CREATIVE COMMONS ATTRIBUTION 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE 4.0 INTERNATIONAL PUBLIC LICENSE security (HSTS) headers, which is a web security policy mech- INTRODUCTION anism that helps to protect websites by using only secure HTTPS connecons. The Common Sense Privacy Evaluaon Iniave is a coordi- The release of this 2018 State of EdTech Security Survey nated effort to evaluate educaon technology (edtech) tools, represents a yearly examinaon of security pracces of edu- protect student privacy, and build in privacy and security caon technology-related online services using our security from the start.1 The Common Sense Privacy Evaluaon Inia- assessment. In 2016 Common Sense privacy ran its inial ve helps clarify privacy policies so teachers can make smart encrypon survey to determine a baseline for the state of choices about the learning tools they use with students and edtech security. Then, in 2017, Common Sense privacy ran so schools and districts can parcipate in evaluang the tech- the encrypon survey again and released our findings, which nology used in K–12 classrooms. Common Sense privacy has showed posive but non-significant trends in the edtech in- been collecng and incorporang feedback from stakehold- dustry with increasing encrypon since 2016, but with clear ers about how to share the results of our privacy evaluaons room for improvement. This 2018 security survey includes since we began this work in 2015. Since that me, Common results from over 2,000 URLs of popular edtech online ser- Sense privacy has spoken with numerous teachers, students, vices. To determine this sample set, we interviewed various parents, developers, vendors, privacy advocates, and indus- teachers, schools, and districts about which services they try representaves about their perspecves on privacy and had used during the 12 months prior to the security survey. security. This research led to the design of a 180-queson This is an increase in products scanned from 1,121 edtech evaluaon framework designed to analyze privacy policies products in 2017 and 1,100 edtech products in 2016. These and create a profile of each edtech product’s privacy and se- services provide a representave sample of the wide range of curity pracces. educaonal technologies, including educaonal games and In May 2018, Common Sense privacy released its ground- tools, for communicaon, collaboraon, formave assess- breaking 2018 State of EdTech Privacy Report.2 The report rep- ment, student feedback, content creaon, and delivery of resents the culminaon of Common Sense privacy’s research instruconal content. These types of services are currently over the previous three years, including the evaluaon of used by millions of children at home and by tens of millions hundreds of educaon technology-related applicaons and of students in classrooms across the . services. In this report, Common Sense privacy went beyond Our overall findings in 2018 indicate a significant increase in evaluang individual edtech products and captured a snap- the percentage of services that both support and require en- shot of the edtech industry as a whole. Common Sense pri- crypon. In addion, our findings indicate that there was a vacy’s overall findings in the privacy report are illustrave of modest decrease in the percentage of services that support current trends in the edtech industry including a widespread encrypon, but do not require encrypon. However, there lack of transparency and inconsistent privacy and security was no significant change in the percentage of services that pracces. implement HSTS. These findings illustrate that the edtech in- dustry has made significant improvement in its use of encryp- Good security, however, is not stac. Edtech industry secu- on of personal informaon over the past three years, but, rity pracces may be – indeed, should be – updated in re- given that 22 percent of edtech products sll do not require sponse to current events and improvements in technology. encrypon, the industry has a long way to go to improve its Aer the release of the privacy report, Common Sense pri- security pracces. vacy immediately began to update its security findings. In or- der to have a solid foundaon for privacy, edtech providers Security pracces of edtech providers should have a higher must also have adequate security pracces. Therefore, in ad- standard than the industry standard for online services and dion to evaluang privacy policies, Common Sense privacy applicaons generally given the potenally sensive nature ulized a comprehensive security assessment to determine of personal informaon that may be gathered from children whether the evaluated edtech products supported encryp- and students. These crucial observaons are whether an on with the return of successful status codes. Edtech prod- edtech service: 1). supports encrypon; 2). requires encryp- ucts that responded successfully were surveyed to deter- on; 3). supports encrypon and requires encrypon; and 4). mine whether they also required encrypon with hypertext supports encrypon and uses HSTS direcves in its headers. transfer protocol (HTTP) to HTTP secure (HTTPS) redirec- Given the size of the sample and the tools used to evaluate on and whether they implemented HTTP strict transport the edtech products, our key findings in the security survey hold a mirror up to the security pracces of the edtech in- 1 Common Sense Media. “Privacy Evaluaon Iniave,” https://www. dustry as a whole. commonsense.org/education/privacy. 2Kelly, Girard, Jeff Graham, and Bill Fitzgerald. 2018 State of Edtech Privacy, https://www.commonsense.org/blog/2018-state-of-EdTech- privacy-report.

