social.heise.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Der Mastodon-Server von und für Heise Medien und insb. die Nachrichten von heise online.

Serverstatistik:

38
aktive Profile

#bvsd

0 Beiträge0 Beteiligte0 Beiträge heute
Andrew 🌻 Brandt 🐇<p>Last night I attended the <a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> BVSD school district's District Accountability Committee meeting. I am the representative to my kids' high school at the DAC, that advises the school board on policy matters. It's a commitment I made to staying involved in local school operations, regardless of the outcome of the election last year.</p><p>The DAC is considering updates to policies surrounding the searches of and interrogations of students on school grounds. The DAC policy subcommittee made several positive changes that strengthen the protections this policy gives to students, who under these kind of circumstances are obviously in a power-imbalance situation.</p><p>But there was one change that I couldn't abide, and when I brought it up, it started a nearly hourlong debate in which many other DAC representatives chimed in with their own concerns.</p><p>The change was to give schools the permission to search students' mobile devices and laptops. It was a one-line insertion into an existing policy that gives school officials permission to search student lockers. </p><p>I made the point that phones/laptops often contain highly sensitive, personal information that falls outside the scope of any legitimate investigation, and that the language was overbroad and failed to take into account the need for student data privacy and limiting the scope of the search, and raises significant civil rights issues.</p><p>Another DAC member raised the issue that the policy seems to lay the responsibility for students maintaining the security of their devices on the students, even when an adult has access to those devices, which seemed weirdly out of sync.</p><p>Yet another DAC member was concerned that there was no guidance about how such searches would be conducted, and under what circumstances. Doesn't changing a policy like this lead to potential 'fishing expeditions' on specious evidence or even just allegations of misbehavior without evidence? </p><p>In the end, the DAC thought this policy would sail through and be passed along to the BVSD board for their approval next week. I think the policy needs significant rework and there's no way the board should pass it in its current form. I will speak at the school board meeting next week to get that point across, because the way it looks right now, I would not want my name connected to this policy.</p><p><a href="https://infosec.exchange/tags/COpolitics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>COpolitics</span></a> <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> <a href="https://infosec.exchange/tags/SchoolBoard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolBoard</span></a> <a href="https://infosec.exchange/tags/policy" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>policy</span></a> <a href="https://infosec.exchange/tags/electmorehackers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>electmorehackers</span></a> <a href="https://infosec.exchange/tags/4thAmendment" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>4thAmendment</span></a> <a href="https://infosec.exchange/tags/PolicyHackers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>PolicyHackers</span></a> <a href="https://infosec.exchange/tags/education" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>education</span></a> <a href="https://infosec.exchange/tags/USPol" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>USPol</span></a></p>
Andrew 🌻 Brandt 🐇<p>Well I didn't win my election, but my interest in <a href="https://infosec.exchange/tags/SchoolBoard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolBoard</span></a> policy is not going away.</p><p>Tonight, immediately after the new board members are sworn in, I will be presenting a public comment to <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> about their use of <a href="https://infosec.exchange/tags/GoGuardian" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>GoGuardian</span></a>, a technology that presents itself as a monitoring tool to ensure that kids visit age- and developmentally-appropriate websites on their school-issued laptops.</p><p>In October, the <a href="https://infosec.exchange/tags/EFF" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EFF</span></a> published a report about the privacy-invading and false-positive-prone tool. <a href="https://redflagmachine.com/research/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">redflagmachine.com/research/</span><span class="invisible"></span></a></p><p>The report highlights key problems about the software misidentifying benign websites with run-of-the-mill, unharmful content as potentially harmful or containing explicit content. Poetry by the Bronte sisters, the text of George Bernard Shaw’s Pygmalion, and even the text of Romeo and Juliet set off red flags. So did words in the Texas driver’s handbook, and health information websites. These false positive warnings are touted by GoGuardian not as a bug but as a desirable feature of the product.</p><p>My concern here is that routine use of GoGuardian sends two very damaging messages to students: It normalizes routine surveillance, and it tells students that they cannot be trusted to use their computers responsibly.</p><p>I will be giving public comment to the new board asking them to direct school administrators to investigate the district's contract with GoGuardian, and to seek out a less invasive, more accurate method of protecting children who use computers.</p><p>If you wish, you can watch the board proceedings on their youtube livestream, starting at 6pm MST (UTC-7). The link is <a href="https://www.youtube.com/@bouldervalleyschooldistric5781/streams" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/@bouldervalleyscho</span><span class="invisible">oldistric5781/streams</span></a></p><p><a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> <a href="https://infosec.exchange/tags/COPolitics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>COPolitics</span></a> <a href="https://infosec.exchange/tags/EdTech" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EdTech</span></a></p>
