Oops! Details Of 100,000 Students Leaked Online
A school testing company's blunder left personal details of more than 100,000 students publicly viewable on the web.
The Princeton Review, which produces courses designed to help students prepare for tests including the SAT (the standard entry exam for US universities), recently switched Internet providers. During the move, password protected mechanisms were inadvertently disabled, allowing for full public exposure to sensitive student records.
Among those which lost their cloaking were one file with names and birth dates of 74,000 Virginia students, and another with more extensive details regarding 34,000 students in Sarasota, Florida. These included their annual test scores, ethnicity and any learning disabilities.
It is reported that the Sarasota education firm had paid $1.7 million for Princeton to develop the system and another $350,000 a year to run it. (Source: heraldtribune.com)
The company suffered further embarrassment as the files also included internal guidelines revealing confidential details about how it prepares texts. Most intriguingly, these included the suggestion that exam writers could rewrite old questions without copyright problems as long as they made sure no three consecutive words remained the same.
The problems came to light when a rival firm was nosing around the site. Its staff informed the New York Times, who then informed the Princeton Review before running the story. Its CEO said "As soon as I found out about [the] security issue, we acted immediately to shut down any access to [the] information." (Source: nytimes.com)
There are no firm details yet on how many files were left unsecured, or who may have seen them during the seven weeks they were apparently viewable. It appears the rival firm found the files by simply guessing at a web address, though some of the relevant pages were indexed by search engines.
Security experts have pointed to several underlying problems which were exposed by the glitch in transferring to the new Internet provider. In particular, confidential information should have been stored on a different server with less restricted details. Furthermore, the seven-week gap suggests the company wasn't paying enough attention when monitoring and reviewing its security measures.
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.