CREATIVE COMMONS ATTRIBUTION 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE 1 4.0 INTERNATIONAL PUBLIC LICENSE Our 2018 security survey key findings indicate: panded beyond the right to be le alone to the right to con- trol your personal informaon. Further, this expanded mean- 1. A significant increase from 2017 of 16 percent in the ing of privacy has taken on new prominence in the digital percentage of services that support encrypon. world. Privacy includes the ability to control your informa- 2. A significant increase from 2017 of 22 percent in the on, who has access to it, and what it is used for – including percentage of services that require encrypon. what decisions are made because of it. To effectuate privacy, security needs to expand in scope as well, to take on the re- 3. A modest decrease from 2017 of 6 percent in the per- sponsibility of protecng these individual decisions. Security centage of services that support encrypon, but do not involves the protecon of a user’s control of their personal require encrypon. informaon, as well as protecon of a vendor’s systems and 4. No significant change from 2017 in the percentage of products from outside influences. services ( 14 percent) that support encrypon and im- plement HSTS. Focus on Encrypon This survey would not have been possible without support from the Privacy Evaluaon Iniave Consorum, which in- Using encrypon to protect data in transit is widely recog- cludes over 150 schools and districts that help inform Com- nized as a best pracce and even, in some cases, a legal re- mon Sense privacy’s work and use the privacy evaluaons quirement to sasfy a “reasonable” standard of security. To and security informaon as part of their veng process for illustrate this preference, priorizes encrypted sites educaonal applicaons and services used in the classroom.3 in its search results, and the browsers Chrome and Firefox The latest findings in the security survey were prepared by show warnings if unencrypted content is shown on a web- the Privacy Evaluaon Iniave team members, which in- page. The lack of encrypon on a site means that informaon clude Girard Kelly, Jeff Graham, Jill Bronfman, and Steve Gar- flowing to and from the user to the site host could poten- ton, all of whom are leaders and experts in the fields of pri- ally be read in plain text along the way – a parcular danger vacy and security, and our 2018 privacy intern, Irene Lee. on unsecured wireless networks – or intercepted en route Our Common Sense privacy team has diverse backgrounds and replaced with other, perhaps dangerous or misleading, in educaon, entrepreneurship, computer science, ethics, content. Even so, Common Sense privacy only applied its law, academia, and public policy. Common Sense privacy be- red “Not Recommended” privacy evaluaon er to sites that lieves that advocacy, parental choice, and school-based de- do not encrypt registraon, login, or pages accessed while a cision making will be more effecve if users are provided user is logged in – an extremely low bar.4 Fortunately, most with comprehensive and up-to-date informaon on the state edtech providers did meet this low bar. Findings from the of security for edtech applicaons and services. Common privacy report indicate that a majority of applicaons and Sense privacy hopes this data will help show the impact that services, approximately 92 percent, use HTTPS encrypon security pracces have on the lives of millions of children of informaon for login and account creaon. and students who use educaonal technology every day and help support meaningful and posive changes in those prac- ces. The following secons will discuss background on the security survey performed in 2016 and 2017, our method- Background ologies, results, categorical concerns, and key findings regard- ing the security pracces used by over 2,000 popular edtech applicaons and services. Preliminary Survey in 2016

