The security literature on computer-based testing (CBT) has developed almost entirely around remote proctoring, where the threat model assumes untrusted examinee-owned hardware operating in an uncontrolled environment. This framing treats institution-controlled hardware under physical invigilation as a secure baseline. We argue this assumption is unsound, substantiating the argument with evidence from Indonesia's national university entrance examination (UTBK-SNBT), a high-stakes CBT administered to 871,496 registered candidates in 2026 (846,518 present) across a distributed network of state-university testing centres. Drawing on publicly documented incidents from the 2025 and 2026 administrations, we reconstruct two organised attacks in which institution-controlled examination hardware was compromised despite physical proctors, metal detectors, and closed-circuit surveillance. In the first, campus IT staff with legitimate administrative privileges installed remote-access software on examination workstations; nine suspects were charged under Articles 30 and 32 of the Electronic Information and Transactions Law. In the second, a covert proxy appliance comprising two mini PCs, a router, and an uninterruptible power supply was concealed within a printer carton approximately six months before the examination. From these incidents we derive a five-class threat taxonomy and construct a STRIDE-based threat model mapped to MITRE ATT&CK. We show that the only control demonstrably effective against the most sophisticated attack was network-layer anomaly detection, whereas the perimeter controls emphasised in policy discourse failed by design. We conclude that trusted-hardware CBT constitutes a distinct, under-theorised threat model, and we outline a research agenda for its systematic study.
Copyrights © 2026