November 1, 2020
|
5 min read
Proctoring software that requires installation gives vendors access to webcams, microphones, browsing history, and personal files, often without users fully understanding what they are agreeing to. This post examines the real risks of browser extensions and plugins, the Cassidy Wolf case as a landmark example of what can go wrong, and how Integrity Advocate's no-download, browser-based architecture eliminates most of these risks by design.

As children, most of us were told never to talk to strangers. The reasoning was straightforward: not everyone can be trusted, and the risk of getting it wrong is too high.
That lesson served us well offline. Online, we seem to have forgotten it entirely.
Every day, people install applications, plugins, and browser extensions onto their devices without giving it much thought. A productivity tool here, a proctoring extension there. What most people do not realize is what can come along for the ride.
The risks of installing unfamiliar software range from inconvenient to serious. Depending on what is embedded in the code, a plugin or extension can:
That last one is not a hypothetical.
Miss Teen USA Cassidy Wolf was among the first public figures to experience what happens when a device is compromised through an inadvertent software installation. Her computer was infected with a Remote Administrative Tool, commonly known as a RAT, which gave a hacker complete control of her webcam without her knowledge or consent.
She was not alone. More than two dozen women had their computers compromised by the same individual. An extensive FBI investigation ultimately resulted in the hacker, a student at the time, being sentenced to prison.
The case was a turning point in public awareness about the risks of software installation. But the threat has not gone away. If anything, the volume and sophistication of malicious extensions has grown significantly since then.
Online proctoring software sits in a uniquely sensitive position. It is installed on personal devices, often by students or workers who have no real choice in the matter. It accesses the webcam, microphone, and in some cases the full contents of the device. And it typically operates in the background, with limited visibility into what it is actually doing.
That is a significant amount of access to grant to any software, let alone software from a vendor whose code has not been independently reviewed.
There is no shortage of cases where browser extensions have caused serious harm, and proctoring extensions are not immune. Organizations that require test takers to install proctoring software are asking them to accept a level of risk that most people do not fully understand when they click install.
Integrity Advocate was built to avoid this problem entirely.
In most cases, Integrity Advocate requires no plugin, extension, or application installation to use the service. The platform is browser-based and accessible via any secure browser, on any device, at any time. There is nothing to install, nothing running in the background, and no code sitting on a test taker's machine after the session ends.
For use cases that do require a lockdown browser, Integrity Advocate takes a fundamentally different approach than most providers:
This matters because the majority of install-based risks come from updates pushed after the initial installation, often without the user's awareness or explicit consent. Removing that vector removes most of the risk.
We still tell children not to talk to strangers online. The same instinct that underlies that advice applies to software. If you would not hand a stranger the keys to your house, you should think carefully before granting an unfamiliar application access to your webcam, microphone, and file system.
Organizations choosing a proctoring provider have a responsibility to apply that same scrutiny on behalf of the people taking their assessments. The question is not just whether the software works. It is whether the people required to install it can trust what it does.
Want to see how a no-download proctoring solution works in practice?
Book a Demo →
{{post-cta}}
Find answers to the most commonly asked questions from our clients.
Depending on what is embedded in the code, a plugin or browser extension can infect a device with viruses or malware, steal personal information stored on the device or entered through the browser, damage or destroy the operating system, or remotely control the device including the webcam without the user's knowledge or consent. These risks apply to any unfamiliar software installation, including proctoring extensions that are presented as required tools for completing an assessment.
A Remote Administrative Tool, commonly known as a RAT, is software that gives an external party complete control over a device, including the webcam, microphone, and file system, without the user's knowledge or consent. The Cassidy Wolf case demonstrated how a RAT installed through an inadvertent software download gave a hacker unauthorized access to her webcam and those of more than two dozen other women. Proctoring extensions that require installation sit in a similar position of device access and carry a similar category of risk, particularly when the extension's code has not been independently reviewed.
Online proctoring software occupies a uniquely sensitive position. It is installed on personal devices by people who often have no real choice in the matter, accesses the webcam, microphone, and in some cases the full contents of the device, and typically operates in the background with limited user visibility into what it is actually doing. Granting that level of access to any software, particularly from a vendor whose code has not been independently audited, represents a meaningful risk that most test takers do not fully understand when they click install.
The majority of install-based risks come from updates pushed to software after the initial installation, often without the user's awareness or explicit consent. A program that appears safe at installation can become a vector for malicious code through a subsequent update. This is why Integrity Advocate's lockdown browser, where one is required, does not receive updates after installation, removing the most common pathway for malicious code injection.