.

Showing posts with label IParadigms. Show all posts
Showing posts with label IParadigms. Show all posts

Friday, September 21, 2012

Cyber Threat & Vulnerability: The Security Risks - A Visual Presentation


In order to better understand the "Cyber Threat & Vulnerability Series," we have prepared the following visual presentation to help you gain perspective in how vulnerable your children are when using TurnItIn.com. As Parents, educators and guardians of our future leaders, you must understand how this one system can not only compromise you, but the children you have brought into this world, or are responsible for on a daily basis as educators. This series is to alert you to the seriousness and potential harm it could put your child in, through no fault of your own. 





As depicted in this slide, when a student submits their application for college, they are required to include all personal information: name, address, phone number, social security number of both themselves and their parents. They are also required by the software to include parents’ occupational information and point of contact number for parents’ employers, along with financial information from tax returns.  Upon acceptance to college, they are required to submit all assignment papers to instructors and TurnItIn.com plagiarism system for comparison to all known documents on the web as well as Turnitin's own database system of held documents from previous students. Based on our investigation, the database held by this privately owned company based in Oakland, California, with international headquarters in Newcastle, England, has the potential vulnerability to be compromised in many ways. We will not disclose the capabilities to hack into this system for obvious reasons. However, the vulnerabilities of this system are plentiful. Accordingly, the risk of all users to include their information in this database affords hackers, and nefarious individuals the opportunity to steal identifying information of both the students and their parents – not to mention stalkers, sexual predators and other persons wishing to cause irreparable harm to students in any specific area.  See Scenario 1 and 2 for how easily it would be for a student to be harmed, and the potential security risks for our country to be harmed at the same time. 





With a unique sales staff who are trained to use covert tactics in selling their product, similar to the old car salesman tactics, any unsuspecting high school principle, dean or president of a junior college will fall prey to the opportunity to help their students succeed.



Outside of financial gains, let's look at the legal side of this investigation. 





How does any private business achieve such success without spending a dime on legal fees? They manipulate the legal system by hiding behind their customers. 
 

 What are the risks to academic institutions?


 What type of remedy does a parent or an academic institution have to stop this type of security risk?



Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain.

Tuesday, September 18, 2012

Tricks and Illusions - False Advertising To Produce Sales (Part 3)


‘Have I got a deal for you. You don’t want to be left out in the cold. If you miss the boat on this, who would want to go to your school? You would be a laughingstock. Everybody’s doing it. Ok, maybe not everybody, but a whole heap of people. Thousands have tried it. Most have stuck with it. And many are unaware of the dangers to themselves or their students. But let’s not worry about danger now. This is education! What could possibly go wrong? Who would want to try to hurt you or your students?’

Best in False Advertising
More than 3,500 higher education institutions use Turnitin, including 69 percent of the top 100 colleges and universities in the U.S. News and World Report Best Colleges list. -TurnItIn.com

Don’t you want to be part of the top 69%? At least, the above statistic leads you to assume that the top 31% did not blatantly reject the greatest anti-plagiarism web service known to man. Or did they? What about the Ivy League schools? Would you imagine Harvard and Princeton to be among the top 10% of the “best colleges”? In many years, they make up #1 and #2. So wouldn’t it be a great way to sell your service if one or both used and publicized your product?

“As far as we know, there is no current subscription to any plagiarism detection software at Harvard.  In 2006, the FAS Instructional Computing Group conducted a pilot of Turnitin for one course.  Subsequently, the university decided not to subscribe.” –Harvard Library, Ask a Librarian website

The truth remains: Harvard did a pilot of anti-plagiarism software, and decided not to sign a contract. Princeton, Yale and Stanford also have chosen their internal honor codes over an external database run by a private company. However, TurnItIn has grown to a meteoric rise in educational partnership thanks to standing on the shoulders of the integrity of past clients. The most famous example is the use of Harvard University in marketing slogans, either formally or informally. “Used by Harvard” is often the only explanation given over multiple years of promotional material, despite the truth of the limited test sample. And even Duke University, which is mentioned in many articles regarding the software, seems to have spent more time studying the effects of anti-plagiarism websites than subjecting their students to them. But the desired effects are astronomical. Even if Harvard were to refute the inclusion claims, 1000's of contracts have already been signed on their supposed endorsement:

Close to 6,500 secondary institutions worldwide now use Turnitin, including 56 percent of the top 100 high schools listed on U.S. News and World Report's America's Best High Schools. –TurnItIn.com
(Each Ivy League University realized the legal implications and recognized the red flags surrounding the use of such a software. How easy the database stripped a student of their intellectual property by stripping them of their copyright under the U.S. Constitution. Potential for their school to be placed in unwanted litigation. How easily the system could be breached, whereby putting their students at risk for identity theft, and cyber-stalking.)

