing this year.

However, one major roadblock to that growth remains the security of IoT devices. A sneak peek Verizon released ahead of its 2017 Data Breach Digest report recounts how one unnamed university was hacked via more than 5,000 connected devices on its campus.

“With a massive campus to monitor and manage, everything from light bulbs to vending machines had been connected to the network for ease of management and improved efficiencies,” the school’s incident officer at the time says in the report preview.

To regain control, the school had to shut down all network access to its IoT segments. “Short-lived as it was,” the incident commander says, “the impact from severing all of our IoT devices from the Internet during that brief period of time was noticeable across the campus.”

The preview identifies the underlying problem as “many IoT manufacturers are primarily designing their devices for functionality; proper security testing often takes a backseat.”

Thursday, August 11, 2016

Study Finds Security Risks in 3-D Printers

International Data Corp. (IDC) recently reported that the $2.5-billion 3-D printing market grew by 20% in 2015. IDC also predicted that education spending on 3-D printing hardware and materials will increase to more than $500 million by 2019.

That kind of spending could be very attractive to hackers. New research on 3-D printing security found printing orientation and insertion of fine defects are areas of concern because of the potential harm to users caused by deliberately weakened products.

“These are possible foci for attacks that could have devastating impact on users of the end products, and economic impact in the form of recalls and lawsuits,” said Nikhil Gupta, an associate professor of engineer at New Your University and a member of the team that did the research.

Since computer-assisted design files used in the printing process don’t include printer-head orientation, hackers could change the process without detection, according to the research. Hacking the orientation could make as much as a 25% difference in the strength of a product.

Hackers could also attack printers connected to the Internet, adding internal defects into products as they are being printed. The researchers were able to introduce submillimeter defects, which could weaken the product, that couldn’t be detected using normal monitoring methods.

Wednesday, July 6, 2016

Campus Blockchain Initiative Underway

Blockchain technology, developed as a digital ledger to record transactions using the digital currency bitcoin, is finding its way onto campus. The Massachusetts Institute of Technology’s Media Lab and educational software provider Learning Machine recently launched an open-source initiative that allows institutions to create, share, and verify blockchain-based educational credentials.

The potential uses of blockchain technology on campus include providing credential verification and tracking students’ progress through their coursework. Through the platform, credentials collected by students can be securely shared with anyone, such as an employer, who requires official documents.

The platform ensures the documentation sent is authentic and valid, according to a release on Blockchain News.

“The goal of our collaboration with the MIT Media Lab is to empower individuals with shareable credentials that can be used peer-to-peer and verified as authentic,” said Chris Jagers, co-founder and CEO of Learning Machine. “The current system for sharing official records is slow, complicated, expensive, and broken for everyone in a myriad of ways. The first generation of students to grow up entirely during the Internet age have started applying for college, and many admissions officers can share stories about applicants trying to text photos of their academic records. The expectations, while seemingly humorous, convey an honest impression about the way things should work. It should be that easy for people to share certified records directly with others and have them trusted as authentic.”

Tuesday, May 3, 2016

More Malware Attacks, Harder to Detect

Malware attacks are happening more often and are harder to detect, according to the State of the Endpoint Report from the Ponemon Institute. Of the 694 IT security administrators surveyed, the number of respondents with a strategy in place to deal with malware fell from 43% in 2015 to 38% this year.

The report found that 68% had experienced distributed denial-of-service (DDoS) attacks, where multiple systems are used to target a single system. In addition, 80% said that they believed their mobile endpoints—defined as laptops, desktops, smartphones, printers, POS machines, or ATMs—had been targets, up from 58% in 2015.

As troubling as that may sound, a bigger concern involves employees. More than 80% of respondents said the biggest threat to endpoint security was negligent or careless employees who don’t follow security policies.

“You’ve got how many different types of laptops? How many versions of Windows? How many applications for those devices? How many phone types, etc.?” asked Michael Davis, chief technology officer of the security start-up firm CounterTack in an article for InformationWeek. “IT has to struggle with all of that variation, while also trying to enforce a standard set of security protocols. And then, on top of that, they have to deal with the end user, so it’s very difficult to enforce anything, even from a purely technology perspective.”

Friday, February 12, 2016

Are Fitness Bands a Security Risk?

A new report found that most of the popular fitness trackers do a bit more than just count the number of steps the user has taken. They let others in on your progress as well.

In the early draft of Every Step You Fake: A Comparative Analysis of Fitness Tracker Privacy and Security, the Canadian nonprofit Open Effect said that all the devices it studied transmitted a unique Bluetooth identifier that can be tracked by beacons that many retailers are using to recognize their customers. Only the Apple Watch had a technique to block the beacons, according to a report in PC World.

The bands can be tracked even if they’re not paired with a smartphone, according to the researchers. Companion apps for the wearables also leak login credentials, allowing users to submit fake tracking information.

“In the course of our technical investigations into transmission security, data integrity, and Bluetooth privacy, we discovered several issues that confirm concerns about the potential uses of fitness-tracking data beyond the typical case of a user monitoring their own personal wellness,” wrote the authors of the report. “The fitness data generated by several wearable devices can be falsified by motivated parties, calling into question the degree to which this data should be relied up for insurance or legal purposes.”

