.

Showing posts with label National Security. Show all posts
Showing posts with label National Security. Show all posts

Monday, September 17, 2012

Cyber Threats & Vulnerability, Part 2: Hiding behind Educational Institutions’ Integrity and Credibility:


Every high school, college and university around the world depends on the perception of their professional credibility in order to attract students to attend their school. Public high schools increasingly have to sell themselves to their communities as private schools, homeschooling as new charter schools rise in popularity and effectiveness. As publicly funded vouchers and inner city lottery selections have proved, schools must compete to garner students’ attention, and attendance despite the socioeconomic status of their community. College grants, scholarships and student loans offer ways to make higher education seemingly accessible to all. But these educational institutions still depend on a student to pay fees to attend and use federal and state funding in order for the school to survive in any economy. In order to support their mission, schools must accept and retain a specific number of students on a yearly basis. Every school wants to be credible and attractive, especially in an increasingly digital world. Integrity and digital relevance are of high importance.
However, the increasing use of emergent technologies to serve the needs of the institution is having a negative effect. Students are being pitted against the school or against the technology company that the school has contracted to use. In a well publicized case in 2007, students from a suburban Washington D.C. high school sued iParadigms LLC over copyright infringement of original student work. In such cases, even though the school is the business client, the client must financially support any criticism against the company’s integrity. As is evidenced by the following paragraph taken from the TurnItIn website, a school must bear the brunt of all legal fees when such a case is brought against TurnItIn for false allegations, copyright infringement, and are held liable for any defamation of character suit by students trying to defend themselves against the findings of this software.
Indemnification:
You agree to indemnify and defend iParadigms from any claim (including attorneys fees and costs) arising from your (a) use of the Site, (b) violation of any third party right, or (c) breach of any of these Terms and Conditions. You agree to cooperate as reasonably required in the defense of any claim. iParadigms reserves the right, at its own expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification under this section and, in any event, you agree not to settle any such matter without the prior written consent of iParadigms.

As is evidenced above, this private company's programmers are hiding behind the school’s reputation. This indemnification clause causes the client to not question the integrity of the software, instead the school questions the integrity of the student when any conflict arises. Therefore, the college must financially and legally defend their honor by subjecting a student to jumping through hoops to defend their own integrity. Many students do not have the same resources or body of work to prove their innocence against a system that has produced what may be a ‘false positive’ due to correlation or coincidence. Student work could merely be producing similarity to the works in the database, particularly if the school employs the same teacher, syllabus, and list of assignments year after year.

As evidenced by the following document forwarded to the University of Arizona faculty by an iParadigms company representative, the university is instructed to demand their students use this software to prevent possible plagiarism:

If you decide to take and continue in this course, you are agreeing to submit your papers
online, when so instructed, to a plagiarism-prevention program called TurnItIn.com.
When you set up your individual account with TurnItIn.com for this class, make sure you
understand and consent to all the terms that the program provides you at that point.  You
should note that TurnItIn.com – always without your name and any personal information
– will retain your paper as part of their database so that students who plagiarize from it
can be detected.   Because of this program, the vast majority of you who do your own
work and cite your sources of information properly will not have to compete with students
who commit undetected plagiarism.  Anyone who has questions or problems with
TurnItIn.com may talk privately about these with the instructor.”
                (you can read the entire PDFdocument here Legal Issues regarding TurnItIn.com)  

A high school student dare not criticize the use of TurnItIn without inviting suspicion over their possible intent to plagiarize. A college student is making a choice over what university they attend, and what classes or major they pursue. So the course syllabus that requires every writing assignment to run through a suspect database hides behind the supposed “choice” of a student to elect to study somewhere, or something else. Often, questioning the use of untested and uncertain software programs is seen as questioning the integrity of the individual teacher, course of study, or school itself. Teachers and administrators are familiar and adept at having to defend the choice of curriculum, textbooks, and methods used within the classroom. Students and parents are left with the choice to support these decisions or go somewhere else.

By determining to use this software, colleges have accepted the results of this software above the word of the student. When a student has been accused of plagiarism the only recourse against this blemish on their integrity and character is to request an ethics committee review. In a normal court of law, when a citizen is accused of a crime, they are innocent until proven guilty and allowed legal representation. However, in academia, they are stripped of their right to legal representation as is evidenced by the following statement from the Ethics Committee of the University of Phoenix:

*Please be aware, per the student code of conduct, tape, digital, or other electronic recording of the committee meeting is not permitted. Also, Students are not entitled to representation by an attorney or any other third party at any point in the process.