Principals, board members, deans, academic facilitators – all strive to be the best educational institution around. Even when not in direct competition, the struggle to get ahead and stay ahead breeds interest in all types of pilot programs and new methodology. But the use of TurnItIn also breeds exposure of an undesired kind, as everyone wants to be known for curtailing cheating, but no one wants to be known as a hotbed for cheaters. Increased reliance on TurnItIn could garner unwanted media attention as more false positives are acquired as students lean more and more on internet access and ease of copying than relying on writing and researching skills that are currently disappearing from the daily lexicon. Schools may be breeding distrust in their students, and in turn the students may be finding better ways to beat the system. And education suffers. When honor is removed for convenience and human investigation replaced with cyber-policing, the gap widens between the teachers and students in the areas of trust and greater educational accountability. After all, the teachers are no longer detecting incorrect assignments – they have a computer do the dirty work for them.

The ‘Harvard Guide to Using sources’ warns of two types of plagiarism: intentional and unintentional. As evidenced above, there will always be students trying to beat the system, and the inclusion of anti-plagiarism software only means there are different tricks to try in avoiding detection. Just as the experienced cat burglar will find away to avoid the invisible laser security system, the experienced cheaters will find ways to thwart the database protocols. In this scenario, there is little that a computer system can do to completely eliminate all instances of cheating. Instilling honor among all students seems the best way to encourage discipline and discourage abuse.

But what about ‘unintended plagiarism’?
You know the scenario: You’ve been working on your paper all semester. You seemingly have a thousand sticky notes littering your desk from the multitude of books, essays, and internet sites you have read in preparation for your work. You are frantically searching for that one thought to end all thoughts – the final quote to drive the whole paper home. And there it is, right in the middle of your desk, staring at you this whole time incredulously like the star athlete that somehow gets picked last in the neighborhood game. You plug that glorious sentence in and submit the paper, satisfied that you have reached the conclusion of a long process. But then the unthinkable happens. That wasn’t an original thought, but something you pulled from your library musings. You forgot to cite the source in your notes, and passed off someone else’s thought as your own. Albeit in a fit of nervous fatigue, but still you are guilty of the crime. How could you? Don’t you care about the honor code? What will your parents think? Your friends? You can kiss that academic internship goodbye. And good luck moving on with your education, or cashing in on those business contacts that your professor had promised to deliver your way.
How does TurnItIn distinguish between the above two scenarios? Quite simply, it doesn’t. It doesn’t care if the student was malicious or messy, underhanded or exhausted. As long as the algorithm tripped a positive result, the job here is done and they move on, happy to have thwarted yet another miscreant on the road to academic perfection. There is no suspicion of innocence, no benefit of the doubt given to the student. The almighty program has spoken, and another career bites the dust. And the positive example of cheaters caught substantiates future use by future clients, who equally wish to lay a heavy hand on those who cheat for the sake of the masses who just want to learn. But what do we really learn through this exercise?
Beware of the Optical Illusion of false advertising
Harvard and Princeton have their own methods of curtailing cheating: honor and knowledge. First, students are encouraged to embrace the honor code. Students should think of themselves as higher entities that represent their families, communities and university well. Second, they are encouraged to know how to avoid common pitfalls that lead many to plagiarize. Avoid procrastination. Cite all sources at every step of the research project. Cite thoughts that are paraphrased and synthesized into your own work. In order to produce the best work, you must examine multiple sources of information and consider many perspectives that came before you. Do so honorably. Turn in knowledgeable, well constructed work. Be careful and consistent in your research. Allow your integrity to guide the note-taking process, and it will naturally shine through in the end product. For many universities, holding students to a higher standard is a more effective measure of combating cheating than any distant database could ever hope to instill.
The ultimate problem is that the use of false advertising by TurnItIn is just the sort of thing its website claims to rid the world of. Whether intentionally or unintentionally, TurnItIn supports the narrative that the best educational institutions employ its services, no matter how minor or short lived their involvement. The numbers touted on the website are instantly suspect. Do former clients count? Are schools included only if more than 50% of teachers mandate usage? Or is 1% enough to warrant inclusion in marketing schemes? iParadigms seems to be on a crusade against faulty submission of written work. But false or misleading claims for the sake of advertising are acceptable and promoted, if it helps spread the use of a program that only desires to save the world from evil. It’s time for TurnItIn to turn itself in to the moral standards it claims to uphold. And that scrutiny of a moral standard can begin by examining the processes used to determine a positive case of plagiarism.

Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain.

Part 4: Dummy Science and FuzzyLogic

Monday, September 17, 2012

Cyber Threats & Vulnerability, Part 2: Hiding behind Educational Institutions’ Integrity and Credibility:


Every high school, college and university around the world depends on the perception of their professional credibility in order to attract students to attend their school. Public high schools increasingly have to sell themselves to their communities as private schools, homeschooling as new charter schools rise in popularity and effectiveness. As publicly funded vouchers and inner city lottery selections have proved, schools must compete to garner students’ attention, and attendance despite the socioeconomic status of their community. College grants, scholarships and student loans offer ways to make higher education seemingly accessible to all. But these educational institutions still depend on a student to pay fees to attend and use federal and state funding in order for the school to survive in any economy. In order to support their mission, schools must accept and retain a specific number of students on a yearly basis. Every school wants to be credible and attractive, especially in an increasingly digital world. Integrity and digital relevance are of high importance.
However, the increasing use of emergent technologies to serve the needs of the institution is having a negative effect. Students are being pitted against the school or against the technology company that the school has contracted to use. In a well publicized case in 2007, students from a suburban Washington D.C. high school sued iParadigms LLC over copyright infringement of original student work. In such cases, even though the school is the business client, the client must financially support any criticism against the company’s integrity. As is evidenced by the following paragraph taken from the TurnItIn website, a school must bear the brunt of all legal fees when such a case is brought against TurnItIn for false allegations, copyright infringement, and are held liable for any defamation of character suit by students trying to defend themselves against the findings of this software.
Indemnification:
You agree to indemnify and defend iParadigms from any claim (including attorneys fees and costs) arising from your (a) use of the Site, (b) violation of any third party right, or (c) breach of any of these Terms and Conditions. You agree to cooperate as reasonably required in the defense of any claim. iParadigms reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification under this section and, in any event, you agree not to settle any such matter without the prior written consent of iParadigms.

As is evidenced above, this private company's programmers are hiding behind the school’s reputation. This indemnification clause causes the client to not question the integrity of the software, instead the school questions the integrity of the student when any conflict arises. Therefore, the college must financially and legally defend their honor by subjecting a student to jumping through hoops to defend their own integrity. Many students do not have the same resources or body of work to prove their innocence against a system that has produced what may be a ‘false positive’ due to correlation or coincidence. Student work could merely be producing similarity to the works in the database, particularly if the school employs the same teacher, syllabus, and list of assignments year after year.

As evidenced by the following document forwarded to the University of Arizona faculty by an iParadigms company representative, the university is instructed to demand their students use this software to prevent possible plagiarism:

If you decide to take and continue in this course, you are agreeing to submit your papers
online, when so instructed, to a plagiarism-prevention program called TurnItIn.com.
When you set up your individual account with TurnItIn.com for this class, make sure you
understand and consent to all the terms that the program provides you at that point.  You
should note that TurnItIn.com – always without your name and any personal information
– will retain your paper as part of their database so that students who plagiarize from it
can be detected.   Because of this program, the vast majority of you who do your own
work and cite your sources of information properly will not have to compete with students
who commit undetected plagiarism.  Anyone who has questions or problems with
TurnItIn.com may talk privately about these with the instructor.”
                (you can read the entire PDFdocument here Legal Issues regarding TurnItIn.com)  

A high school student dare not criticize the use of TurnItIn without inviting suspicion over their possible intent to plagiarize. A college student is making a choice over what university they attend, and what classes or major they pursue. So the course syllabus that requires every writing assignment to run through a suspect database hides behind the supposed “choice” of a student to elect to study somewhere, or something else. Often, questioning the use of untested and uncertain software programs is seen as questioning the integrity of the individual teacher, course of study, or school itself. Teachers and administrators are familiar and adept at having to defend the choice of curriculum, textbooks, and methods used within the classroom. Students and parents are left with the choice to support these decisions or go somewhere else.

