{"id":17275,"date":"2026-05-18T12:36:01","date_gmt":"2026-05-18T19:36:01","guid":{"rendered":"https:\/\/jasonsblog.ddns.net\/?p=17275"},"modified":"2026-05-18T12:36:01","modified_gmt":"2026-05-18T19:36:01","slug":"the-school-spy-boom-nobody-asked-for","status":"publish","type":"post","link":"https:\/\/jasonsblog.ddns.net\/index.php\/2026\/05\/18\/the-school-spy-boom-nobody-asked-for\/","title":{"rendered":"The School Spy Boom Nobody Asked For"},"content":{"rendered":"\n<p>How has this been slipping through the cracks, abusing student&#8217;s privacy? <\/p>\n\n\n\n<p><a href=\"https:\/\/reclaimthenet.org\/the-school-spy-boom-nobody-asked-for\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/reclaimthenet.org\/the-school-spy-boom-nobody-asked-for<\/a><\/p>\n\n\n<div class=\"wp-block-ub-divider ub_divider ub-divider-orientation-horizontal\" id=\"ub_divider_3c23a580-c304-406f-9e01-45fd669b5fd1\"><div class=\"ub_divider_wrapper\" style=\"position: relative; margin-bottom: 2px; width: 100%; height: 2px; \" data-divider-alignment=\"center\"><div class=\"ub_divider_line\" style=\"border-top: 2px solid #ccc; margin-top: 2px; \"><\/div><\/div><\/div>\n\n\n<h5 class=\"wp-block-heading\">Somewhere between the biometric lunch lines and the 24\/7 monitoring software, American education became a data hoarding operation with a teaching problem.<\/h5>\n\n\n\n<p>By Christina Maas<\/p>\n\n\n\n<p>Instructure, the company that runs Canvas, the learning management system used by 41 percent of North American universities, would like you to know that it takes your privacy very seriously. It says so on its website, right next to the TrustEd Apps Data Privacy Certification Seal.<\/p>\n\n\n\n<p>The company earned that seal while running a system that stored billions of private student messages on servers accessible through unverified free accounts, retained data for years without mandatory deletion schedules, and ultimately responded to the largest education data breach in history by wiring money to criminals in exchange for a text file claiming the stolen data had been destroyed.<\/p>\n\n\n\n<p>The text file, for the record, is called a \u201cshred log.\u201d Instructure received it from ShinyHunters, the hacking group that breached Canvas twice in eight days this May, stole 3.65 terabytes of data across 8,809 institutions, defaced login pages at 330 universities during finals week, and then offered to pinky-promise the data was gone if Instructure paid up. Instructure paid. The amount is undisclosed. Rumors suggest $10 million.<\/p>\n\n\n\n<p>\u201cWhile there is never complete certainty when dealing with cyber criminals, we believe it was important to take every step within our control to give customers additional peace of mind, to the extent possible,\u201d Instructure wrote in its announcement.<\/p>\n\n\n\n<p>The company bought peace of mind for 275 million people by taking the word of the criminals who robbed them. It\u2019s a bold strategy. It\u2019s also, according to every cybersecurity expert and law enforcement agency that has expressed an opinion on the subject, exactly what you\u2019re not supposed to do.<\/p>\n\n\n\n<p>But the real story is what was sitting on those servers, why schools keep shoveling more data onto them, and why nobody involved in this arrangement seems to think the students whose data it is should have any say in the matter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What \u201csome private messages\u201d actually means<\/h2>\n\n\n\n<p>Instructure\u2019s breach disclosure used careful language. Names, email addresses, student IDs, and \u201csome private messages.\u201d That phrasing is designed to make you picture a leaked school directory. It is not a leaked school directory.<\/p>\n\n\n\n<p>Canvas is where students message professors about failing a class because a parent is dying. It\u2019s where they request disability accommodations, which means disclosing their diagnosis. It\u2019s where they report sexual harassment. It\u2019s where they write things they would never put on social media, because they believe they\u2019re talking to one person in confidence.<\/p>\n\n\n\n<p>Instructure itself promotes Canvas as a portal for on-demand mental health support, advertising integrations that let students \u201cconnect with a mental health professional\u201d directly through the platform. So students did. And now those conversations are part of a 3.65-terabyte data package that a criminal group claims to have deleted, based on the same trustworthiness that led them to hack a company twice in one week and replace university login pages with ransom notes.<\/p>\n\n\n\n<p>ShinyHunters\u2019 ransom letter said, \u201cSeveral billions of private messages among students and teachers and students and other students involved, containing personal conversations and other [personal identifying information].\u201d<\/p>\n\n\n\n<p>Whether the number is inflated or not, the category is accurate. These are the most private communications students generate, written under the assumption of confidentiality, stored indefinitely by a company the students never chose, never contracted with, and in most cases never heard of until the week their finals got canceled.