PARCC field tests had major data security flaws and of course they knew all about it

parcc-securityBy Brad McQueen

The Common Core testing company, PARCC , knew it had major data security flaws in its computer-based field tests, administered by Pearson Testing this past spring to over 1 million students in 14 states, but they went ahead with the field test anyway.

The PARCC test was piloted by over 1 million students this past spring so that PARCC/Pearson testing group could then use the data gathered to fine tune their tests, which they will then sell back to states to use as their Common Core assessments during the 2014/2015 school year. The PARCC field test had a testing window that stretched from 3/24 – 6/6/14 in which the states had to administer their test.

As stated in my previous article  about data security and the field tests, the students and the schools taking part in these field tests received nothing in return for their services.  Or so I thought.

According to internal emails between “state leads” in our departments of education and the PARCC group, those students taking the field test may have received a lesson in good old Common Core deception.

In order to maintain data security the computerized tests must maintain a secure connection to the online test using a popular browser like Internet Explorer.  It is similar to when you require a secure connection online to do your taxes online or pay your bills online.   Any breach in security can cause a loss of valuable personal information.

Twelve days  before the PARCC field tests were due to begin, an email was sent to state leads that warned of both internal and external  data security flaws in the PARCC computerized tests that posed a security risk to student data.

There are flaws that are internal to the PARCC computerized test that pose threats to student data security

The PARCC test has a feature that allows kids to “highlight” the text of passages with a color by clicking on it to aid in comprehension.  It also has a feature that enables kids to check on the meaning of words on the test, similar to an online dictionary, where kids can “select” a word or phrase by clicking on it.  In fact, PARCC boasts about this feature.

The problem is that when kids try to use the “highlight” or “select” features it causes the students to be logged off of their secure connection to the test if they are using certain versions of the popular web browser Internet Explorer  as its Accelerator feature is triggered. The Accelerator feature allows a user to quickly surf the web for various things like dictionaries or maps. There is then a lag time between when the student is logged off the test and when the test administrator logs them back on where the field test security is breached.

In a PARCC email from Danielle Griswold to all PARCC state leads on 3/12/14 they confirm,

“The down time between when students are exited from the secure test mode in TestNav (the online test platform) and when the proctor resumes the testing leaves a gap that is a security risk.”

To avoid this security flaw, the test administrator must manually disable the Accelerator feature to prevent the kids from being exited from the test. The PARCC test does not have the capability of disabling the Accelerator feature on the Internet Explorer automatically, rather it must be done manually by a human.

The only other way, and the best way to disable this security flaw, is to remove the highlighting and selecting feature from the test. But PARCC/Pearson has already invested heavily in these prized accommodation features in all its pretest literature, training manuals, tutorials and practice test items.  Think they’ll do the right thing?

Oh yeah, if kids are using iPads, and many did during the field tests, there is no way to disable the Accelerator function.  The PARCC crowd doesn’t seem concerned about kids using iPads when they say in their email, “similar issue for iPads will remain, but the number of iPad users for Field Test is much smaller.” This is small comfort to those kids and their data, but thanks for caring PARCC, Pearson, and Departments of Education.

There are also flaws that are external to the PARCC computerized test that pose additional threats to student data security

I should have told you not to eat before reading this article, because there’s more.

There are also flaws that are external to the PARCC computerized test that pose additional threats to student data security when using certain versions of Internet Explorer with the Accelerator feature.

Common applications like anti-virus updating, screensavers, pop-up blockers, or the computer accessing other programs will exit the student from the test exposing them to a data security risk until they are manually logged back on to the test by the test administrator.  These applications must also be disabled manually before the test begins.

Sounds like there were loads of ways for your kids’ data security to be breached during the PARCC field test, huh?  But remember when PARCC, Pearson, and your state Departments of Education delayed/cancelled the field test so that they could correct these serious test security flaws?  Me neither.

What PARCC/Pearson and your State Departments of Education actually did instead was stay on schedule with the field test, keep all the security flaws a secret, and updated their test administrator’s field test instructions to include that the administrators must manually disable the Internet Explorer Accelerator feature and all the other possible applications that cause students to be exited from the field test and triggers a breach in student data security.

Here’s the update  sent to the field test administrators on 3/20/14, four days before the tests were to begin:
______________________________________________________________________________

General Note for Computer-Based Testing

Before Testing

As Test Administrators and/or Technology Coordinators prepare student test taking devices for the field test, please be sure to take the following steps to ensure test security:

1. Check every device to ensure that all software applications, including Internet browsers, cameras (still and video), screen capture programs (live and recorded such as Skype), email, instant messaging, application switching, media players (such as iTunes) and printing, are closed on all student testing devices before the test begins.

