sigma Posted August 16, 2022 Posted August 16, 2022 This was presented at DEFCON. A tale of a classroom management system and default passwords. https://whitehoodhacker.net/dc30-the-big-rick.pdf 2
mavhc Posted August 16, 2022 Posted August 16, 2022 Never trust hardware people to write software, and never ever trust them to write secure software. Also LanSchool is apparently terrible, storing unencrypted keystroke logs
sigma Posted August 16, 2022 Author Posted August 16, 2022 Never trust hardware people to write software, and never ever trust them to write secure software. Also LanSchool is apparently terrible, storing unencrypted keystroke logs I was quite shocked at the idea of storing unencrypted keystroke logs!
mavhc Posted August 16, 2022 Posted August 16, 2022 So would everyone with a brain, how these companies get away with charging for such rubbish is amazing, Open Source software would never get away with that
Davit2005 Posted August 16, 2022 Posted August 16, 2022 I'm guessing the keystrokes is for the banned word functionality. It can be disabled during installation but even then why store un-encrypted if this is the case and not jus report on the banned word???
Lenovo_Tori Posted August 16, 2022 Posted August 16, 2022 LanSchool Classic does encrypt the logs that contain keystrokes. The logs are only viewable in the LanSchool Teacher app that instructors use to get additional context when they receive keyword alerts. Customers should limit who on their network has access to the Teacher App. Features like Secure Mode can further control which users can connect to students using the Teacher Console. 1
pete Posted August 17, 2022 Posted August 17, 2022 (edited) LanSchool Classic does encrypt the logs that contain keystrokes. The logs are only viewable in the LanSchool Teacher app that instructors use to get additional context when they receive keyword alerts. Customers should limit who on their network has access to the Teacher App. Features like Secure Mode can further control which users can connect to students using the Teacher Console. My concern would be why Lanschool is capturing (and the Teacher App is making available) what are clearly email logins (slide/page 21) - anyone with access to the Teacher App can harvest credentials for students and (with the IT admin tool, presumably staff?), which is a classic data breach. Not to mention a solid "any teacher could have logged in as me" defense in court. It's not particularly tricky to identify login fields and ignore anything typed into them. Edited August 17, 2022 by pete 1
mikes Posted September 15, 2022 Posted September 15, 2022 (edited) My concern would be why Lanschool is capturing (and the Teacher App is making available) what are clearly email logins (slide/page 21) - anyone with access to the Teacher App can harvest credentials for students and (with the IT admin tool, presumably staff?), which is a classic data breach. Not to mention a solid "any teacher could have logged in as me" defense in court. It's not particularly tricky to identify login fields and ignore anything typed into them. Don't all "classroom management" software capture all keystrokes though? I'm pretty sure if I set impero to monitor the word "moomoo" and someone had "moomoo" in their password, that would show up under the flagged words in the logs would it not? or is this Lanschool software capturing every single keystroke into a logfile somewhere, rather than just flagging that a particular word was detected? EDIT OK I just read the PDF, it keeps every single keystroke in a nice easy to read text file including e-mail address and password fields!!!!!!!!! it's amazing US schools have all this fancy kit yet their security is utterly nonexistant ?? Edited September 15, 2022 by mikes 1
mavhc Posted September 15, 2022 Posted September 15, 2022 They only have fancy kit if they're in fancy areas, the school my friend works in she's buying extension cables so they can plug in laptops, and half the classrooms don't have projectors/screens. Very few people care about security, esp the security of students' personal info
Davit2005 Posted September 15, 2022 Posted September 15, 2022 Don't all "classroom management" software capture all keystrokes though? I'm pretty sure if I set impero to monitor the word "moomoo" and someone had "moomoo" in their password, that would show up under the flagged words in the logs would it not? or is this Lanschool software capturing every single keystroke into a logfile somewhere, rather than just flagging that a particular word was detected? EDIT OK I just read the PDF, it keeps every single keystroke in a nice easy to read text file including e-mail address and password fields!!!!!!!!! it's amazing US schools have all this fancy kit yet their security is utterly nonexistant ?? Yep that is fatal flaw as default setting which I think it is. I hope it is put as a note on the enable button, the implications.........
Davit2005 Posted September 15, 2022 Posted September 15, 2022 Don't all "classroom management" software capture all keystrokes though? I'm pretty sure if I set impero to monitor the word "moomoo" and someone had "moomoo" in their password, that would show up under the flagged words in the logs would it not? or is this Lanschool software capturing every single keystroke into a logfile somewhere, rather than just flagging that a particular word was detected? EDIT OK I just read the PDF, it keeps every single keystroke in a nice easy to read text file including e-mail address and password fields!!!!!!!!! it's amazing US schools have all this fancy kit yet their security is utterly nonexistant ?? Huge risk though, and enabled by default.....
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now