Thursday, December 17, 2015

Consumer Acceptance Pushes Biometric ID

Once the stuff of spy thrillers and futuristic movie sagas, biometrics appear ready to ramp up in the next year as an accepted system for authenticating user identity, according to a report in Mobile Commerce Daily.

One company, Mitek Systems, even goes so far as to predict that biometrics will be incorporated in almost 50% of mobile financial transactions in 2016, thanks to new programs such as Apple’s Touch ID.

“We see a lot of interest in the kill-the-password movement,” said Sarah Clark, Mitek’s vice president of product.

A number of financial institutions have been piloting identity verification systems due to the rise in customers wanting to open accounts through their mobile devices. These customers don’t want to deal with a bricks-and-mortar location and they may not have a secure computer. According to Mitek, 86% of the millennial age group handle financial transactions on a mobile device, usually a smartphone.

At one time people may have been spooked by the idea of using their fingerprints or facial and voice recognition as an ID. Now consumers seem totally comfortable with the concept.

Biometric authentication is likely to spread to other applications, such as point-of-sale systems, campus ID cards, and online test-taking.

Tuesday, July 28, 2015

Security Is a Problem for Higher Ed

Higher education continues to receive failing grades when it comes to keeping its files safe from hackers, finishing last in a recent study conducted by the security ratings firm BitSight. The problem for higher ed is tight budgets, a lack of control, and an open environment needed for bring-your-own-device programs.

Despite eight recorded breaches this year, higher ed has stayed out of the headlines because the attacks tended to be small. However, the large amount of valuable intellectual property, connections to other campus organizations, and student information are tempting to hackers.

“They have a lot of intellectual property that would be nice for others to have, and their systems aren’t very well protected,” Stephen Boyer, chief technology officer and co-founder of BitSight, said in an article in CRN Magazine. “I think we’re going to continue to see these types of breaches.”

The open culture of academia is another security issue, according to Robert Desman, director of business development at Carceron Managed IT Services.

“More than any single thing, it’s a cultural issue, and we’re still in the infancy of where the institutions are in terms of being security-conscious,” Desman said. “They’ll go ahead and build up their police forces if they have a lot of incidents, but it’s always a case of closing the barn door after the horses have gotten out.”

Monday, July 6, 2015

Cybercriminals Target Ed Sector

The 2015 Global Threat Intelligence Report found that the education sector accounted for more than a third of all the reported malware incidents. NTT.Com Security analyzed more than six billion attacks and reported that the bring-your-own-device (BYOD) format instructors are beginning to use could be to blame.

Students and staff use a variety of devices on institutional networks, often providing personal information in the process. Cybercriminals understand that and so focus their attacks on those networks.

“The history of open networks at education institutions has resulted in network architectures where there is usually no strong separation between areas containing sensitive data and untested areas where professors, students, or visitors can connect,” said Chris Camejo, director of assessment services for NTT.Com Security. “This makes it more difficult to prevent, detect, and respond to attack. IT officials must develop a strategy that is custom to the BYOD culture that they have embraced.”

Monday, February 9, 2015

University Servers Could Be Targets

Hackers may be turning their attention to data stored on college and university IT infrastructures. A hacker gained access to data from an unnamed U.S. university early in 2014, according to a warning issued by the Department of Homeland Security (DHS).

The hack initiated a denial-of-service attack against the servers and used about 98% of the school’s bandwidth. The DHS memo warned that government-funded research programs are appealing targets and university networks can offer hackers a way in.

“University networks, which often have multiple levels of connectivity and accessibility to fuel collaboration, may present easier targets for cyber-espionage actors than sensitive government or private-industry networks,” the memo said.

The memo also warned that less sophisticated cybercriminals may look to hack university networks to carry out phishing scams, insert ransomware, or create havoc with student financial information. The university network can also be used as a base for cybercriminal attacks on other IT systems because constant use by students can mask the criminal activity.

Friday, September 12, 2014

Coursera Is Quick to Fix Possible Breach

While preparing to teach Stanford Law’s first Coursera class, the instructor stumbled across a potential breach that could have knocked Apple’s issues with a hack of iCloud security and compromising photos of entertainers out of the headlines. Jonathan Mayer, a computer scientist and lawyer, while setting up his massive open online course, was able to gain access to nine million Coursera names and email addresses.

In a blog post, Mayer wrote that: 
  • Any teacher can dump the entire user database, including over nine million names and email addresses.
  • Once logged into your Coursera account, any website that you visit can list your course enrollments.
  • Coursera’s privacy-protecting user IDs don’t protect much. 

Mayer alerted Coursera, which addressed the issues immediately and sent an apology to its users. Once the patches were completed, Mayer found plenty of improvements, but problems still exist.

“The bad news is that anyone with teacher access can still look up any individual student’s contact information, so long as he or she either knows the student’s internal ID (it’s embedded in many pages) or can guess a distinctive part of the student’s email address (maybe try first initial last name?),” he said. “That’s a questionable security model, and it’s potentially inconsistent with Coursera’s privacy policy.”