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Nobody asked you<\/h2>\n\n\n\n<p>Here\u2019s the part that makes the whole thing feel like satire. None of these 275 million people signed up for Canvas. Not one. You don\u2019t create a Canvas account the way you create a Gmail or an Instagram account. You get enrolled by your university, usually before orientation, into a platform that immediately becomes mandatory for completing your degree. You can\u2019t submit assignments without it. You can\u2019t take exams. You can\u2019t check your grades or communicate with professors through any other channel that the school will recognize. Opting out of Canvas means opting out of your education.<\/p>\n\n\n\n<p>The privacy policy governing what happens to your data on this mandatory platform was not agreed to by you. Your university agreed on your behalf, through a procurement contract you\u2019ve never seen and couldn\u2019t negotiate if you wanted to.<\/p>\n\n\n\n<p>Instructure is refreshingly honest about this arrangement, at least on paper. Its summary privacy notice states, \u201cIf you are an end-user of a school or company that uses our Products, your organization determines how your personal information is processed. This means that your organization\u2019s privacy policy governs the use of your personal information, even when your personal information is shared with us.\u201d<\/p>\n\n\n\n<p>That means your data is Instructure\u2019s problem, except it\u2019s actually your school\u2019s problem, except your school can\u2019t access, secure, or even see the servers where your data lives.<\/p>\n\n\n\n<p>The legal mechanism enabling this pass-the-buck privacy architecture is FERPA\u2019s \u201cschool official\u201d exception, which lets schools hand student records to third-party vendors without student consent, as long as the vendor is \u201cunder the direct control\u201d of the school.<\/p>\n\n\n\n<p>This is a situation where the school has no access to the vendor\u2019s servers, no authority over the vendor\u2019s security practices, and apparently no ability to prevent the same hacking group from breaching the vendor twice in eight months. But sure. <em>Direct control<\/em>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Meanwhile, schools are collecting everything<\/h2>\n\n\n\n<p>Canvas lost messages. That\u2019s what this particular breach took. But Canvas is just one slice of a much larger surveillance apparatus that American schools have been building with cheerful enthusiasm, and the next breach will be richer because of it.<\/p>\n\n\n\n<p>Let\u2019s start with bodies. Over two million students in 48 US states now scan their fingerprints every day at school, mostly to buy lunch. Lynchburg City Schools in Virginia rolled out fingerprint scanners across its elementary schools because, and this is the actual justification, the lunch lines were too slow. Kids fumbling with PINs were holding things up.<\/p>\n\n\n\n<p>The obvious solution, of course, was to build a biometric database of children. <a href=\"https:\/\/wvmetronews.com\/2023\/05\/15\/facial-recognition-technology-coming-to-west-virginia-schools\/\">Fayette County Schools<\/a> in West Virginia has been fingerprinting students for building access for nine years and is now deploying Verkada cameras with facial recognition.<\/p>\n\n\n\n<p>The superintendent explained that \u201cthe more technology and tools we have, I would have to say, the better off we are.\u201d<\/p>\n\n\n\n<p>Pearson, which runs 21 million certification exams a year, <a href=\"https:\/\/www.pearsonvue.com\/us\/en\/about\/news\/2026\/pearson-adds-redrock-biometrics-palmid.html\">announced<\/a> in January that it\u2019s rolling out palm-print biometrics across its global testing network by mid-2026, layering palm-print scanning on top of the palm-vein system it has used since 2006.<\/p>\n\n\n\n<p>Your hand is now a login credential, and the mathematical representation of your palm sits on a server somewhere. Vendors love to point out that they don\u2019t store actual fingerprint images, just numerical templates. This is technically true and practically meaningless, because the templates are linked to student names and IDs, and they\u2019re stored on servers defended by the same industry that just let ShinyHunters walk off with 3.65 terabytes of student data through an unverified free account.<\/p>\n\n\n\n<p>Then there\u2019s what students write, think, and search for. Gaggle, GoGuardian, Securly, Bark, and Lightspeed have built a multi-billion-dollar industry on the premise that every word a child types on a school-issued device should be read by an algorithm in real time.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.gaggle.net\/blog\/speaks\/what-we-stand-for\">Gaggle<\/a> alone tracks approximately six million students across 1,500 school districts, scanning emails, documents, and chat messages around the clock.<\/p>\n\n\n\n<p>According to the Center for Democracy and Technology, 81 percent of teachers say their schools use some form of student monitoring software, and only one in four say the monitoring stops when school hours end.<\/p>\n\n\n\n<p>The rest of the time, these systems are watching students at home, on evenings and weekends, reading their Google Docs drafts and flagging their Canvas messages.