In the fall of 2016, Common Sense privacy conducted a sur- vey of 1,221 edtech products used in schools or by young EdTech Security people.5 Common Sense privacy tested only login URL lo- caons because that is where personal or sensive informa- Privacy vs. Security on is collected. The inclusive goal of the encrypon sur- vey was to allow people to be able to run these tests them- selves without any addional technical training. School dis- Privacy and security are intertwined, and security is the trict staff, parents, students, people in STEM classes, people foundaon of effecve individual privacy. For example, en- crypon of supports the privacy of communica- 4Common Sense Media. “Evaluaon Tiers,” https://www.commonsense. ons contained therein. The understanding of privacy has ex- org//privacy/about/evaluation-tiers. 5Common Sense Media. “Encrypon Support - an Inial Survey,” 3Common Sense Media. “School Districts Inform Our Work,” https:// 1 Dec. 2016, https://www.commonsense.org/education/privacy/blog/ www.commonsense.org/education/privacy/about/districts. encryption-support-initial-survey.

2 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE commonsense.org/educaon/privacy learning how to code, and vendors all can have visibility into quire encrypon on login – that is, they enforce secure inter- this evaluaon process. This test is not complicated, and if acons between the browsers used by students and teach- a developer is launching a new edtech service, this type of ers and their websites upon exchange of user credenals tesng is a crical part of product development. Common such as usernames and passwords.12 Sites that are secure Sense privacy goes into more detail about addional security have an “https://” in the URL and are visually indicated with tesng in the Informaon Security Primer, but this basic en- a green lock next to it in most browsers on such pages. This crypon test script is an easy starng point.6 To make Com- level of security is a best pracce that should be standard mon Sense privacy’s work both more transparent and more in the industry. The standard means no one can read some- accessible, Common Sense privacy has been able to release one’s personal informaon, even on an open wireless net- this encrypon test publicly under an open-source license.7 work, and even contributes to something as basic as search The repository contains documentaon that describes how engine rankings. It is important to understand that this list to scan individual URLs of edtech products and how to batch- only covers applicaons with logins over the web. It does scan hundreds or even thousands of URLs.8 9 For vendors, not cover mobile applicaons yet. However, including mo- Common Sense privacy strongly recommends using this en- bile applicaons in our encrypon survey and on our list of crypon test to check the login URLs of all your products secure edtech products is on Common Sense privacy’s road as part of your security pracces. A school or district could map for the future. use this encrypon survey as part of a quick triage when it As part of publishing this list of vendors and websites, Com- is evaluang whether to incorporate new technology in the mon Sense privacy notes that it is important to clarify what classroom. Common Sense privacy has incorporated these this list means and what it does not mean. There are many checks as part of the evaluaon process and intends to con- good reasons a vendor might not be on this list, including: nue to expand automated checks of more edtech products in the future. 1. The vendor only offers a private login for subscribers; 2. The vendor’s service does not require a login; In addion, on some sites, different “user-agent-strings” are 3. The vendor’s login varies based on client, so every cus- treated differently.10 User-agent (UA) strings are contained tomer has a different subdomain; or in HTTP headers and are intended to idenfy devices re- 4. Common Sense privacy has not yet tested the specific quesng online content. In praccal terms, this allows sites vendor at this me. to use encrypon with some browser agents and not use it with others. When Common Sense privacy moves forward to Therefore, just because a vendor is not listed does not mean scanning connected devices and the Internet of Things (IoT), the vendor failed our encrypon survey. Common Sense pri- it will be important to note that this is one reason the secu- vacy’s list is representave but not all-inclusive, and it is grow- rity of connected devices lags behind that of many other ser- ing all the me. Common Sense privacy will connue to run vices: Some sites explicitly allow connected devices to send this survey yearly and update the list in the Appendix ac- informaon through unencrypted connecons while other cordingly. The list of sites surveyed comes from the districts devices support encrypon.11 The future of security may de- supporng the Privacy Iniave, and the sites are among the pend on how well we can secure these incredibly proliferat- most popular services used in classrooms and for homework ing connected devices going forward. by K–12 students.

When Common Sense privacy ran the first survey in Octo- ber 2016, there were many long conversaons about how Encrypon List to share the results.13 In these conversaons, publishing a list of sites that did not support encrypon on login was As a result of our research, Common Sense privacy has pub- not widely supported. The intenon was to increase trans- lished a list of vendors and websites that both support and re- parency rather than cricize or rate companies. Common Sense privacy does this work to provide resources so we 6 Common Sense Media. Informaon Security Primer for Evaluang can all do a beer job creang and using technology to sup- Educaonal Soware, https://www.commonsense.org/education/privacy/ 14 security-primer. port inquiry. Common Sense privacy has spent a significant 7Common Sense Media. “README.md,” https://github.com/ amount of me talking with vendors, teachers, district staff, commonsense-org/scanner. 8Common Sense Media. “check.md,” https://github.com/commonsense- 12Common Sense Media. List of Sites with Encrypted Logins, https:// org/scanner/blob/master/examples/check.md. www.commonsense.org/education/privacy/sites-with-encrypted-logins. 9Tange, Ole. “GNU Parallel: The Command-Line Power Tool.” ;login: The 13Common Sense Media. “Surveying Encrypon Pracces of Technology Usenix Magazine, vol. 36, num. 1, Feb. 2011, pp. 42-47. Used Within Schools,” https://www.commonsense.org/education/privacy/ 10Piejko, Pawel. “List of User Agent strings.” DeviceAtlas, 7 March 2018, survey/encryption. https://deviceatlas.com/blog/list-of-user-agent-strings. 14Common Sense Media. “Informaon Security Primer for Evaluang 11Common Sense Media. “allow seng User-Agent #1,” https://github. Educaonal Soware,” https://www.commonsense.org/education/privacy/ com/commonsense-org/scanner/issues/1. security-primer.

CREATIVE COMMONS ATTRIBUTION 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE 3 4.0 INTERNATIONAL PUBLIC LICENSE parents, and students, and the overwhelming majority of in- ogy industry. To that end, this security survey is intended to dustry professionals strives to meet security standards and increase transparency and access to informaon for vendors provide secure products. With the Privacy Evaluaon Inia- and for their customers. Across the industry, Common Sense ve, Common Sense privacy looks to honor and respect that privacy’s work on transparency of encrypon pracces has intent. In 2016 and 2017, over 600 edtech websites were sought to unite all the stakeholders in seeking beer security listed as meeng basic encrypon standards, while over 500 for informaon collected from children and students. either did not require or enforce encrypon. In this inial year of research and evaluaon of results, the hope was that the number of websites that support encrypon, as a pro- poron of edtech sites and vendors we survey, would sub- METHODOLOGY stanally increase in the coming years. In 2018 we now have over 1,000 edtech websites currently listed in the Appendix The encrypon survey methodology used by Common Sense as meeng basic encrypon standards. Going forward, we privacy has not changed between the inial 2016 survey, the expect that this process of encouragement rather than crit- updated survey in 2017, and our current 2018 survey. Our icism will support transparency and yet another increase in methodology has connued to cover the same security met- the number of compliant vendors. rics, including what was incorporated in as well as outside the scope of this survey. As Common Sense privacy described in the first iteraon of the survey, encrypon is a basic require- Updated Survey in 2017 ment for edtech products that collect usernames, passwords, and other personally idenfiable informaon. Using encryp- on to protect data in transit is widely recognized as a best In early March of 2017, Common Sense privacy ran its en- pracce and, in some cases, has been designated as a com- crypon tests on 1,215 logins used by 1,121 unique edtech ponent of a “reasonable” standard of security. products used in schools and by youth. This was a follow-up survey from research we began in October 2016.15 These This survey performed four acons at each URL locaon: new results indicated that there had been measured improve- 1. Sent an HTTP request to the login URL and checked ment between October 2016 and March 2017. In October the HTTP status code (i.e., asked whether HTTP was 2016, 52 percent of the 1,221 login URLs we surveyed re- supported); quired encrypon, 25 percent did not support encrypon at all, and an addional 20 percent did not require encrypon. 2. Sent an HTTPS request to the login URL and checked As of March 2017, 56 percent required encrypon, 23 per- the HTTP status code (i.e., asked whether HTTPS was cent did not support encrypon at all, and 18 percent sup- supported); ported, but did not require, encrypon. The results indicated a modest increase of 4 percent in the number of sites that re- 3. Sent an HTTP request to access the login URL to quired encrypon at login and a small decrease of 2 percent see whether the site redirected to HTTPS (i.e., asked in the number of sites that failed to fully support encrypon. whether HTTPS was required); and This was progress, even if 44 percent of edtech websites sur- 4. Inspected the URL header for the presence of HTTP veyed in 2017 sll did not require encrypon. Strict Transport Security (HSTS) direcves.

