Investigating the Security & Privacy Risks from Unsanctioned Technology Use by Educators

  • Easton Kelso
  • , Ananta Soneji
  • , Syed Zami Ul Haque Navid
  • , Yan Shoshitaishvili
  • , Sazzadur Rahaman
  • , Rakibul Hasan

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

With the increasing digitization of teaching and learning activities, technology-generated data has become the target of attacks from external adversaries and abuse by technology providers. Researchers have investigated stakeholders’ perceptions of security and privacy risks from technologies and how those risks are affecting institutional policies for acquiring new technologies. However, outside of institutional vetting and approval, there is a pervasive practice of using applications and devices acquired personally. It is unclear how these applications and devices affect the dynamics of the overall institutional ecosystem. We address this gap through an online survey-based study targeting educators and administrators from K-12 and higher education institutions in the United States. Our study identified 494 unique applications used by educators, and examined the perceived and subsequent risks associated with integrating these technologies into an institution’s ecosystem. The findings highlight a significant lack of privacy and security awareness among educators when selecting new tools, as well as widespread uncertainty regarding regulatory compliance. Additionally, institutional warnings and policies on unsanctioned app use appear to have limited effectiveness in changing educators’ behaviors. To mitigate these challenges, we identified the need for institutions to provide clear guidelines, data privacy and security training, and vetted alternatives that meet the needs of educators while ensuring compliance. A collaborative approach between educators and administrators will be key to balancing automation and data privacy.

Original languageEnglish (US)
Title of host publicationCHI EA 2025 - Extended Abstracts of the 2025 CHI Conference on Human Factors in Computing Systems
PublisherAssociation for Computing Machinery
ISBN (Electronic)9798400713958
DOIs
StatePublished - Apr 26 2025
Event2025 CHI Conference on Human Factors in Computing Systems, CHI EA 2025 - Yokohama, Japan
Duration: Apr 26 2025May 1 2025

Publication series

NameConference on Human Factors in Computing Systems - Proceedings

Conference

Conference2025 CHI Conference on Human Factors in Computing Systems, CHI EA 2025
Country/TerritoryJapan
CityYokohama
Period4/26/255/1/25

ASJC Scopus subject areas

  • Human-Computer Interaction
  • Computer Graphics and Computer-Aided Design
  • Software

Fingerprint

Dive into the research topics of 'Investigating the Security & Privacy Risks from Unsanctioned Technology Use by Educators'. Together they form a unique fingerprint.

Cite this