By determining to use this software, colleges have accepted the results of this software above the word of the student. When a student has been accused of plagiarism the only recourse against this blemish on their integrity and character is to request an ethics committee review. In a normal court of law, when a citizen is accused of a crime, they are innocent until proven guilty and allowed legal representation. However, in academia, they are stripped of their right to legal representation as is evidenced by the following statement from the Ethics Committee of the University of Phoenix:

*Please be aware, per the student code of conduct, tape, digital, or other electronic recording of the committee meeting is not permitted. Also, Students are not entitled to representation by an attorney or any other third party at any point in the process.

In the case of a high school student being accused of this type of crime, parents automatically believe the evidence provided by the school. After all, the school wouldn't lie about such a thing, right? What happens to that student as a result of such an allegation?  The student withdraws and finds the doors of other schools and institutions suspect of their future behavior. Instead of teaching students how to cite sources properly, TurnItIn brands students as cheaters, determining their academic and professional careers suspect of future abuse. The innocent student may become depressed because no one believes them, asserting the integrity of the school above the integrity of the individual. These students are the eggs that must be cracked to prepare the omelet of greater defense against plagiarism. Parents of accused students must hire a forensic computer expert in order to clear their child's name, moving thousands of dollars previously earmarked for academic growth towards producing an affidavit to prove their innocence. And in the case of a false positive or incorrect assessment, does the school reimburse the parent or student these costs? Not based on the ‘terms and conditions’ agreed upon by simply using or piloting the program within the classroom.

Exonerated students are left to move on with life and often must sign anti-disclosure agreements to prevent a scandal. If other schools heard about the actual effects that use of this software breeds, they might not pledge future financial support to this private company. And therein lies the problem: legally, the company is set up to gain at the expense of the school’s integrity and the student’s career. When are we going to realize that the risks are too high for the potential rewards this company produces? Next, we will examine the way this company advertises for future clients using the integrity of the institutions they are supposed to protect. Also, we will see whether or not the system actually produces the desired results of a safer, plagiarism-free world that it claims.

Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain.

Part 3: Tricks and Illusions - False Advertising To Produce Sales

Cyber Threats & Vulnerability, Part 1:




“We owe you a big apology for the intermittent service outages we experienced… that may have impacted your website, your email and other services. We let you down and we know it. We take our responsibilities – and the trust you place in us – very seriously. I cannot express how sorry I am to those of you who were inconvenienced.”

The above statement was from a mass email sent out by Scott Wagner, CEO of GoDaddy.com. Beyond the risqué SuperBowl ads and high profile sports marketing efforts lies a company that takes seriously the services offered, and the real implications of the vulnerable client information they storehouse. This company holds the security interests of the paying customer above any potential public criticism that accompanies announcing and rectifying a breach. Database security is a serious business.

Over the past few years, computer systems from the Department of Defense to the Social Security Administration and the Veterans Administration have been hacked into. These breaches have been conducted by individuals and foreign governments – their goals including the procurement and distribution of military secrets, or simply the acquisition of personal information of average citizens for purposes of sales and marketing.  Just this past week, the reigning king of domain addresses, GoDaddy.com was breached. Other large private companies have also suffered scrutiny for similar past events. Media focuses on the large databases which have been breached, does not negate the many smaller databases that have equally experienced harm or data intrusion due to spamming, phishing or hacking. Are these known cases just the beginning of exposing our vulnerability, when everything we do when using the internet is wrapped around online data transactions? For the sake of convenience, many of us pay our bills online, transfer funds or stocks online, and order products or services via private websites, we think we can trust. Many supermarkets and big-box stores request all sorts of personal information to track customer preferences and needs. Local, state and federal agencies also encourage us to pay our real estate or personal property tax online, renew our driver’s licenses online, and even offer a reduced rate for renewing certain registrations online.