As Common Sense privacy observed in its 2017 survey, since The results of the survey are an indicator – not an abso- 2016 there was sll a lack of support for encrypon from lute measure – of how edtech services encrypt informaon some of the vendors, and these gaps in encrypon prac- passed during login. They provide an accurate representaon ce were found in vendors of all sizes. Results indicated that of trends across the products surveyed, but an authoritave encrypon was absent in some products across the board, statement about any specific product would require a more including products offered by small firms, early and middle- detailed evaluaon assessment.16 stage start-ups, midsize privately held companies, and enter- prise vendors operang in thousands of districts with millions In evaluang the survey results, we categorized each edtech of learners. From the onset, Common Sense privacy intended product according to whether it met the following criteria: to connue to conduct this survey on a regular basis and doc- • Supports encrypon; ument the trends observable in the results. Connuing and • Supports encrypon and requires encrypon; prospecvely increased support for encrypon is one proxy • Supports encrypon and uses HSTS direcves in its for safe and secure pracces across the educaonal technol- headers; or

15Common Sense Media. “Encrypon Support - an Inial Survey,” 16Common Sense Media. “Surveying Encrypon Pracces of Technology 1 Dec. 2016, https://www.commonsense.org/education/privacy/blog/ Used Within Schools,” https://www.commonsense.org/education/privacy/ encryption-support-initial-survey. survey/encryption.

4 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE commonsense.org/educaon/privacy • Does not use encrypon at all. previous years, we treat response codes in the range of 200- 399 as successful server responses.17 All other responses are considered non-successful. A response code of 0 likely indicates an issue with the server configuraon or lack of 2018 RESULTS support for HTTPS. Errors in the range of 400 or above indi- cate some form of error either in the request or in the server response. Approximately 89 percent of the 1,428 login URLs The results from our 2018 encrypon survey examined returned a successful status code in response to an HTTPS over 2,000 unique edtech products to determine whether request. The following chart illustrates HTTP and HTTPS sta- they support encrypon with the return of successful status tus responses codes: codes. This is an increase in products scanned from 1,215 edtech products in 2017, and 1,221 edtech products in HTTPS Status Codes 2016. Edtech products that respond successfully were sur- 100% veyed to determine whether they also required encrypon with HTTP to HTTPS redirecon and whether they imple- 75% mented HTTP strict transport security (HSTS) headers. The

following results summarize our 2018 findings of edtech 50% products scanned that returned a successful status code;

support encrypon; require encrypon; support encrypon, Percentage 25% but do not require encrypon; support encrypon and use HSTS direcves in their headers; do not use encrypon at 0% all; and need further review. 2016 2017 2018 Year

