e-Literate

Present is Prologue

Author: Phil Hill

  • Ed Tech Cybersecurity: Suppose they gave a data breach and nobody came

    Ed Tech Cybersecurity: Suppose they gave a data breach and nobody came

    It has now been four weeks since Chegg announced a data breach compromising personal information of up to 40 million users. Cue the crickets because the only coverage in ed tech press thus far is from EdWeek, which focuses on the K-12 market. That’s a shame, because if ed tech companies want a case study to help understand the implications of FBI warnings or the European Union’s new Global Data Privacy Regulations (GDPR), this example from Chegg should be illustrative. The same goes for institutions.

    As a recap, Chegg discovered on September 19th a data breach dating back to April that “an unauthorized party” accessed a data base with access to “a Chegg user’s name, email address, shipping address, Chegg username, and hashed Chegg password” but no financial information or social security numbers. The company has not disclosed, or is unsure of, how many of the 40 million users had their personal information stolen. On September 25th Chegg notified the SEC about the breach, focusing on guidance for company financials. The company then started notifying users and “certain regulatory authorities” on September 26th.

    A “hashed password” is a typical process where the entered password is converted to random-looking cryptographic characters not intended to be decrypted. Subsequent password entries use the same hash again and software compares not the passwords but the hashed passwords to see if they come out identical. While this practice of one-way hashes is well-known, there are far too many web sites (including in ed tech) using plain text, reversible hashes, or poor cryptography schemes.

    This 2016 article in Wired gives a good overview of hashing and data breaches and notes that the level of compromise depends on the details.

    In theory, no one, not a hacker or even the web service itself, should be able to take those hashes and convert them back into passwords. But in practice, some hashing schemes are significantly harder to reverse than others. The collection of 177 million LinkedIn accounts stolen in 2012 that went up for sale on a dark web market last week, for instance, had actually been hashed. But the company used only a simple hashing function called SHA1 without extra protections, allowing almost all the hashed passwords to be trivially cracked. The result is that hackers were able to not only access the passwords, but also try them on other websites, likely leading to Mark Zuckerberg having his Twitter and Pinterest accounts hacked over the weekend.

    By contrast, a breach at the crowdfunding site Patreon last year exposed passwords that had been hashed with a far stronger function called bcrypt, the fact of which likely kept the full cache relatively secure in spite of the breach.

    What is problematic with the Chegg data breach is that no further information has been made public and there has yet to be any interest from the broader ed tech press to dig up answers. We have no idea how serious this breach is, and I do not believe that the users with compromised personal information have had any updates since the initial email blast and associated post.

    Less than one week before the Chegg discovery of the data breach, the FBI put out a warning about ed tech and K-12 schools, but the details could easily be applied to higher education.

    The FBI is encouraging public awareness of cyber threat concerns related to K-12 students. The US school systems’ rapid growth of education technologies (EdTech) and widespread collection of student data could have privacy and safety implications if compromised or exploited.

    EdTech can provide services for adaptive, personalized learning experiences, and unique opportunities for student collaboration. Additionally, administrative platforms for tracking academics, disciplinary issues, student information systems, and classroom management programs, are commonly served through EdTech services.

    There is also the GDPR angle described in the EdWeek article.

    One of the first to call attention to the Chegg breach was Hill, an education consultant and market analyst for the company MindWires Consulting who posted a blog and a tweet about the SEC disclosure. [snip]

    One of the more pressing questions is whether the breach will draw the scrutiny of data-privacy regulators, said Hill in an interview. He pointed to the new rules put in place as part of GDPR, the sweeping European data privacy regulation that took effect earlier this year.

    The European policy has come into focus recently with the admission by social media giant Facebook — which has a major presence in schools — that hackers gained access to 50 million of its accounts. European authorities have said they are investigating how many users on the continent were affected, and whether it would trigger GPDR enforcement.