2. In addition, schools should work with their technology staff to configure the common applications listed below to NOT launch on any student test taking devices during testing sessions:

a. Anti-virus software performing automatic updates

b. Power management software on laptops warning of low battery levels

c. Screen savers and sleep mode

d. E-mail with auto message notification

e. Calendar applications with notifications, such as Google Calendar

f. Pop-up blockers
______________________________________________________________________________

Access the full attachment to the 3/12/14 email from PARCC to its state leads explaining the full extent of the field test security flaws here.

So teachers who will play the role of field test administrators, who are already overwhelmed with their teaching responsibilities, are also supposed to play computer gurus using their mostly underwhelming, out-of-date school technology to maintain all data security manually?

All this will be done on behalf of a private testing company, PARCC/Pearson, free of charge so that this same company can then adjust its test and sell it back to the states as their Common Core test next year for millions of dollars.  Only in the world of Common Core would this make sense.

Companies are out for profit, so I understand their motive, but why are our Departments of Education colluding with these data predators? It’s education malpractice.

Sarah Gardner, Arizona’s Director of PARCC Assessments echoed a sentiment that other PARCC state leads parroted when she stated the following in her April 2014 newsletter a full month after receiving the email from PARCC alerting her to the serious data security flaws inherent in the PARCC field test:

“There may be a few glitches, but that’s why we are field testing…and working out these glitches will lead to better operational tests.”

All of PARCC’s state Departments of Education unanimously declared the PARCC field tests a success with only minor “glitches”.  Those of us who work in schools that took the field test or parents who have kids who took the field test remember quite a different story.

Don’t be gas-lighted

Many of my teacher sources here in Arizona complained of kids taking hours to log on to their computers to take the field tests only to be logged off the test or have the test freeze.

It sounds like New Mexico experienced similar problems as reported by Ed Week.  Computers at Cibola High School in Albuquerque, N.M., are set to update automatically during the school day, said Ryan Kettler, the assistant principal for 11th grade, “so that would come up and boot the kids off.”

And in New Jersey the NJ Spotlight reported, “…there was plenty of chatter in New Jersey and elsewhere about deeper problems with the exams…Various blogs have surfaced, most of them critical, where teachers said that the computers froze.”

Now we know what the truth was behind all those kids being logged off the tests or having their tests freeze mid-answer so that they needed to have their test resumed by the test administrator.

You see, the Common Core crowd is great at gas-lighting its opposition. Gas-lighting is a form of mental abuse where the abusers keep telling the big lies so that you start to doubt your own memory, intelligence, or version of reality.

Funny how seeing an email of the Common Core crowd’s conversations not only reaffirms our own reality that they are pulling the big lie on us, but it really exposes them for the gas-lighters  that they are.  I encourage every concerned citizen to submit a RFI (Request for Information) to your state Department of Education, you can get one online.  Request all the emails between your state Superintendent of Instruction and state leads and the PARCC group.

These people are your employees; check on what they’ve been doing to education in your state.  Your gut instinct telling you that something stinks is correct.  Gas-light that Common Core.

bradBrad McQueen is a former Common Core insider and current public school teacher in Tucson, Arizona and is the author of the anti-Common Core book “The Cult of Common Core”. Connect with Brad at cultofcommoncore@gmail.com

Related articles:

Ducey back peddles on Common Core, wants to keep federal standards

AZ Senate Education Committee passes Common Core kill bill

Arizona Senate to consider Common Core replacement bill

Bottom line on common core: Sunday’s comic

Arizona House passes bill to remove Common Core standards

Badass Teachers oppose Common Core

There is common ground on Common Core

HB2190 challenges Common Core crony capitalism

Promotion of Common Core by the Department of Education is a Violation of Existing Federal Law

The dark side of Common Core Standards for education

Arizona launches Common Core Standards resource

“Don’t Send Your Child to School Day” protest wins widespread support

1 Comment on "PARCC field tests had major data security flaws and of course they knew all about it"

  1. Sounds strangely like the Obamacare Website “glitches”, don’t you think? Does anyone know the extent of the personal data requested by the pilot exam? I know the College Board not only wants your DOB, address, phone, race, religion INCLUDING DENOMINATION, when you take the PSAT.

    Watch the CEO of Knewton (affiliated with Pearson/PARCC) brag :

    “We literally know everything about what you know and how you learn best, because we have five orders of magnitude and more data about you than Google has. We literally have more data about our students than any company has about anybody else about anything.”

    http://www.youtube.com/watch?v=Lr7Z7ysDluQ

Comments are closed.