Tag: Cybersecurity

  • Phone-free multi-factor authentication is key to K12 cybersecurity strategy

    Phone-free multi-factor authentication is key to K12 cybersecurity strategy

    As cyber threats against educational institutions continue to rise, the need to protect sensitive data and maintain secure, accessible learning environments is more crucial than ever. Authentication has always been a cornerstone of cybersecurity, but traditional methods are proving insufficient. For educational institutions facing unique challenges, deviceless authentication (which doesn’t require a cell phone) is emerging as an innovative solution, allowing schools to secure their networks without requiring users to have access to physical devices. Identity Automation’s RapidIdentity platform offers versatile deviceless options, including WebAuthn and Pictograph, which deliver robust, device-free authentication tailored to the needs of schools.

    Why Authentication Matters in Education Today

    With sensitive student data, health records, and other critical information at stake, cybersecurity in schools is a priority. Federal agencies like the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Education (ED) have increasingly emphasized the need for multi-factor authentication (MFA) as an essential security measure. They urge schools to strengthen their defenses with MFA, advocating for security standards that go beyond passwords. Guidance from federal government’s K-12 Cybersecurity Act and the Department of Education’s resources on protecting student privacy provide best practices guidelines, but implementing MFA in education brings its own challenges.

    Access to physical devices isn’t universal in education, and institutions are increasingly adopting device restrictions. Many students do not own personal devices, while others may be prohibited from using them on campus. Teacher unions often object to districts requiring teachers to use their personal phones for school activities. This is where deviceless authentication becomes critical: it enables every user to securely access school systems without needing an additional device, creating a seamless, secure experience for students and staff alike.

    Trends in Deviceless Authentication

    Across sectors, authentication methods are evolving to increase security while minimizing reliance on devices, passwords, and other traditional methods. Here are a few key trends:

    1. WebAuthn for Passwordless Security: WebAuthn is a leading technology enabling secure, passwordless authentication across platforms. By using biometric sensors or hardware keys, WebAuthn eliminates the need for passwords entirely. For schools, WebAuthn provides a versatile deviceless solution by allowing users to authenticate through built-in or connected hardware options on any device available in the school setting, such as a laptop or desktop computer.
    2. Pictograph Authentication for Visual Simplicity: Pictograph offers a unique, highly accessible way to authenticate by allowing users to choose and memorize a series of images rather than passwords or device-based codes. This method is ideal for students of all ages, as it does not require any device ownership and is easy for younger users to remember. Pictograph aligns well with educational environments, where students can log in quickly without needing a phone or other hardware.
    3. Adaptive and Contextual MFA: Adaptive authentication adjusts security requirements based on factors like user location or behavior, providing extra layers of security without requiring a device. Schools benefit from these dynamic adjustments, allowing students and teachers to access resources with minimal friction while ensuring that the security adapts to higher-risk scenarios.
    4. Zero-Trust Frameworks: Educational institutions increasingly adopt Zero Trust models, which prioritize strict identity verification at every access point. Deviceless options like WebAuthn and Pictograph fit seamlessly into this framework, making it possible for schools to implement Zero-Trust principles even in challenging environments where users may not have access to dedicated devices.

    RapidIdentity’s Deviceless Authentication Solution

    At Identity Automation, we understand the unique security needs in education and the critical importance of balancing secure access with usability. Our RapidIdentity platform is designed to provide flexible, deviceless authentication options, including WebAuthn and Pictograph, that address the specific challenges of school districts.

    • WebAuthn Integration: WebAuthn allows users to authenticate with cryptographic keys generated by their devices, such as biometric sensors or security keys. RapidIdentity’s support for WebAuthn enables schools to offer passwordless, device-independent security that fits naturally within classroom settings. Whether a student is using a computer lab or a shared school device, WebAuthn provides a frictionless and secure way to log in without needing to rely on personal devices.
    • Pictograph for Visual Authentication: Designed with younger students and device-limited environments in mind, RapidIdentity’s Pictograph feature offers a user-friendly alternative to traditional authentication methods. Instead of entering a password or using an SMS code, students can select a personalized sequence of images. This solution is particularly useful for younger students who may struggle with text-based passwords or who lack access to personal devices, providing an easy-to-remember and device-free way to log in securely.
    • Role-Based Access and Adaptability: With thousands of students, teachers, and staff accessing systems daily, RapidIdentity’s platform provides adaptable, role-based access specifically designed for educational institutions. Users are only prompted for higher levels of authentication when necessary, reducing friction while enhancing security. Deviceless options like WebAuthn and Pictograph make this process even smoother by offering flexible solutions that require no additional hardware for authentication.
    • Compliance and Federal Mandates: RapidIdentity’s solutions are built to help schools align with federal guidelines, offering a secure yet flexible way to implement MFA without compromising accessibility. With deviceless options, schools can protect student data and meet cybersecurity mandates without requiring users to carry devices, making compliance achievable for districts of all sizes and means.
    • Scalability and Cost-Effectiveness: Schools can avoid the high costs of purchasing, deploying, and managing hardware tokens or mobile-based authentication solutions by using RapidIdentity’s deviceless authentication. For cash-strapped districts, the ability to secure their environments without extensive device investments is a game-changer, offering schools a highly scalable and economically feasible solution.

    Partnering with Identity Automation for a Safer Future

    In a landscape where cyber threats are increasingly sophisticated, RapidIdentity’s deviceless authentication options, including WebAuthn and Pictograph, stand as versatile and powerful tools in an educational institution’s security arsenal. With Identity Automation, school districts can confidently adopt robust, compliant, and user-friendly authentication solutions designed specifically for the education sector.