Andrew 🌻 Brandt 🐇<p>I've just posted my latest <a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> <a href="https://infosec.exchange/tags/SchoolBoard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolBoard</span></a> candidate newsletter. If you're not on my mailing list, check it out here: <a href="https://mailchi.mp/e442db061909/election-day-is-upon-us-sko-bvsd" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mailchi.mp/e442db061909/electi</span><span class="invisible">on-day-is-upon-us-sko-bvsd</span></a></p>
Andrew 🌻 Brandt 🐇<p>Hi folks. Yesterday I posted on my other Mastodon account about a pretty stupid gift card <a href="https://infosec.exchange/tags/scam" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>scam</span></a> that was sent to an email address I use as a political candidate for my run for <a href="https://infosec.exchange/tags/SchoolBoard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolBoard</span></a> (<a href="https://toot.bldrweb.org/deck/@andrewbrandt/111326617529695469" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">toot.bldrweb.org/deck/@andrewb</span><span class="invisible">randt/111326617529695469</span></a>)</p><p>Tonight, I received a more ominous, targeted <a href="https://infosec.exchange/tags/spearphishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>spearphishing</span></a> email against that same campaign address.</p><p>It appears to be some form of Adobe e-signature message. The text content was weird and off.</p><p>The email has a file attachment that, if you double-click it, opens a browser window and displays a form that looks like a login dialog box. The login box is a <a href="https://infosec.exchange/tags/phishing" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>phishing</span></a> attack, designed to steal credentials that you enter into it.</p><p>What was distinctive about this is the fact the attackers customized the login form so it has my campaign logo embedded within the form. It also pre-populated the username field with the email address that they sent the original email to. It was not generic; This was targeted.</p><p>The form will permit you to enter data into the password field three times, appearing to fail each time, and then redirects you back to your own website. It collects the IP address you were using at the time you submitted the form, and any of the passwords you submitted, and sends them to a <a href="https://infosec.exchange/tags/Telegram" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Telegram</span></a> bot account. </p><p>I have captured the network traffic of the phishing attempt, in which I entered bogus data, and have identified the owner of the Telegram bot account and other identifiable information. I'll be reporting it to Telegram for shutdown as soon as possible.</p><p>I guarantee, if this is happening to me -- a relative nobody in my lowly, local school board race -- it is happening all over the country to political candidates of any stature.</p><p>There is less than one week until election day in the United States. Colorado voters already have their ballots and can turn them in by dropping them in a ballot collection box anytime between now and election day.</p><p>Just another reason why we need to <a href="https://infosec.exchange/tags/ElectMoreHackers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ElectMoreHackers</span></a> </p><p>Also, once again: nice try, losers. Keep going. You're sure to hit pay dirt at some point. :ablobcateyeroll:​</p><p><a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> <a href="https://infosec.exchange/tags/COpolitics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>COpolitics</span></a></p>
Andrew 🌻 Brandt 🐇<p>Hey, hacker fam. Quick update on what's going to be a big week.</p><p>Tomorrow I'm flying out to Bellevue and Wednesday I'm speaking at <a href="https://infosec.exchange/tags/BlueHat" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BlueHat</span></a> about the work <span class="h-card" translate="no"><a href="https://infosec.exchange/@SophosXOps" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>SophosXOps</span></a></span> has done helping <a href="https://infosec.exchange/tags/Microsoft" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Microsoft</span></a> protect all Windows users from a very devious attack.</p><p>After I return, I'm in full-swing campaign mode running for the <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> <a href="https://infosec.exchange/tags/SchoolBoard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolBoard</span></a>. I've been doing door-knocking and meet-and-greet for days. Yesterday I spent hours giving out water to marathon runners here in <a href="https://infosec.exchange/tags/boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>boulder</span></a> </p><p>Next week though - I'll be participating in a candidate forum hosted by BVSD and you will be able to watch it live from anywhere because it will be broadcast by <a href="https://infosec.exchange/tags/livestream" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>livestream</span></a> on BVSD's Youtube channel (<a href="https://www.youtube.com/@bouldervalleyschooldistric5781/streams" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/@bouldervalleyscho</span><span class="invisible">oldistric5781/streams</span></a>). October 18 from 6pm-7:30pm MDT (UTC -6)</p><p>You can read up now on the forum and ** you can even submit questions.** </p><p>If you work in <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> or fight <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>malware</span></a> like me, I'd like you to submit questions to the forum. You can send in questions about <a href="https://infosec.exchange/tags/ChatGPT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ChatGPT</span></a> or any other subject, as long as it pertains to public education in some way. The link to submit questions and get more information (including a detailed look at my platform) is here: <a href="https://www.impactoneducation.org/event/2023-bvsd-board-of-education-candidate-forum/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">impactoneducation.org/event/20</span><span class="invisible">23-bvsd-board-of-education-candidate-forum/</span></a></p><p>I try not to clutter up the infosec feed with this stuff, so for more, follow <span class="h-card" translate="no"><a href="https://toot.bldrweb.org/@andrewbrandt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>andrewbrandt</span></a></span> </p><p>Together, we're going to <a href="https://infosec.exchange/tags/ElectMoreHackers" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ElectMoreHackers</span></a></p>