In the case of a high school student being accused of this type of crime, parents automatically believe the evidence provided by the school. After all, the school wouldn't lie about such a thing, right? What happens to that student as a result of such an allegation?  The student withdraws and finds the doors of other schools and institutions suspect of their future behavior. Instead of teaching students how to cite sources properly, TurnItIn brands students as cheaters, determining their academic and professional careers suspect of future abuse. The innocent student may become depressed because no one believes them, asserting the integrity of the school above the integrity of the individual. These students are the eggs that must be cracked to prepare the omelet of greater defense against plagiarism. Parents of accused students must hire a forensic computer expert in order to clear their child's name, moving thousands of dollars previously earmarked for academic growth towards producing an affidavit to prove their innocence. And in the case of a false positive or incorrect assessment, does the school reimburse the parent or student these costs? Not based on the ‘terms and conditions’ agreed upon by simply using or piloting the program within the classroom.

Exonerated students are left to move on with life and often must sign anti-disclosure agreements to prevent a scandal. If other schools heard about the actual effects that use of this software breeds, they might not pledge future financial support to this private company. And therein lies the problem: legally, the company is set up to gain at the expense of the school’s integrity and the student’s career. When are we going to realize that the risks are too high for the potential rewards this company produces? Next, we will examine the way this company advertises for future clients using the integrity of the institutions they are supposed to protect. Also, we will see whether or not the system actually produces the desired results of a safer, plagiarism-free world that it claims.

Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain.

Part 3: Tricks and Illusions - False Advertising To Produce Sales

Cyber Threats & Vulnerability, Part 1:




“We owe you a big apology for the intermittent service outages we experienced… that may have impacted your website, your email and other services. We let you down and we know it. We take our responsibilities – and the trust you place in us – very seriously. I cannot express how sorry I am to those of you who were inconvenienced.”

The above statement was from a mass email sent out by Scott Wagner, CEO of GoDaddy.com. Beyond the risqué SuperBowl ads and high profile sports marketing efforts lies a company that takes seriously the services offered, and the real implications of the vulnerable client information they storehouse. This company holds the security interests of the paying customer above any potential public criticism that accompanies announcing and rectifying a breach. Database security is a serious business.

Over the past few years, computer systems from the Department of Defense to the Social Security Administration and the Veterans Administration have been hacked into. These breaches have been conducted by individuals and foreign governments – their goals including the procurement and distribution of military secrets, or simply the acquisition of personal information of average citizens for purposes of sales and marketing.  Just this past week, the reigning king of domain addresses, GoDaddy.com was breached. Other large private companies have also suffered scrutiny for similar past events. Media focuses on the large databases which have been breached, does not negate the many smaller databases that have equally experienced harm or data intrusion due to spamming, phishing or hacking. Are these known cases just the beginning of exposing our vulnerability, when everything we do when using the internet is wrapped around online data transactions? For the sake of convenience, many of us pay our bills online, transfer funds or stocks online, and order products or services via private websites, we think we can trust. Many supermarkets and big-box stores request all sorts of personal information to track customer preferences and needs. Local, state and federal agencies also encourage us to pay our real estate or personal property tax online, renew our driver’s licenses online, and even offer a reduced rate for renewing certain registrations online.

The ease of the internet has encouraged an exponential increase in the use of database storage of personal information for public and private use. But the security responsibilities can be overlooked when they are not the primary reason for the stored information. Are these databases harvesting our information for use in compiling demographics, statistics and other data reporting for sales and marketing? Does the information always stay with the company who gathers it? Or is it shared with other databases who collaborate financial deals with the original host? What about the private companies and banking institutions who harvest our personal and financial information – are there enough safeguards in place to ensure our information will not fall into the wrong hands? With all the identity theft that has been discovered over the years, it seems this collected information is no longer fully safe. And with the difficult economic times, concern must be given to whether these private companies fail financially? In the face of bankruptcy and bailouts, will they sell our information to the highest bidder in order to remain solvent?

The use of the internet and the quick sharing of personal information is not going away anytime soon. Now, our children are doing their homework via the internet, and we encourage them to use anti-plagiarism software before submitting their homework. Aspiring college students must fill out online applications before acceptance into public and private colleges and universities. While parents safeguard their children at home, they equally believe school principals and teachers are effectively researching the software they utilize in their schools. But what if these school administrators are currently overstretched in their duties, and cannot fully scrutinize the programs, and tools that are highly regarded or encouraged by their districts? Our investigation has proved that whatever the reason, they are not fully safeguarding our children. In fact, they are perpetuating their downfall by requiring software that leaves them vulnerable. Two such concerns are TurnItIn Anti-Plagiarism Software and TurnItIn Admissions Software.