    The Facebook breach was no doubt more problematic, as its breach exposed far more personal information as well as access to Facebook Login, thus compromising third-party platforms. But both data breaches involve consumer-based systems and similar numbers of users. In legal terms, however, GDPR is based on protecting citizens of the European Union. When I asked a Chegg spokesman about the GDPR-based notifications, they replied in general terms.

    We actually do have an office in Berlin. Chegg’s customer base is principally US-based, and the core focus of our business is the United States. We are providing notice to the particular regulatory agencies, in the US and Internationally- including Europe.

    GDPR has been criticized as creating impossible to fully comply requirements, and there are two aspects worth covering here – Supervisory Authority and Notification of Data Breach. This article gives a good summary and whom to notify – the Supervisory Authority.

    For most companies, choosing a GDPR Lead Supervisory Authority is a straightforward decision. A company based in Paris, France would appoint the supervisory authority in France as the lead supervisory authority. A UK-based company would choose the Information Commissioner’s Office (ICO), which is the supervisory authority for the UK.

    For companies that operate in multiple EU member states, the lead supervisory authority would normally be the supervisory authority in the country where the company’s headquarters is or where its main business location is in the EU. More specifically, it would be the Supervisory Authority in the country where the final decisions are made about data collection and processing.

    A U.S. company that does not have a base in an EU member state has a problem. If it does not have a base in an EU member state where data procession decisions are made, it will not benefit from the one-stop-shop mechanism. Even if a company has a representative in an EU member state, that does not trigger the one-stop-shop mechanism.

    The company must therefore deal with the supervisory authority in every member state where the company is active, through its local representative.

    In Chegg’s case, presumably the Berlin office allows them to use the one-stop mechanism of a lead authority. But smaller ed tech companies may not have this benefit and require interactions with many different country regulators ((Genius system – make the process much more difficult for smaller companies.)).

    What about notification requirements in the case of a data breach? The relevant section is Article 33 of GDPR where Chegg would be a “controller” [emphasis added].

    • In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. 2Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
    • The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
    • The notification referred to in paragraph 1 shall at least:
      1. describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
      2. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
      3. describe the likely consequences of the personal data breach;
      4. describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

    In this case, Chegg would have had to notify its Lead Supervisory Authority by September 22 the details described above. According to the SEC form, initial notifications to regulators beyond the SEC started September 26.

    Would there be a lawsuit based on this delayed notification? We don’t know yet, but one important distinction is that in the EU the process must go through the official data regulators. Article 77 of GDPR specifies these actions.

    Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.

    In other words, a country regulator must decide whether it wants to pursue action against Chegg. In the US, similar complaints or lawsuits can be filed by individuals against the company with a data breach. The intention of GDPR is to go after the big tech companies – Google, Facebook, etc – and Chegg may be too low-profile to warrant close attention. Despite the large numbers involved of up to 40 million users, it is unknown how many are EU citizens.

    Will there be further fallout for Chegg than the initial flurry of financial news that helped drive down its stock price by 21 percent since the notification? It looks like the biggest issue is job security for US lawyers, as there have been at least four dozen lawsuits seeking class-action status filed with the general theme of the company not securing its systems properly or not notifying investors of the risks of data security. I have no idea if any of these will stick ((These types of lawsuits come out of the woodworks when stock prices drop.)), but Chegg’s initial focus on SEC and financial notifications seems well-placed.

    In the meantime, other ed tech companies would do well to view this data breach as a case study and opportunity to figure out how secure their systems are, and if they would be able to comply with GDPR regulations (or if they would be required to do so). More broadly, how many companies collecting personal information use adequate protection of hashed passwords? How many know what to do in the case of a data breach? Now is the time to find out and take action, before the next event occurs.

    I will repeat my call that Chegg needs to more fully disclose the details of the incident to the general public. There has been no new information shared by Chegg based on its investigation. I would add that this subject should get more attention from ed tech press.

    Update: Based on interaction with executive director of OpsecEdu, the description of common password security approaches has been changed to not state that most use one-way hashing.