0 200 3xx 4xx 5xx Products Scanned Figure 1: This chart illustrates the comparison of HTTPS re- sponse codes across all three years. The 2018 encrypon survey scanned 1,428 edtech products that observaonally displayed a registraon or login URL; these URLs are used by visitors to provide personal infor- Table 1: This table illustrates the percentage of HTTPS status maon to log into and use the service. Among the 1,428 codes returned from a HTTPS request. scanned login URLs 18 percent include login pop-ups which are visually disnguished from login URLs because the collec- Year 0 200 3xx 4xx 5xx on of personal informaon may occur on any URL through 2016 0.20 0.71 0.07 0.01 0 a separate visual element that is layered (or that pops up) 2017 0.18 0.75 0.06 0.01 0 on top of the main webpage. Login pop-ups do not clearly 2018 0.09 0.88 0.01 0.01 0 display a separate login URL, but sll provide the opportu- nity for a visitor to provide personal informaon to the ser- vice. For the purposes of this survey, the encrypon results of the base or homepage URL is used as a proxy for any corresponding login URL if the site displays a login pop up. Supports Encrypon Lastly, among the 1,428 URLs scanned approximately 2 per- cent responded successfully to HTTPS requests but not to Similar to previous years we use the classificaons of: does HTTP requests. This means for a small subset of products the not support encrypon; supports, but does not require en- “HTTP redirects to HTTPS” response is largely irrelevant, as crypon; requires encrypon; and needs review. The 2018 the infrastructure is configured to not respond to any HTTP survey found that approximately 90 percent of the 1,428 lo- requests. gin URLs scanned supported encrypon. However, only ap- proximately 9 percent of login URLs scanned sll did not sup- port encrypon, and a small amount of responses, approxi- mately 1 percent, fell into our “needs review”” classificaon. Successful Status Codes In 2016, approximately 25 percent of login URLs scanned did not support encrypon, while approximately 23 percent A successful HTTPS response from a web request can in- of login URLs scanned in 2017 did not support encrypon.

dicate several factors about the configuraon of the server 17Wikipedia. “List of HTTP status codes,” https://en.wikipedia.org/wiki/ that include the server’s support for encrypon. Similar to List_of_HTTP_status_codes.

CREATIVE COMMONS ATTRIBUTION 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE 5 4.0 INTERNATIONAL PUBLIC LICENSE The 2018 results demonstrate a significant improvement 2016 study, where the results indicated that approximately compared to previous years and indicate a decreasing trend 20 percent of the login URLs surveyed supported encryp- in the percentage of edtech products that do not support en- on, but did not require it. In addion, this finding is also a crypon on login. These findings would appear to suggest an modest decrease from the 2017 study, which reported that increased awareness of encrypon on the part of the edtech 18 percent of login URLs supported, but did not require en- vendors who understand the importance of encrypng per- crypon. sonal informaon on login and a realizaon that customers have come to expect educaonal sites that collect any per- sonal informaon should use encrypon. HTTP Strict Transport Secu- Level of HTTPS support rity (HSTS) Headers 100%

75% The 2018 survey found that only approximately 13 per- cent of the 1,428 login URLs implemented HSTS headers. 50% This means the remaining 87 percent did not implement HSTS headers which indicated that those that did implement Percentage 25% HTTPS encrypon were sll potenally exposing users to a 0% man-in-the-middle (MITM) aack.18 In 2016, only approxi- 2016 2017 2018 mately 14 percent of login URLs surveyed used HSTS direc- Year ves. Likewise, in 2017, only 14 percent of login URLs sur- veyed used HSTS direcves. This consistently low percent- Does not support Supports, but does not require age of HSTS deployments most likely demonstrates a lack of Requires Needs review resources and understanding of the importance of HSTS in the educaonal seng. These percentages can be expected Figure 2: This chart illustrates the comparison of HTTPS sup- to increase if the expectaon of adequate security pracces port across all three years. for the edtech community extends beyond use of a basic HTTPS protocol moving forward. Table 2: This table illustrates the percentage of login URLs that require encrypon, support but does not require encryp- Table 3: This table illustrates the percentage of login URLs on, does not support encrypon and that need further re- that implement HTTP Strict Transport Security (HSTS) head- view across all three years. ers across all three years.