Andrew 🌻 Brandt 🐇<p>NBD, just got to march in a Labor Day parade in Louisville, CO because I am a candidate for local office. Got a chance to shake hands with my rockstar congressman Joe Neguse and thank Colorado's Secretary of State Jena Griswold for helping defend democracy in 2020 and beyond. </p><p>Pretty sure this was the first time any participant in the parade wore a <a href="https://infosec.exchange/tags/Defcon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Defcon</span></a> speaker badge!</p><p><a href="https://infosec.exchange/tags/SchoolBoard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SchoolBoard</span></a> <a href="https://infosec.exchange/tags/COPolitics" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>COPolitics</span></a> <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> <a href="https://infosec.exchange/tags/LaborDay" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LaborDay</span></a> <a href="https://infosec.exchange/tags/LouisvilleCO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LouisvilleCO</span></a></p>
Andrew 🌻 Brandt 🐇<p>I haven't seen much about this, but I saw a data breach notification come from the local K-12 school district (<a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a>) this morning, and then someone else who lives in a neighboring district (<a href="https://infosec.exchange/tags/SVVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SVVSD</span></a>) mentioned that they had also seen a breach notification from their school district.</p><p>This is the notification. It says, in part, that this was "a nationwide data incident affecting over 350 school districts and higher education organizations across the US"</p><p>Does anyone have more information on these school data breaches/intrusions that seem to have been much larger than previously thought?</p><p><a href="https://infosec.exchange/tags/databreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>databreach</span></a> <a href="https://infosec.exchange/tags/schoolboard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>schoolboard</span></a> <a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> <a href="https://infosec.exchange/tags/StVrain" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>StVrain</span></a> <a href="https://infosec.exchange/tags/colorado" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>colorado</span></a> <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/schoolbreach" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>schoolbreach</span></a></p>
Andrew 🌻 Brandt 🐇<p>Hi folks. I wanted to share a bit of news about something outside of the world of <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>infosec</span></a> that I'm getting involved in: I'm officially a candidate running for school board in the town where I live, Boulder, Colorado. The election is this November!</p><p>I won't be posting about education policy topics on this account; I've set up a separate Mastodon account on the server used by many locals in <a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a>: <span class="h-card" translate="no"><a href="https://toot.bldrweb.org/@andrewbrandt" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>andrewbrandt</span></a></span> and using that account as the main one for my campaign. I hope you will follow me there if you care about compassionate, supportive schools that are not hostile to the <a href="https://infosec.exchange/tags/LGBTQ" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LGBTQ</span></a> community.</p><p>I've also set up a campaign website where I'll be trying to reach <a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> county voters at <a href="https://brandtforbvsd.co/" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="">brandtforbvsd.co/</span><span class="invisible"></span></a></p><p>This is a bit of a reach for me. I haven't ever run for...well, anything, before. I am looking for people who can help me run my campaign, including folks who might know a thing or two about the <a href="https://infosec.exchange/tags/VAN" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>VAN</span></a> system for reaching registered voters. I'd also welcome references to people who can help me craft visuals for the website and for things like campaign yard signs.</p><p>I've been extremely humbled by the support I've already received from many current and former <a href="https://infosec.exchange/tags/BVSD" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>BVSD</span></a> board members, and hope to continue the challenging (and unpaid) work of helping to manage a wonderful and well run school district with a nationally-renowned superintendent.</p><p>Most importantly, I believe that, as a hacker, I have a unique opportunity to help guide the local public school system as it faces unprecedented challenges in the form of emerging technologies like <a href="https://infosec.exchange/tags/ChatGPT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ChatGPT</span></a> and other large language models and <a href="https://infosec.exchange/tags/AI" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>AI</span></a> platforms, as well as trying to navigate the tricky waters of internet safety and data privacy for school-age kids.</p><p>If you believe, as I do, that we need to do a better job as a society at helping the next generation deal with these thorny issues, I hope you'll support my campaign and follow me on this journey. Thanks for reading! Please boost for reach.</p><p><a href="https://infosec.exchange/tags/schoolboard" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>schoolboard</span></a> <a href="https://infosec.exchange/tags/Boulder" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Boulder</span></a> <a href="https://infosec.exchange/tags/LouisvilleCO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LouisvilleCO</span></a> <a href="https://infosec.exchange/tags/LafayetteCO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>LafayetteCO</span></a> <a href="https://infosec.exchange/tags/SuperiorCO" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>SuperiorCO</span></a> <a href="https://infosec.exchange/tags/elections" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>elections</span></a></p>