  • e-Literate Sightings in the Fall 2018 Conference Season

    e-Literate Sightings in the Fall 2018 Conference Season

    We should have posted this a week ago, but we at e-Literate are in the midst of Fall 2018 conference season, and we’d love to connect with people at the various conferences we’re attending. We’re going for the divide-and-conquer strategy this year.

    We’re looking forward to connecting in person and scouring for tasteful tchotchkes we can put in new conference bags.

  • North American Higher Ed LMS Market Share by Enrollments: A consolidating market

    North American Higher Ed LMS Market Share by Enrollments: A consolidating market

    We have published market share data measured by total institutional enrollment instead of institutional count in several posts at e-Literate over the years, within the twice-annual reports of our LMS Market Analysis service, and for several of our premium subscribers of the same service. In July of this year we reported that Canvas had overtaken Blackboard as the market leader in US higher education in terms of institutional adoptions as well as scaled by enrollment. These last two posts got a fair amount of media and vendor attention.

    What we have realized, however, is that we have not made this information on market share by enrollment easy to access in one place. LMS company revenue tends to be based on the total enrollment of adopting institutions, thus this enrollment-based measure provides a more direct connection to company finances. Given the increased importance of LMS provider business models and revenue to the future trends of the market, we are sharing the information more broadly.

    In this view below we share North American (US and Canada combined) total enrollment for LMSs that are primary – that is, available for the entire institution. Total enrollment in this case means the institutional student count, but it does not imply that all students at that institution actually have courses using the LMS (see comment below from John Fritz). It is important to note that during an LMS transition there is often a period of time (6 – 18 months) where two systems overlap, with both available to the school. Therefore the total market share enrollments will be somewhat higher than actual total enrollments, as a subset of LMS-transitioning institutions will be counted twice.

    You can download a spreadsheet version here.

    LMS Market Share by Enrollment NA HE

    Some notes on the data worth considering:

    • Canvas has not just surpassed Blackboard Learn in this updated view, 35% to 33% – it has also expanded its lead as the most-adopted LMS in North American higher ed markets (while Moodle has clear lead worldwide in total installed base).
    • D2L Brightspace has been in third place for NA HE markets since 2016 when viewing by enrollments.
    • Moodle is fourth and has been dropping in recent years.
    • The top view of total enrollments adds in the effect of changing enrollments – both at a national level and an institutional level.
    • In the past five years, the LMS Market for North American higher ed has become increasingly dominated by “the Big Four” (Instructure Canvas, Blackboard Learn, D2L Brightspace, Moodle) for institution-wide adoptions; the aggregate market share of year’s top four systems moving from 80% to 95% in past five years.

    This last point deserves more analysis. There are other systems gaining new institutional clients (think Schoology here, or think CBE-specific platforms like Motivis), but they are mostly picking up either small schools or being adopted for specific programs and not for the entire institution.

    Consolidation of NA HE LMS Market

    Expect more coverage as we enter ed tech fall conference season.

    Update 8/3: Added sentence in third paragraph to clarify usage of total enrollment terminology.

  • Chegg Data Breach May Affect Up To 40 Million Users

    Chegg Data Breach May Affect Up To 40 Million Users

    Chegg – a publicly-traded provider of digital textbooks, tutoring and study guides – notified the SEC yesterday that they learned a week ago about a security breach dating back to April 2018. In their 8-K filing:

    On September 19, 2018, Chegg learned that on or around April 29, 2018, an unauthorized party gained access to a Company database that hosts user data for chegg.com and certain of the Company’s family of brands such as EasyBib. The Company understands that the information that may have been obtained could include a Chegg user’s name, email address, shipping address, Chegg username, and hashed Chegg password. The investigation into the incident, which is supported by third-party forensics, is ongoing. To date, the Company understands that no social security numbers or financial information such as users’ credit card numbers or bank account information were obtained. The Company expects to start notifying approximately 40 million active and inactive registered users and certain regulatory authorities on September 26, 2018.

    Chegg takes the security of its users’ information seriously and will be initiating a password reset process for all user accounts.