    To explore how RapidIdentity can strengthen your school’s cybersecurity posture, reach out to Identity Automation today. Our team is ready to help you navigate these challenges and implement solutions that keep your data secure while making authentication easy for every user. Contact us to learn more about deviceless authentication and other ways RapidIdentity can empower your school with comprehensive, modern security.

    Source link

  • PowerSchool Got Hacked. Now What? – The 74

    PowerSchool Got Hacked. Now What? – The 74


    Get stories like this delivered straight to your inbox. Sign up for The 74 Newsletter

    Were you a current or former student in the last few decades? Or a parent? Or an educator? 

    If so, your sensitive data — like Social Security numbers and medical records — may have fallen into the hands of cybercriminals. Their target was education technology behemoth PowerSchool, which provides a centralized system for reams of student data to damn near every school in America.

    Given the cyberattack’s high stakes and its potential to harm millions of current and former students, I teamed up Wednesday with Doug Levin of the K12 Security Information eXchange to moderate a timely webinar about what happened, who was affected — and the steps school districts must take to keep their communities safe.

    Sign-up for the School (in)Security newsletter.

    Get the most critical news and information about students’ rights, safety and well-being delivered straight to your inbox.

    Concern about the PowerSchool breach is clearly high: Some 600 people tuned into the live event at one point and pummeled Levin and panelists Wesley Lombardo, technology director at Tennessee’s Maryville City Schools; Mark Racine, co-founder of RootED Solutions; and Amelia Vance, president of the Public Interest Privacy Center, with questions. 

    PowerSchool declined our invitation to participate but sent a statement, saying it is “working to complete our investigation of the incident and [is] coordinating with districts and schools to provide more information and resources (including credit monitoring or identity protection services if applicable) as it becomes available.”

    The individual or group who hacked the ed tech giant has yet to be publicly identified.

    Asked and answered: Why has the company’s security safeguards faced widespread scrutiny? What steps should parents take to keep their kids’ data secure? Will anyone be held accountable?

    Watch the webinar here.


    In the news

    Oklahoma schools Superintendent Ryan Walters, who says undocumented immigrants have placed “severe financial and operational strain” on schools in his state, proposed rules requiring parents to show proof of citizenship or legal immigration status when enrolling their kids — a proposal that not only violates federal law, but is likely to keep some parents from sending their children to school. | The 74

    • Not playing along: Leaders of the state’s two largest school districts — Oklahoma City and Tulsa — rebuked the proposal and said they would not collect students’ immigration information. Educators nationwide fear the incoming Trump administration could carry out arrests on campuses. | Oklahoma Watch
       
    • Walters filed a $474 million federal lawsuit this week alleging immigration enforcement officials mismanaged the U.S.-Mexico border, leading to “skyrocketing costs” for Oklahoma schools required “to accommodate an influx of non-citizen students.” | The Oklahoman
       
    • Timely resource guide: With ramped-up immigration enforcement on the horizon — and with many schools already sharing student information with ICE — here are the steps school administrators must take to comply with longstanding privacy and civil rights laws. | Center for Democracy & Technology

    A federal judge in Kentucky struck down the Biden administration’s Title IX rules that enshrined civil rights protections for LGBTQ+ students in schools, siding with several conservative state attorneys general who argued that harassment of transgender students based on their gender identity doesn’t constitute sex discrimination. Mother Jones

    Fires throw L.A. schools into chaos: As fatal wildfires rage in California, the students and families of America’s second-largest school district have had their lives thrown into disarray. Schools serving thousands of students were badly damaged or destroyed. Many children have lost their homes. Hundreds of kids whose schools burned down returned to makeshift classrooms Wednesday after losing “their whole lifestyle in a matter of hours.” | The Washington Post 

    • At least seven public schools in Los Angeles that were destroyed, damaged or threatened by flames will remain closed, along with campuses in other districts. | The 74

    Has TikTok’s time run out? With a national ban looming for the popular social media app, many teens say they’re ready to move on (and have already flocked to a replacement). | Business Insider

    Instagram and Facebook parent company Meta restricted LGBTQ+-related content from teens’ accounts for months under its so-called sensitive content policy until the effort was exposed by journalist Taylor Lorenz. | Fast Company

    Students’ lunch boxes sit in a locker at California’s Marquez Charter Elementary School, which was destroyed by the Palisades fire on Jan. 7. (Photo by Justin Sullivan/Getty Images)

    The Federal Communications Commission on Thursday announced the participants in a $200 million pilot program to help schools and libraries bolster their cybersecurity defenses. They include 645 schools and districts and 50 libraries. | FCC

    Scholastic falls to “furry” hackers: The education and publishing giant that brought us Harry Potter has fallen victim to a cyberattacker, who reportedly stole the records of some 8 million people. In an added twist, the culprit gave a shout-out to “the puppygirl hacker polycule,” an apparent reference to a hacker dating group interested in human-like animal characters. | Daily Dot

    Not just in New Jersey: In a new survey, nearly a quarter of teachers said their schools are patrolled by drones and a third said their schools have surveillance cameras with facial recognition capabilities. | Center for Democracy & Technology

    The number of teens abstaining from drugs, alcohol and tobacco use has hit record highs, with experts calling the latest data unprecedented and unexpected. | Ars Technica


    ICYMI @The74

    Librarians Gain Protections in Some States as Book Bans Soar

    RFK Jr. Could Pull Many Levers to Hinder Childhood Immunization as HHS Head

    Feds: Philadelphia Schools Failed to Address Antisemitism in School, Online


    Emotional Support

    New pup just dropped.

    Meet Woodford, who, at just 9 weeks, has already aged like a fine bourbon. I’m told that Woody — and the duck, obviously — have come under the good care of 74 reporter Linda Jacobson’s daughter.


    Get stories like these delivered straight to your inbox. Sign up for The 74 Newsletter

    Source link