Tuesday, July 15, 2014

Smartphones Enable Fingerprint Security

Biometrics, such as fingerprint ID technology, would solve some security problems for college and university campuses. Without having to remember passwords or carry an ID or payment card, students could log into campus systems, access their dorms, and buy course materials at the bookstore, using just their finger.

At least one expert thinks the retail industry is ready to plunge into biometric tech. If it’s successful, that may encourage the use of biometrics in more consumer applications, including higher education. Sebastien Taveau, chief evangelist for touchpad vendor Synaptics, said smartphones are making fingerprint IDs easier and more palatable to consumers.

In an interview with the National Retail Federation’s Stores magazine, Taveau said consumers didn’t like the idea of pressing a fingerprint-sensing pad at retail checkouts. However, “they likely are going to be more comfortable having the fingerprint validated on their own smartphone or device so they can control it,” he explained.

That also means the fingerprint data are stored on the device, not in the retailer’s network, so the store doesn’t have to worry about hacking.

Tuesday, February 12, 2013

Student's Social Media Habits at High Risk

Having students use their own electronic devices for schoolwork is one of the newest trends in education as administrators work to bridge the technology gap in their classrooms. However, a study from Cisco found those students are also at high risk for security issues, according to an article at ITPortal.com.

The networking firm reported in its 2013 Annual Security Report that online shopping sites are 21 times more likely and search engines are 27 times more likely to release malware on personal computers or mobile devices than pornography or gambling sites. The riskiest sites for malware are online advertisements, which are 182 times more likely to spread a virus.

In addition, the Cisco Connected World Technology Report suggested that Generation Y respondents don’t really care. It found that 91% of Generation Y employees said the age of privacy is over and a third claim not to be worried about data about them available online.

“Unfortunately, what the security studies show is the next-generation workforce’s lifestyles are also introducing security challenges that companies have never had to address to this scale,” Cisco said in a release.

The report found that more than 33% of all infections from global malware occur in the United States, while cases of Android malware rose 2,577% in 2012. The good news is the threat to mobile malware was just 0.5% of the total.

“Today, we live a blended work-personal life,” said John Stewart, senior vice president of Cisco global government and corporate security. “The hackers know this, and the security threats that we encounter online, such as embedded web malware while visiting popular destinations like search engines, retailers, social media sites, and smartphone/tablet apps, no longer threaten only the individual; they threaten our organizations by default.”

Thursday, October 25, 2012

Network Infrastructure Still a Concern for Schools


A recent survey from Enterasys, a network security firm, found that administrators and instructors understand the value of having technology in the classroom. The question is whether the networks schools are using can deliver, according to an article in eSchool News.

The study reported 21% of schools that participated in the study use digital textbooks and 36.5% plan to begin using digital texts within the year. However, just 26% of the schools said they can move to digital with their current network infrastructure.

While 84% reported they could monitor a student’s online activities as mandated by the Federal Communications Commission, 27% said it was either impossible or difficult to customize access based on factors such as grade level. In addition, 46% plan to use online assessments as their only form of testing within five years, while 15% said it’s either impossible or difficult with their current infrastructure.

Wednesday, April 13, 2011

Bleak Findings for Web Security in Symantec Report

The notion of web security is looking more like a contradiction in terms, according to the annual threat security report issued April 5 by Symantec. The report says daily web-based attacks increased 93% from 2009 to 2010 and that social media sites, such as Facebook and Twitter, are particularly vulnerable.

Attackers use the popular social media sites to distribute malware because users trust messages they think are coming from friends. The Symantec report estimates that nearly 17% of all links posted to Facebook actually connect to malicious software. In addition, 65% of links that have used URL-shorteners were malicious—and 75% of those bad links were clicked on at least 11 times.

Mobile devices are not yet being targeted as often, but that could change soon as smartphones turn into electronic wallets with the use of near-field communications. This could prove a particularly troubling trend on college campuses as schools look for ways to make payment methods easier for students.

“The biggest issue right now is the false sentiment of security people have when using social networks or when installing smartphone apps,” says Catalin Cosoi, head of BitDefender’s Online Threat Labs, in an article for TechNewsWorld. “Since these services or devices are represented by known international institutions, they believe that they are safe.”

Saturday, February 5, 2011

PDF security weakness noted

Given that many e-textbooks are still distributed in a .pdf format, or given that according to a recent BISG study as many as 40% of students pirate their textbooks (or have friends that do), the following recent news piece should give some pause to students acquiring textbooks in .pdf formats, and the publishers who produce them.

A MSNBC story reports that PDFs are now the number one vehicle for for web-based attacks. The story notes that currently e-readers are safe but that could change as more content moves to those devices and the devices take on more processing and multi-function capability (like the iPad and other tablets). Students should watch to make sure that textbooks they acquire in pdf format come from trusted sources, as the article notes that "spear-phishing" (targeted and personal attacks to a user from a known source) are a common method used in some of the .pdf-related malicious attacks.