    Note that the company learned of the data breach a week ago, and the notifications appear to be centered on calming investors (their stock price dropped 12% based on the news). The only way that I discovered this news was through financial market notifications and their 8-K filing:

    In connection with the disclosure of the security incident discussed in Item 8.01 below, on September 25, 2018, Chegg, Inc. (the “Company” or “Chegg”) reaffirmed its previous guidance for the third quarter of 2018 as most recently stated in the press release issued on July 30, 2018 and furnished as an exhibit to a Current Report on Form 8-K filed that day with the Securities and Exchange Commission (the “SEC”) (the “July Guidance”). Chegg also announced that it currently believes that the security incident discussed in Item 8.01 below will not have a material impact on its financial results for the full year ending December 31, 2018.

    According to their filing, Chegg is notifying current and former users starting today, but as yet there has been no public notification. I do not know why it took the company a full week for notifications to begin, but I suspect it is due to internal investigations to fully understand the nature of the breach – what was compromised and what was not.

    For reference, California privacy laws do not stipulate exactly how quickly companies must notify users of a data breach. The law stipulates:

    The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c) [ed. section on cooperation with law enforcement], or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.>

    What is missing thus far is useful information for the public. What happened, how did this happen, what steps Chegg has taken to mitigate the risk, whether there remains a security vulnerability. I suspect it was wise to only disclose this breach to public equity markets based on guidance for financial losses, and not to the general public.

    Chegg needs to more fully disclose the details of the incident to the general public, and do this very soon.

    Update 1: I have modified post title to more accurately reflect that it is unknown how many user accounts were accessed. Here is a ZDNet article with additional descriptions.

    Update 2: I contacted Chegg for additional information. Their spokesperson said the company “a lot of obligations of how and when disclosures of non-public information can be made”, and that a public post is now available with further descriptions.

    We recently discovered that some user account data from Chegg.com, or of one of its family of student services, may have been acquired by an unauthorized party. Our understanding is that the data that may have been obtained could include names, email addresses, shipping addresses, Chegg usernames, and hashed Chegg passwords. Our current understanding is that no financial information such as credit card numbers, bank account information, or social security numbers was obtained. As a result, we are prompting users to change their Chegg.com or Chegg affiliate passwords upon login.

    [snip]
    For more information, please review the FAQs below.

    FAQ:

    1. What happened?
      • We recently discovered that some user account data from Chegg.com, or of one of its family of student services, may have been acquired by an unauthorized party.
      • While our investigation into this matter continues, we are letting users know what we know now because we value our relationship with them.
      • An investigation, supported by a third-party forensics firm, was commenced.
    2. What information was affected?
      • Our understanding is that the names, email addresses, shipping addresses, Chegg usernames, and hashed Chegg passwords of some of our users may have been obtained as a result of this incident.
      • Our current understanding also is that no financial information such as credit card numbers, bank account information, or social security numbers was obtained.

    There are six additional questions addressed in the FAQ section. This post is a good step forward in transparency, although I believe it was a mistake not to have this available at the same time as notifications to the SEC and financial markets. We will update as we get new information.

  • Blackboard Learn Ultra in 2018: Is it ready and does it matter?

    Blackboard Learn Ultra in 2018: Is it ready and does it matter?

    One of our longest-running series of posts is on the prospects and status of Blackboard’s Learn Ultra, the user experience redesign and move to the cloud of the world’s second-most-used (behind Moodle) and highest-revenue-producing academic LMS. It is fashionable to claim the LMS is dead or passé, yet this product category remains the centerpiece of educational technology at colleges, universities, and K-12 districts. To understand Learn Ultra is to understand much of the overall LMS market.

    Looking at the timeline of e-Literate coverage, the broad story emerges:

    • 2012: Blackboard acquires Moodlerooms, and one benefit was the see of a cloud-based platform strategy.
    • 2014: Blackboard prematurely announced Learn Ultra (new user experience) and Learn SaaS (move to the cloud).
    • 2015: Learn Ultra is already a year late (more realistically, the BbWorld14 announcement was wildly unrealistic), but the University of Phoenix selects Learn Ultra as its next-generation learning platform.
    • 2016: Blackboard switches CEOs, admits that Learn Ultra is still not ready, and struggles with a major messaging problem around the transition.
    • 2017: No coverage – maybe we got tired of lack of not having customers to talk to.
    • 2018: Blackboard makes Learn Ultra the core of its message at its users conference BbWorld18.