<\/p>\n\n\n\n<p>But here\u2019s the part relevant to the Canvas breach. Every one of these surveillance systems generates data. Gaggle archives student communications for \u201ccompliance.\u201d GoGuardian logs browsing histories. Securly builds behavioral profiles. All of it flows to vendor servers under the same FERPA \u201cschool official\u201d exception that lets Instructure hold billions of private messages. All of it sits there, accumulating, because no one told anyone to delete it. And all of it will be part of the next breach.<\/p>\n\n\n\n<p>Gaggle, to its credit, offers a wonderfully precise summary of what it does and doesn\u2019t monitor. It \u201cdoes not monitor students\u2019 social media accounts, personal email accounts, personal devices, or web browsers.\u201d It does monitor \u201ccontent and activity, such as documents or chat messages, produced using a school-owned device, email address, or online tools within Google Workspace for Education, Microsoft 365, Google Chat, Microsoft Teams, and the Canvas learning management system.\u201d So it doesn\u2019t monitor your personal stuff. It just monitors everything you do on the device the school gave you, the email the school assigned you, and the learning platform the school requires you to use.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The hoarder\u2019s paradise<\/h2>\n\n\n\n<p>Instructure\u2019s privacy policy says it keeps your data \u201cfor as long as we have a legitimate business need to do so or as required by law.\u201d If that sounds like it could mean anything, that\u2019s because it can. \u201cLegitimate business need\u201d is whatever Instructure decides it is. The policy doesn\u2019t specify how long your Canvas messages stick around, whether they get deleted when you graduate, or what happens to them if your school switches to a different LMS.<\/p>\n\n\n\n<p>Instructure was acquired by KKR and Dragoneer Investment Group for $4.8 billion in November 2024. The company has a stated goal of reaching $1 billion in revenue by 2028.<\/p>\n\n\n\n<p>Under private equity ownership, data is a balance sheet item. Minimizing data, holding less, deleting sooner, means destroying value. The company that couldn\u2019t isolate free trial accounts from its production servers is being run on a growth timeline set by a private equity firm.<\/p>\n\n\n\n<p>If you were looking for an explanation of why Instructure built a customer acquisition program that shared infrastructure with the private messages of 275 million students, you could do worse than look at who writes the checks.<\/p>\n\n\n\n<p>Instructure will improve its security. ShinyHunters will find a new target. The lawsuits will settle and the fundamental architecture will remain: students conscripted into platforms they didn\u2019t choose, surveilled by software they don\u2019t know about, identified by biometrics they can\u2019t revoke, generating data they can\u2019t control, all of it stored by companies whose financial incentives point in the opposite direction from the students\u2019 interests.<\/p>\n\n\n\n<p>The 275 million people whose data was stolen from Canvas this month are trusting the word of a criminal hacking group that their private messages have been deleted.<\/p>\n\n\n\n<p>At some point in the future, the breach won\u2019t just be messages. It\u2019ll be the fingerprints, the surveillance logs, the behavioral profiles, and the mental health disclosures that schools have been enthusiastically collecting ever since.<\/p>\n\n\n\n<p>Every new data point a school adds to the pile is a gift to the next ShinyHunters. And right now, schools are giving very generously.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How has this been slipping through the cracks, abusing student&#8217;s privacy? https:\/\/reclaimthenet.org\/the-school-spy-boom-nobody-asked-for Somewhere between the biometric lunch lines and the 24\/7 monitoring software, American education became a data hoarding operation with a teaching problem. By Christina Maas Instructure, the company that runs Canvas, the learning management system used by 41 percent of North American universities, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,7],"tags":[],"class_list":["post-17275","post","type-post","status-publish","format-standard","hentry","category-tech","category-world"],"blocksy_meta":[],"featured_image_src":null,"author_info":{"display_name":"Jason","author_link":"https:\/\/jasonsblog.ddns.net\/index.php\/author\/jturning\/"},"_links":{"self":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17275","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/comments?post=17275"}],"version-history":[{"count":1,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17275\/revisions"}],"predecessor-version":[{"id":17276,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/posts\/17275\/revisions\/17276"}],"wp:attachment":[{"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/media?parent=17275"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/categories?post=17275"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jasonsblog.ddns.net\/index.php\/wp-json\/wp\/v2\/tags?post=17275"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}