Uncovering Security Flaws in Digital Education Products for Schoolchildren

When Tony Porterfield’s two sons came home from elementary school with an assignment to use a reading assessment site called, he was curious, as a parent, to see how it worked. As a software engineer, he was also curious about the site’s data security practices.

And he was dismayed to discover that the site not only was unencrypted, but also stored passwords in plain text — security weaknesses that could potentially have allowed unauthorized users to gain access to details like students’ names, voice recordings or skill levels. He alerted the site to his concerns. More than a year later, the vulnerabilities remain.