    (Note: It might be easier to view this as a full page timeline instead of the embed within this post.)

    What we have been asked multiple times, by institutions, by investors, by other ed tech companies: is Learn Ultra ready, and does it matter? The unsurprising answer to both questions is a qualified and somewhat confusing it depends. To describe a little further, Learn Ultra’s Base Navigation is ready, but the Course View is not ready for meaningful adoption; furthermore, Learn Ultra is important to Blackboard’s future, but we think SaaS is more important to its present.

    Is It Ready?

    To ask this question requires an understanding of terminology, as we first described in this post. Blackboard1 is pushing the metric that there are 61 or 62 Learn Ultra customers “in production” or “using Ultra”, yet we have found very few that use, or even plan to use, Learn Ultra as their primary, institution-wide LMS. What gives? What became quite clear at this year’s BbWorld 18 users conference is that when Blackboard says in production, what they mean is that the LMS administrator has enabled the Ultra navigation, which uses the new Ultra user experience framework as the landing page / dashboard with activity feed that users see before entering a specific course. The company calls this Base Navigation, but at this point every course can be configured to be in the Original Experience or the Ultra Experience. Thus, enabling the possibility of running a course in Ultra counts as in production (note that Blackboard now lists 91 clients on Ultra).

    Slide from BbWorld18

    Once a school has enabled Learn Ultra Base Navigation, they could choose to move exclusively to Ultra (e.g. the University of Phoenix, Northwest Florida State College, and a few others), or they could choose to keep all courses in Original (e.g. Northeastern State University), or they could choose to have some courses in Ultra and some in Original (used by the majority of schools investigating Ultra). This last mode is known as Dual Course mode, and even Blackboard executives seemed surprised to find out that the vast majority of schools putting Ultra in production are in fact running in Dual Course. For many of these schools, there are no definitive plans to move exclusively to Ultra.

    Upon re-reading this description, I believe that I should give more credit than just describing a landing page and base navigation. The cross-course functionality is and has been a long-term goal of Ultra, as we described as early as 2016.

    Creating a brand for a set of design goals is inherently fraught. Let’s look at two examples of how it makes communication of Blackboard’s strategy tricky for them. First, there’s mobile. Blackboard came out last year with a mobile app called Bb Student. It provides students with that activity stream view across courses and, of course, it’s mobile-first. (In fact, it’s mobile-only at the moment.) Furthermore, the company has made the product available for both traditional 9.x customers (which at this point is pretty much everybody) and their SaaS customers. People inside the company feel like they should be getting more credit for delivering on two major design goals (mobile first and stream-based activity views) as well as for delivering it to customers on the 9.x platform (which was more significant of a technical achievement than is immediately obvious).

    This is not a matter of Blackboard moving the goal posts, per se, and it is probably more accurate to say that Ultra cross-course functionality enabled by Base Navigation is ready and showing some benefits.

    Learn Ultra Base Navigation Brochure

    The challenge is that this move is not sufficient to make a material change in Blackboard’s company prospects. At best, Learn Ultra Base Navigation without usage of Course View will slightly slow down the rate of customers defecting for another LMS. For Learn Ultra to matter and to make Learn newly competitive, they need customers to also use Course View as the primary choice at their institution, and that usage by-and-large is not ready outside of a handful of schools.As an example from BbWorld18, Belmont University presented their experience moving to Learn SaaS (the important issue in the present, and a predecessor for  adopting Ultra)  and to “the Ultra Experience”. But after we asked a question about faculty adoption of the Ultra Course Experience, the administrator clarified that there are no courses running Ultra – all they have done is enable the Ultra base navigation, and they do not expect to do any course migrations for at least another year. This full adoption of Learn Ultra might become important in the future, but it is not driving decisions today.

