Hacking Into The Indian Education System Reveals Score Tampering

Debarghya Das has a fascinating story on how he managed to bypass a silly web security layer to get access to the results of 150,000 ISCE (1...


Debarghya Das has a fascinating story on how he managed to bypass a silly web security layer to get access to the results of 150,000 ISCE (10th grade) and 65,000 ISC (12th grade) students in India. While lack of security and total ignorance to safeguard sensitive information is an interesting topic what is more fascinating about this episode is the analysis of the results that unearthed score tampering. The school boards changed the scores of the students to give them "grace" points to bump them up to the passing level. The boards also seem to have tampered some other scores but the motive for that tampering remains unclear (at least to me).

I would encourage you to read the entire analysis and the comments, but a tl;dr version is:

32, 33 and 34 were visibly absent. This chain of 3 consecutive numbers is the longest chain of absent numbers. Coincidentally, 35 happens to be the pass mark.
Here's a complete list of unattained marks -
36, 37, 39, 41, 43, 45, 47, 49, 51, 53, 55, 56, 57, 59, 61, 63, 65, 67, 68, 70, 71, 73, 75, 77, 79, 81, 82, 84, 85, 87, 89, 91, 93. Yes, that's 33 numbers!


The comments are even more fascinating where people are pointing out flaws with his approach and challenging the CLT (central limit theorem) with a rebuttal. If there has been no tampering with the score it would defy the CLT with a probability that is so high that I can't even compute. In other words, the chances are almost zero, if not zero, of this guy being wrong about his inferences and conclusions.

He is using fairly simple statistical techniques and MapReduce style computing to analyze a fairly decent size data set to infer and prove a specific hypothesis (most people including me believed that grace points existed but we had no evidence to prove it). He even created a public GitHub repository of his work which he later made it private.

I am not a lawyer and I don't know what he did is legal or not but I do admire his courage to not post this anonymously as many people in the comments have suggested. Hope he doesn't get into any trouble.

Spending a little more time trying to comprehend this situation I have two thoughts:

The first shocking but unfortunately not surprising observation is: how careless the school boards are in their approach in making such sensitive information available on their website without basic security. It is not like it is hard to find web developers in India who understand basic or even advanced security; it's simply laziness and carelessness on the school board side not to just bother with this. I am hoping that all government as well as non-government institutes will learn from this breach and tighten up their access and data security.

The second revelation was - it's not a terribly bad idea to publicly distribute the very same as well as similar datasets after removing PII (personally identifiable information) from it to let people legitimately go crazy at it. If this dataset is publicly available people will analyze it, find patterns, and challenge the fundamental education practices. Open source has been a living proof of making software more secured by opening it up to public to hack it and find flaws in it so that they can be fixed. Knowing the Indian bureaucracy I don't see them going in this direction. Turns out I have seen this movie before. I have been an advocate of making electronic voting machines available to researchers to examine the validity of a fair election process. Instead of allowing the security researchers to have access to an electronic voting machine Indian officials accused a researcher of stealing a voting machine and arrested him. However, if India is serious about competing globally in education this might very well be the first step to bring in transparency.

COMMENTS

Name

3D,1,acquisition,3,agile,2,algorithms,2,Amazon,4,analytics,6,Apple,3,architecture,5,augmented reality,2,behavioral economics,1,BI,6,big data,29,Black Swan,1,books,1,bottom of the pyramid,3,branding,1,brazil,1,channels,1,cloud,68,Cloud Computing,7,cognitive psychology,2,collaboration,3,collaborative filtering,5,conference,3,creativity,3,CRM,2,crowdsourcing,2,data centers,3,data science,9,database,5,design,13,design thinking,17,dropbox,1,education,2,enterprise software,26,entrepreneurs,12,eula,1,experience design,3,facebook,1,freemium,1,gamification,3,Google,7,hadoop,3,healthcare,1,hiring,1,Iaas,3,india,1,innovation,16,intellectual property,1,interaction design,2,IoT,1,machine learning,2,management,9,marketing,1,meetings,1,microblogging,1,Microsoft,2,millenial,1,mobile,9,music,1,network effect,5,NewSQL,1,nosql,9,OEM,1,open source,3,outsourcing,1,paas,9,parallel computing,2,platform,4,polygot,1,power laws,1,privacy,1,private cloud,1,product management,5,prototyping,2,psychology,2,public policy,1,RDBMS,1,recommendation systems,2,REST,2,retail,1,RIM,1,SaaS,24,sales,4,security,4,SOA,2,social,25,sports,1,strategy,21,sustainability,8,talent,2,telcos,4,tos,1,Twitter,5,usability,1,user experience,3,virtualization,5,voting machine,2,web 2.0,1,
ltr
item
Cloud Computing: Hacking Into The Indian Education System Reveals Score Tampering
Hacking Into The Indian Education System Reveals Score Tampering
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivEKkWQ08WcW7cTPjsf5vWYP6rmCQ6sqZm3yczRfeCa0GuYn0LixHZty3pTw1dUgP0nCJuVDiSGJoqexbvYcSC84q1Ifg7M-XJBlxr_gAVd1R_7B84p1fKoZHoK45tjOhhJrDDGKazNZ0/s400/hack_meme.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEivEKkWQ08WcW7cTPjsf5vWYP6rmCQ6sqZm3yczRfeCa0GuYn0LixHZty3pTw1dUgP0nCJuVDiSGJoqexbvYcSC84q1Ifg7M-XJBlxr_gAVd1R_7B84p1fKoZHoK45tjOhhJrDDGKazNZ0/s72-c/hack_meme.jpg
Cloud Computing
https://hereiscloudcomputing.blogspot.com/2013/06/hacking-into-indian-education-system.html
https://hereiscloudcomputing.blogspot.com/
http://hereiscloudcomputing.blogspot.com/
http://hereiscloudcomputing.blogspot.com/2013/06/hacking-into-indian-education-system.html
true
4467119141698964002
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS CONTENT IS PREMIUM Please share to unlock Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy