Jump to content

Recommended Posts

Posted
They appear to be seeing the homework/achievement/attendance/activity log of a.n.other student, but all i've seen is screenshots of the first landing page - not sure if anyone has clicked into them and seen further data within or not.
  • Thanks 1
Posted
We have as yet received no communication despite being affected having received calls from another school informing us their parents/staff could see our students! Very worrying how this was allowed to happen. I suspect Classcharts will be receiving strong words and a fine from the ICO.
Posted
What sort of info is being shared - would any of it be classified as special category?

 

Yes, if special category data is made available in ClassCharts. In short, I think people were getting the same view they would if they were actually the parent of the children in question.

Posted
surely everyone's data is siloed away from each other... but clearly not

 

It can't be siloed, because you could have a parent with children in two different ClassCharts schools, so they would need access to both schools from the one app.

Posted
Are you a MAT/Trust and the School 1,2 & 3 in your group or are the schools completely separate?

 

We're single school too, and our parents were seeing up to 5 other schools/children. If they logged out and back in, they got a different 5 schools and 5 children.

  • Thanks 1
Posted
"We regret to inform you that a data breach has occurred on Class Charts; rest assured, we are actively addressing the issue, you do not need to take any actions but we will be in contact with affected users to ensure their data security." is now shown on a banner on the Homepage (after you login)

 

That banner is no longer on the site...

  • Thanks 1
Posted

We have not been contacted by them nor were were instructed to take any specific action on the classcharts system when we initially reported it.

 

Interesting that the banner is no longer on the home page.

Posted

Fwiw judging by the lack of national news coverage this was likely just for about the period of time they suggest, probably an artefacts of the recovering the system from the outage (502 error) that occurred just before.

 

I suspect it was a caching issue with a service not refreshing a token somewhere in their mid layer, and thus returning the wrong data. Hopefully the data is not commingled in a monolithic database/file system, and the token is the key to which store is queried for student data. (This might even make sense: within the platform as a whole student identifiers might not be unique, improving data security… (they might only be unique to the school instance) so when the mid tier cache didn’t update the school it was supposed to be accessing, it pulled the wrong student! Though if identifiers were unique across the entire platform this couldn’t have happened. Soooo…)

Posted
We have not been contacted by them nor were were instructed to take any specific action on the classcharts system when we initially reported it.

 

Interesting that the banner is no longer on the home page.

 

They've not even acknowledged my email. It's concerning that people who phone up are being given different advice.

Posted
We have parental screenshots timed between 10:23 and 10:52.

I have offered them to CC but they haven't taken me up on the offer.

 

Where does Computer Misuse Act stand on clicking through to information you know you're not meant to have, then screenshotting it? I've been cautious with this in the past.

Posted
Have any of you who have a known breach assessed it and decided to make a report to ICO. Your DPO ideally should have done so with appropriate staff input, within 72 hours of the breach being known.
Posted
Have any of you who have a known breach assessed it and decided to make a report to ICO. Your DPO ideally should have done so with appropriate staff input, within 72 hours of the breach being known.

 

Do any of us have a known breach? I know our parents have seen other students' data, but I don't know for fact any of my school's data was exposed. Obviously, I can make assumptions, but...

Posted
Do any of us have a known breach? I know our parents have seen other students' data, but I don't know for fact any of my school's data was exposed. Obviously, I can make assumptions, but...

Only if anyone has told you. Earlier, there was a post that showed a head's letter, so that's likely make which school has a breach known, but doesn't mean they have been made aware. Do Class charts know? You'd hope so, but the info to know that might have been volatile and lost.

Posted
Do any of us have a known breach? I know our parents have seen other students' data, but I don't know for fact any of my school's data was exposed. Obviously, I can make assumptions, but...

 

This is part of the issue, we can't tell unless someone contacts the school to let us know they have seen our data or ClassCharts lets us know. I have less than full confidence we will be told anything, so we will never know if our data was kept secure or our data was left open and we just haven't been told about it. Having been shafted by one company already in this fashion I am getting a bit fed up with Education companies playing fast and loose with GDPR, and data security. Our SLT currently do not want to open ClassCharts back up to our parents, and I agree with them but also realise that actually this does nothing to protect them.

  • Thanks 3
Posted
Only if anyone has told you. Earlier, there was a post that showed a head's letter, so that's likely make which school has a breach known, but doesn't mean they have been made aware.

That was my screenshot and we haven't yet made the other schools aware; have other schools notified the schools they know of?

Posted

We each have 72 hours to make a disclosure to the ICO, ie by approx 11am Thursday.

 

My thinking, and what I'll be suggesting to DPO, is we file an explanation report tomorrow afternoon if we've heard nothing from ClassCharts; the ICO need to be made aware of it and the more reports they get, the better.

Posted
This is part of the issue, we can't tell unless someone contacts the school to let us know they have seen our data or ClassCharts lets us know.

 

Which brings us back to my earlier question about Computer Misuse Act. If I open the app for my kid's school and see 5 other kids in 5 other schools, I know I'm not meant to see that information. So, am I breaking any laws by clicking through to that data and screenshotting it? It's like if you sent me an email intended for someone else - if during the first paragraph I realise it's not for me and reply so, that's fine, but I shouldn't carry on reading the whole email and any attachments and then notify you.

 

I'll happily tell ClassCharts what we saw and notify the schools in question directly, but not if that incriminates me or the parents who (hypothetically...) sent me screen shots.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...