    Does It Matter?

    Given that we’ve been asking for three entire years whether Learn Ultra is ready, one obvious follow-up question is whether it matters any longer. I do think the question matters as Blackboard is pinning their corporate turnaround on Learn Ultra as the core piece, and this message was heavily promoted at BbWorld 18.

    This messaging makes some sense in that we consider it unlikely that Blackboard can gain significant numbers of new clients (those moving from another LMS to Blackboard Learn, beyond a dozen or fewer schools) without Learn Ultra. Learn Original Experience has too much baggage and is too dated to compete with Canvas or Brightspace by D2L, at least in North America. The company’s new Learn LMS clients are largely the University of Phoenix and ANGEL contract conversions.

    To be fair, the exceptions include several schools in North Dakota (migrating from Moodle) as well as Northwest Florida State College (migrating from D2L). But even with NW Florida State, they based their decision on Learn Ultra.

    Based on interviews with clients arranged by Blackboard, and based on our own connections at BbWorld, what we consistently heard during dozens of interviews and from listening to panel discussions was that Learn Ultra Course View makes sense primarily for programs or schools that have not been on Blackboard Learn before. Bb Learn clients seem to have too many expectations of needing the same functionality they had before, pushing Ultra to be largely feature-compatible with Original and thus losing some of its simplicity in the process. When the Illinois Institute of Technology migrated from Learn self-hosting to SaaS, which enabled them to explore Ultra, they chose one program and a handful of faculty that were willing to jump into Learn Ultra, but for almost all others they are sticking with the Original Course View for the time being. The soonest they would expect moving primarily to Learn Ultra at the Course View would bet 3-5 years from now. You can hear the same dynamic in a recent Rod’s Pulse Podcast (shared under CC-BY-NC-SA license and also available at Inside Higher Ed), with Rod Murray interviewing Rob McCunney about their school (University of the Sciences) and its migration to SaaS and Ultra. It is a fascinating first-hand description of their experiences. Please note that they use use the terms Traditional and Original interchangeably.

    R Murray: We turned on the SaaS in January, but we really kept the Original Experience until July. In mid-July we flipped the switch to turn on the Ultra Experience. Now again for those of you are not as familiar with the way Blackboard works, that wasn’t changing the course format. They were still traditional courses, but you know all those tabs and modules disappeared, and we ended up with a new base navigation in Blackboard, which they called the Ultra Experience. So that was a major change, and we do have some summer sessions, but we felt this was the least painful way to turn it on. We didn’t want to wait till August just before our fall students came back.

    In terms of turning on the Ultra Experience, what were some of the major issues that you saw, that you were concerned with?

    R McCunney: Besides the fact that we lost the tabs and modules, so we kind of rolled out OneCampus as Rod said, I think one of the major things that that I noticed wasn’t really even on the admin side, it was just getting people used to something that was completely different as soon as they logged in to that institution page. Where’s my stuff, where is my modules? It just looks completely different than what they’re used to, and there’s some stuff missing, and we replaced it. We put stuff in other areas, and we communicated that, but that was probably the biggest hurdle. Just what is this, what is this Blackboard Ultra that you’re changing me to? And at that point, in July we only changed basically the institution page. Your average user, once they get into their course they didn’t notice anything different, but that initial freak out of here I don’t know where my form is. We told them a dozen times where it is, but it’s somewhere else. That was probably one of the major hurdles, and I didn’t anticipate that as being a big as an issue as it was. I thought there was going to be more nuts and bolts issues, which there were very few of those for the most part.

    R Murray: Right now of course we don’t have that many students here in the summer, so the real test will be in another week or so when students come back and really start. We all start kicking the tires, even on the traditional courses within the Ultra Experience.

    [snip]

    R Murray: The next big change that we have to live through has to do with converting courses to the Ultra course view. Now here at our university we certainly didn’t do it en masse, we went to play with it for at least this term and maybe next. But there are some courses that we decided made a lot of sense to convert to the Ultra course view. Those schools that those courses that are brand new, especially online courses that are brand new, it made sense to develop them directly in the [Ultra] course view.