The ease of the internet has encouraged an exponential increase in the use of database storage of personal information for public and private use. But the security responsibilities can be overlooked when they are not the primary reason for the stored information. Are these databases harvesting our information for use in compiling demographics, statistics and other data reporting for sales and marketing? Does the information always stay with the company who gathers it? Or is it shared with other databases who collaborate financial deals with the original host? What about the private companies and banking institutions who harvest our personal and financial information – are there enough safeguards in place to ensure our information will not fall into the wrong hands? With all the identity theft that has been discovered over the years, it seems this collected information is no longer fully safe. And with the difficult economic times, concern must be given to whether these private companies fail financially? In the face of bankruptcy and bailouts, will they sell our information to the highest bidder in order to remain solvent?

The use of the internet and the quick sharing of personal information is not going away anytime soon. Now, our children are doing their homework via the internet, and we encourage them to use anti-plagiarism software before submitting their homework. Aspiring college students must fill out online applications before acceptance into public and private colleges and universities. While parents safeguard their children at home, they equally believe school principals and teachers are effectively researching the software they utilize in their schools. But what if these school administrators are currently overstretched in their duties, and cannot fully scrutinize the programs, and tools that are highly regarded or encouraged by their districts? Our investigation has proved that whatever the reason, they are not fully safeguarding our children. In fact, they are perpetuating their downfall by requiring software that leaves them vulnerable. Two such concerns are TurnItIn Anti-Plagiarism Software and TurnItIn Admissions Software.

TurnItIn Anti-Plagiarism Software is currently being used by over 3500 schools, colleges and universities worldwide. The goal of such software is to detect plagiarism among students from high school to doctoral studies, from class assignments to masters’ theses. But does it really detect cheating without setting up students to false allegations? According to their own website, TurnItIn receives over 60 million papers a day. Each submitted work is placed into the TurnItIn database for future use, without the knowledge or consent of the student. The terms and conditions of iParadigm states: "we may only use the content of your paper for the purpose of performing our services for your educational provider and for future use as part of our database."  This implies consent to reuse a person's paper for use within the greater database in its discovery of future plagiarized work. However, evidence proves that documents submitted to their database have been distributed to additional cheat-detection sites for profit. The TurnItIn website states they are a California based company, but does that correctly infer where their database is held? Is it in California or in their new International Headquarters located in Newcastle, England? When students submit papers to TurnItIn’s system, it is included in a privately held company database known as iParadigm, LLC. While the company claims they do not retain owner’s name or identity stamp, the unsuspecting creator of said paper has just been stripped of their personal copyright because they submitted willingly, albeit required, through a school, college or university. Should it be a goal of schools at any level to assist students in shedding ownership to intellectual property?

TurnItIn Admissions Software is a whole other security risk. When a student submits an application to their ‘dream’ college or university they may be required to submit their application using this software.  College applications gather many levels of sensitive information: name, address, phone number, email address, social security number, parents’ occupation and employers, even financial information. Where is this information stored? Does it remain solely with the university admissions? Or does it transfer with the student essay in order to report back to the school a flagged entry? And is this sensitive identifying information then properly withdrawn from the intellectual property used to detect future underhanded entries? Is the TurnItIn database secure from hacking before this supposed information swipe occurs? Are there private companies and social organizers who would do just about anything for the contact information of countless prospective clients and sympathizers? Just who is watching over your child’s personal information and keeping their identity safe?

“The service outage was due to series of internal network events that corrupted router data tables. Once the issues were identified, we took corrective actions to restore services for our customers… We have implemented a series of immediate measures to fix the problem. At no time was any sensitive customer information, including credit card data, passwords or names and addresses, compromised.” GoDaddy.com

When database security is compromised, this is the response we expect from those we trust with our sensitive information. For a company to react, respond, and reply to those involved. GoDaddy.com offered its customer base a declaration of the importance of the incident, an explanation of what was and was not compromised, and a reassurance of personal security. An account credit was also offered as a sign of good faith and continued pledge of service to the client. All such databases should be required to protect the identities they are privy to. This week, we will examine how iParadigm and other database creators are upholding this responsibility. We may not be as secure as we think we are.

Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain. 

Part 2:  Hiding behind Educational Institution Integrity and Credibility