e-Literate

Present is Prologue

Author: Phil Hill

  • Instructure Security Assessment Results

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities.  Instructure has also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.  Part 1 of this series of posts described the concept.  Part 2 gave a mid-term update, describing the process involved and initial results.  In this post I’ll describe the full results of the security assessment.  I’ll add my actual analysis in the final post.

    The purpose of the testing was to validate and review the Canvas LMS design and implementation with respect to vulnerabilities that could be exploited by a motivated hacker.  Securus employed security experts to ethically hack, both manually and with automated tools, a test environment to try and identify specific vulnerabilities, working from the perspective of both an unauthorized user and an authorized user.  There was a range of exploits tested, but the basic idea is to find out if someone could access information or functionality that should be protected by system controls including role-based security.

    Summary of Findings

    The findings were presented to Instructure on November 29, 2011 in report form and with a conference call to discuss.

    (more…)

  • Instructure Security Mid-Term

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities.  Instructure has also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.  Part 1 of this series of posts describes the concept.  In this post, I’ll give a mid-term update, describing the process involved and initial results.  In the next post I’ll describe the full results of the security testing.  I’ll try to keep my actual analysis in the final post, after I have objectively described the process and results.

    The purpose of the testing was to validate and review the Canvas LMS design and implementation with respect to vulnerabilities that could be exploited by a motivated hacker.  Securus employed security experts to ethically hack a test environment to try and identify specific vulnerabilities, working from the perspective of both an unauthorized user and an authorized user.  There was a range of exploits tested, but the basic idea is to find out if someone could access information or functionality that should be protected by system functionality including role-based security.

    There are two particular viewpoints that have led to my interest in this independent observer role.

    • No enterprise software platform is perfect and you should always expect some vulnerabilities.  The issue should not just be on whether there are vulnerabilities, but perhaps more importantly, on how a company or organization responds to a security vulnerability or incident.
    • I have called for transparency from LMS vendors and open source communities, arguing that they should share information from their third-party security audits and tests.

    (more…)

  • Regulatory Barriers to Innovation for Ed Tech and Open Education

    Over the past few weeks there has been a significant backlash growing against SOPA (the anti-piracy bills introduced in Congress) – read here or here for background.  The biggest change since the bills were introduced is that big technology vendors (significantly including Microsoft and working through the Business Software Alliance) have either withdrawn support or gotten off the fence.  The BSA is now officially lobbying against SOPA as written.  In the world of strange bedfellows, there are also a number of politicians on both sides of the aisle publicly opposing the bill.  It does take some real legislative talent to help create a Pelosi – Paul – Issa common cause.

    Despite the growing opposition, there certainly appears to be a concerted effort in Congress to get the bill passed.  The outcome is far from clear at this point.

    While SOPA by itself remains a major threat to innovation for educational technology and open education in general, it may be helpful to step back and see the growing list of federal laws and regulations that could have a major impact on innovation in higher education.  While each issue is interesting in and of itself, a pattern is emerging.  This pattern suggests that organizations interested in preserving the status quo – are actively pushing back against the tide of change brought by online systems, online education, and digital content.

  • How Georgia Tech Has Shown the Perils of SOPA

    This has been a tough week for open education, at least in higher education.  First came the news that Georgia Tech has taken down a 14-year-old student wiki site that allowed discussions and collaboration across courses and across semesters.  Next came the news of more details on proposed intellectual property laws in Congress, dubbed SOPA for Stop Online Piracy Act, that are being drafted in a draconian manner to protect content providers while taking away reasonable “safe harbor” protections for internet site operators.  Despite the nominal differences in these two pieces of legislation, I think that the Georgia Tech FERPA decision has shown just how dangerous SOPA could be to higher education.

    Ramblin Wreck

    The system under consideration at Georgia Tech was “Swikis”, a site that students used for their coursework and broader educational usage.  As described in the Chronicle, all it took was for one student to cause the institution to shut down the whole Swikis program, despite the fact that students choose how to participate.  The reason for Georgia Tech’s decision was their interpretation over violating FERPA regulations.  No ambiguity here, just a simple interpretation by the institution despite the fact that FERPA was written into law in 1974, well before we had an internet and collaborative online software.

    (more…)

  • Instructure and Security Testing

    Instructure has had a very interesting reaction to the news and blogs about security vulnerabilities with Blackboard’s Learn LMS several months ago.  They have decided to engage Securus Global, the same firm that did the ethical hacking for the Australian universities in the Blackboard investigation, to test Instructure’s Canvas LMS product.  They have also invited me to be essentially an embedded reporter – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.

    While doing research for a my post analyzing Blackboard’s response to the reports of security vulnerabilities, I had the opportunity to interview several LMS vendors to get background on their philosophies and practices around security.  I think it is important to understand how the broader LMS market is handling security concerns, especially as the LMS has become such a central part of the an institutions’ academic operations.

    (more…)

  • What If OpenClass Succeeds in Disrupting LMS Market?

    Right now the e-Literate site is close to over-heating from Michael’s voluminous posts – all very thoughtful, but we’re going to need some WordPress coolant.

    During discussions over the past week in person and over blogs, I’ve had three people ask essentially the same question – will Pearson’s OpenClass LMS offering and associated corporate strategy lead to more competition or less competition in the LMS space for higher ed, or how will the competitive landscape change?  Obviously the nature of this question is speculative with no concrete answers, but I do think that technology market trends can help us with an educated guess.

    (more…)

  • When Large Companies Enter Ed Tech

    I had a very interesting conversation on the way home from EDUCAUSE with Frank Florence, who is the Senior Director of Education Market Management for Cisco.  We discussed the changes happening in the ed tech market, and Frank helped me understand some of the market forces behind the changes we’re seeing.  One topic in particular was the dynamic between entrepreneurial companies that develop within a vertical market and larger companies that span markets.  I have argued that internal investment from larger companies is helping to change the ed tech market, but Frank provided valuable insight into the nature of the typical market forces we’re living through.  This observation of large company involvement helping to change the LMS portion of the ed tech market is shown below, in many of the companies in the top gray bar and some that are not listed.

    (more…)