2016 2017 2018 Year HSTS Does not support 0.25 0.23 0.09 2016 0.14 Requires 0.52 0.56 0.78 2017 0.14 Supports, but does not require 0.20 0.18 0.12 2018 0.13 Needs review 0.03 0.03 0.01

Requires Encrypon

The 2018 survey found that approximately 78 percent of lo- gin URLs required encrypon. In contrast, only 56 percent of login URLs in 2017 and 52 percent of login URLs in 2016 required encrypon by redirecng HTTP requests to HTTPS. The 2018 results are a significant improvement compared to previous years and an indicaon of an increasing trend in the percentage of edtech products that require encrypon on login.

Addionally, in 2018 the survey found that approximately 12 percent of login URLs supported encrypon, but did not re- 18Open Web Applicaon Security Project. “Man-in-the-middle aack,”” quire it. This finding is similar to the results obtained in the https://www.owasp.org/index.php/Man-in-the-middle_attack.

6 2018 STATE OF EDTECH SECURITY SURVEY, COMMON SENSE PRIVACY EVALUATION INITIATIVE commonsense.org/educaon/privacy support edtech vendors in implemenng encrypon, such CONCLUSION as the Open Web Applicaon Security Project’s Guide to Cryptography. Further, Common Sense privacy encourages Between October 2016 and March 2017, Common Sense readers of this survey to conduct addional research and privacy observed a non-significant increase in the percent- examine how sites they use support encrypon. Change can age of edtech products with support for encrypon. The be difficult, but acknowledging the discrepancies between 2018 results indicate marked improvement in the percentage best pracces in security and reality is important, and the of support for encrypon over our previous surveys. How- transion to using encrypon to protect educaonal data is ever, edtech vendors sll fail to deploy HTTPS sengs in essenal and long overdue in 2018. Common Sense privacy configuraons that maximize the efficacy of the security pro- believes industry awareness and consumer expectaon tecons in place. It is our hope that more vendors will redi- will drive beer security pracces that include support for rect all HTTP requests to HTTPS as well as properly imple- encrypon as technology plays an ever increasing role in ment HSTS headers to ensure adequate protecon of per- the educaon community moving forward. sonal informaon. As discussed in the 2016 survey, encryp- on is a foundaonal step that sites must take to support basic security and privacy. If a site does not support encryp- on, many schools and districts will not even consider using it. Common Sense privacy strongly encourages stakeholders to evaluate how sites support encrypon and raise aware- ness about the importance of encrypon of personal and sensive informaon with vendors, developers, or other in- terested pares. In addion to the resources provided in this security survey, Common Sense privacy encourages these stakeholders to use Common Sense privacy’s freely available toolkit.19

The need for strong encrypon to protect informaon passed to a site is broadly accepted.20 Both Firefox and Chrome already integrate stronger warnings into their browsers when sites do not support encrypon, and the use of strong encrypon of data in transit is widely recognized as part of what constutes “reasonable security.” Before receiv- ing the results of our 2018 survey, Common Sense privacy ancipated that less than 5 percent of all websites would fail to require encrypon due to various factors. Instead our results indicated that approximately 22 percent of websites failed to require encrypon.

Common Sense privacy remains commied to highlighng beer pracces to improve the state of security in the edtech industry. Publicly available resources, such as our 2017 list of websites that require encrypon and our current list from 2018, which is available in the Appendix of websites that require encrypon as defined in this survey, are helpful to the extent that they allow consumers to make informed decisions about whether or not to use a product given its support for encrypon at the me of the survey.21 In addion, there are other resources freely available to

19Common Sense Media. “Freely Available Tools to Check for Encryp- on” Feb. 2017, https://www.commonsense.org/education/privacy/blog/ freely-available-tools-to-check-for-encryption. 20Schneier, Bruce, “Why We Encrypt.” Schneier on Security, https://www. schneier.com/blog/archives/2015/06/why_we_encrypt.html. 21Common Sense Media. “Announcing the List of Sites That Require Encrypted Login,” April 2017, https://www.commonsense.org/education/ privacy/blog/list-of-sites-that-require-encrypted-login.