    Schools are trying out the Ultra Experience in terms of the landing page and cross-course functionality, but by-and-large they are very cautious jumping into the Ultra Course View where most of the functionality resides.

    Based on this situation, we believe that the migration to Learn SaaS might be a better indicator – at least in the short run – than Ultra adoption of whether a school plans to stick with Blackboard. When a school moves to Learn SaaS, they all tend to sign contract extensions for 1 – 3 years or at least internally plan no LMS migrations for more than 1 – 3 years. And the migration to Learn SaaS does not suffer from the vague terminology issues – a school either uses Learn deployed on SaaS (through AWS) or they don’t.

    Learn SaaS progress slide

    383 clients on Learn SaaS as of BbWorld 18 is good progress and easy to understand. This issue is what likely matters more to Blackboard clients today and for the next few years, but in the long run the company needs Learn Ultra to be accepted – including at the course level – in order to become more competitive and pick up new clients.

    In the end, Learn Ultra is partially ready and does matter, more so in the future, but the Learn SaaS migration matters much more today. This answer is a real improvement over the situation a year ago and even from the beginning of this year, but it is still a far cry from a simple yes and yes answer that Blackboard would like to have.

    Update: Fixed name of Rob McCunney

  • Timeline of e-Literate Coverage of Blackboard Learn Ultra

    Timeline of e-Literate Coverage of Blackboard Learn Ultra

    While doing research for an upcoming analysis post on Blackboard Learn, I found myself wanting to have a coherent timeline of past e-Literate coverage on the development and adoption of Learn Ultra. The most useful timeline tool seems to be TimelineJS by Knight Lab out of Northwestern University, so I gave it a try. The result of combining article data with this tool is an interactive timeline that allows the reader to browse relevant posts since 2012, showing the date of publication, a linked post title, and a snippet of content. You can click on the timeline navigation at the bottom, or you can browse through the overall story by using the arrows by text or swiping left / right on mobile devices. It might be easier to view this as a full page timeline instead of the embed within this post.

    Going through this exercise, I was a little surprised to see the two-year gap in coverage between July 2016 and July 2018.

    Let us know if this timeline view is useful. We may create other versions to help navigate topics like the OPM market.

     

     

    One sample page:

    Timeline of coverage of Learn Ultra

  • Expansion of OPM-Derivative Model: Disney covers online degrees for hourly employees through Guild Education

    Expansion of OPM-Derivative Model: Disney covers online degrees for hourly employees through Guild Education

    Two weeks ago The Walt Disney Company announced a new educational benefit program called Disney Aspire that goes beyond what other recent benefit programs have offered. As described in a company blog [emphasis added]:

    Disney Aspire is the most comprehensive program of its kind. To make participation easier for eligible employees, The Walt Disney Company will cover 100 percent of tuition upfront and will also reimburse application fees and required books and materials, removing the worry of paying to start or continue school. The program is designed for working adults and offers our Cast Members and employees maximum choice and flexibility with their studies, regardless of whether the program and classes they choose are tied to their current role at Disney. Disney Aspire includes a network of schools that offer a wide array of disciplines and diplomas—including college and master’s degrees, high school equivalency, English-language learning, vocational training and more.

    This program is offered through Guild Education to 80,000 of Disney’s hourly employees in the US (after 90 days of employment), and the ‘regardless’ point is crucial – the options for degrees is not constrained to pre-selected majors or degrees that have to be tied to an employee’s current role.

    Yesterday there were additional details announced by the University of Florida Online (UF Online) about programs that they are offering for Disney Aspire.