TurnItIn Anti-Plagiarism Software is currently being used by over 3500 schools, colleges and universities worldwide. The goal of such software is to detect plagiarism among students from high school to doctoral studies, from class assignments to masters’ theses. But does it really detect cheating without setting up students to false allegations? According to their own website, TurnItIn receives over 60 million papers a day. Each submitted work is placed into the TurnItIn database for future use, without the knowledge or consent of the student. The terms and conditions of iParadigm states: "we may only use the content of your paper for the purpose of performing our services for your educational provider and for future use as part of our database."  This implies consent to reuse a person's paper for use within the greater database in its discovery of future plagiarized work. However, evidence proves that documents submitted to their database have been distributed to additional cheat-detection sites for profit. The TurnItIn website states they are a California based company, but does that correctly infer where their database is held? Is it in California or in their new International Headquarters located in Newcastle, England? When students submit papers to TurnItIn’s system, it is included in a privately held company database known as iParadigm, LLC. While the company claims they do not retain owner’s name or identity stamp, the unsuspecting creator of said paper has just been stripped of their personal copyright because they submitted willingly, albeit required, through a school, college or university. Should it be a goal of schools at any level to assist students in shedding ownership to intellectual property?

TurnItIn Admissions Software is a whole other security risk. When a student submits an application to their ‘dream’ college or university they may be required to submit their application using this software.  College applications gather many levels of sensitive information: name, address, phone number, email address, social security number, parents’ occupation and employers, even financial information. Where is this information stored? Does it remain solely with the university admissions? Or does it transfer with the student essay in order to report back to the school a flagged entry? And is this sensitive identifying information then properly withdrawn from the intellectual property used to detect future underhanded entries? Is the TurnItIn database secure from hacking before this supposed information swipe occurs? Are there private companies and social organizers who would do just about anything for the contact information of countless prospective clients and sympathizers? Just who is watching over your child’s personal information and keeping their identity safe?

“The service outage was due to series of internal network events that corrupted router data tables. Once the issues were identified, we took corrective actions to restore services for our customers… We have implemented a series of immediate measures to fix the problem. At no time was any sensitive customer information, including credit card data, passwords or names and addresses, compromised.” GoDaddy.com

When database security is compromised, this is the response we expect from those we trust with our sensitive information. For a company to react, respond, and reply to those involved. GoDaddy.com offered its customer base a declaration of the importance of the incident, an explanation of what was and was not compromised, and a reassurance of personal security. An account credit was also offered as a sign of good faith and continued pledge of service to the client. All such databases should be required to protect the identities they are privy to. This week, we will examine how iParadigm and other database creators are upholding this responsibility. We may not be as secure as we think we are.

Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain. 

Part 2:  Hiding behind Educational Institution Integrity and Credibility

Thursday, September 13, 2012

21st Century Security Threat


By: Sean McGowan and Elizabeth Kilbride 

We all remember the day. Our seemingly peaceful existence and domestic tranquility was forever altered by four hijacked planes used to kill our own people. It was time when we began asking the tough questions: Just how safe is America? How vulnerable are our lives and our institutions? If terrorists could come to our soil, gain entry, learn how to operate our planes in our schools, and then learn our security protocols and expected responses, then in what other areas are we at risk? These are tough questions we did not imagine having to ask, but did so for the sake of our families and future generations.

At a time when the world’s governments are responding to multiple cyber threats of hacking, identity theft, and a thousand other cyber vulnerabilities, we must ask ourselves a few simple questions.

What if we are not as safe as we think we are? 

And what if our area of strongest vulnerability contains the segment of society we rely on for our enduring legacy – our children? Is the safety of our future leaders being put in danger by those we entrust their safety to? Are they more at risk now than when we first learned of the physical breach to our homeland’s security?
In today’s world of fast-paced information and technological savvy, we entrust computer databases with our most sensitive information, allowing them to harvest and catalog our personal, financial, and vocational histories. We allow others access to use, analyze and store private information that includes not only our identities, but identifiable database connections to our parents and other contacts for the sake of credit references.  Are these databases secure enough from being taken over by unwanted cyber-intruders who could sell our information to the highest bidder? Are they currently in the hands of companies of unknown financial solvency that may have to sell that knowledge as leverage to avoid bankruptcy and default?
What if these databases are taken over by an enemy who wishes to steal our identity in order to infiltrate our country to do us harm? And what if this enemy finds that the most vulnerable segment of our society, those just starting out into this brave new world, are the very targets for a type of identity invasion to an epic degree?

These are the questions we should be asking ourselves before we allow our personal and professional information to be shared with such databases. The sad truth is, we as citizens have allowed this to happen to our society by trusting those we do business with every day. We have given our trust over our very identities to those with little background in securing such information. And we are finding more and more that in order to engage in the modern workplace, we are being forced to give our information in order to succeed in today’s increasingly interconnected yet decreasingly secure world.

Over the next few weeks, we will be examining one such database and explain how it has not only become entrenched in our society, but how the involuntary inclusion of our personal information today will have serious repercussions in the future. We will begin to examine the social, political and security threats that it poses. Currently, there is a breach in our wall of security that we hold so dear. It will be known as the new 9/11 threat to our nation and the world. And how we safeguard against and respond to this threat will ultimately determine whether or not we leave this world a better place for our children to thrive in.

Invited co-author of this article, Sean McGowan is published author, a teacher of Civics and American History, as well as a Chaplain.