    As part of this relationship, Disney employees may apply to one of several fully online bachelor’s degrees – the Bachelor of Arts or Bachelor of Science in business administration from the Warrington College of Business; the Bachelor of Science in sport management from the College of Health and Human Performance; and the Bachelor of Arts in public relations, and the Bachelor of Science in telecommunication from the College of Journalism and Communications. If granted admission by the University of Florida, Disney cast members could begin UF Online classes in January 2019 as part of the University’s spring semester. Once cast members sign up for the Disney Aspire educational benefit, a coach from Guild Education will contact them to determine their eligibility to receive educational benefits, review their academic background, and to provide qualified prospective students with a unique link to the UF Online admissions application.

    One reason this announcement is interesting is the rapid growth of Guild Education, providing a derivative of Online Program Management (OPM) services. Guild describes itself as providing a platform that connects large-employer educational benefit programs with partner schools such as UF Online, Brandman University, Valencia College, etc. As we described in June when Walmart and Discover Financial announced their benefit programs:

    I think these moves are more significant than just individual benefits. What we are seeing is UF Online, along with a handful of others, defining a different approach to marketing and finding potential online students, at least for undergraduate degrees. Historically, there is a common assumption that to enable a scalable online program there is a need for traditional digital marketing as the primary approach – Google AdWords, call centers, social media campaigns – with a partnership or two thrown in on the side. The origin of the OPM market is centered on providing these services in exchange for a percentage of tuition revenue, and for the majority of cases, the OPM’s spending on this marketing and enrollment management category is the most expensive service in the package. The Employer Pathways approach by UF Online has the potential to flip the student acquisition assumptions – primarily driven by employer partnerships with traditional digital marketing channels as a secondary approach.

    Since the June post, Guild Education raised a round of $40 million for a total of $71.5 million since 2015. As EdSurge noted in its article, however:

    One challenge is that few employees who are given education benefits options take advantage of them. The Wall Street Journal recently reported that while nearly 90 percent of mid- and large-size companies offer tuition reimbursement, less than 10 percent of employees at those companies take advantage of the benefits.

    That figure is even lower at Guild’s partner companies, where only 3 to 5 percent of employees take advantage of the educational offerings, says Carlson. “We are optimistic that our companies want to go beyond that.”

    Guild Education works on a tuition revenue share basis, although the details of these agreements are not public information yet. Charging tuition revenue sharing for up-front marketing and acquisition of students for online programs – sounds like a lot of overlap with the OPM market, but for a new or derivative model. This gets to Michael’s point most recently described in a post about Noodle Partners and their evolving model:

    In my last two posts, I talked about OPMs being long-term partners in the ongoing management of online programs. I also argued that unbundling of services opens up a world of possibilities for solving different problems, and that we therefore need an umbrella product category called “Digital Enablement Solutions” with other (emerging) subcategories that could live along side Online Program Management.

    Guild Education does not provide any of the program management services beyond admissions, as they do not help with program design, instructional design, student support, ed tech platforms or analytics. So it would be a mistake to lump them into the OPM category, but there are some interesting overlaps. We referenced this situation in our response to the SUNY Online Education Request for Information.

    Financing models are proliferating in higher education, to the point of creating a great deal of market confusion, in part because one size does not fit all. Universities will likely have to evaluate a wide range of financial models and make sure that their approved portfolio of solutions providers includes a substantial subset of those models.

    As for the educational partners, there is long-term potential but not yet sufficient demand for that flip in student acquisition assumptions. UF Online estimates that within the next two years they might reach 10% of students coming from their Employer Pathways. One motivation for this type of program, according to Associate Provost and Director of UF Online Evie Cummings, is that ideally the  “coach from Guild” will be able to pre-screen applicants, since the cost of marketing to students who do not make it through the admissions process is quite expensive for selective institutions.

    Beyond the online programs, starting in January there are likely to be face-to-face options as well, as described in the Orlando Sentinel.

    Under the education program, Disney employees can take courses toward a high school diploma, a college degree or vocational skill.

    A Disney spokeswoman said the online courses are the first rollout of the tuition program and employees would be eligible for in-person classes — at Valencia College as well as other schools — in the next phase beginning in January.

    Count this news as further evidence of the broader market of Digital Enablement Solutions based on tapping into corporate HR and learning opportunities rather than traditional ad-based student recruitment methods.