e-Literate

Present is Prologue

Tag: Chegg

  • Chegg vs. Pearson: Are back-of-chapter answers intellectual property?

    Chegg vs. Pearson: Are back-of-chapter answers intellectual property?

    We interrupt our regularly scheduled post series on Argos Education for this breaking news…

    No, I’m not talking about the news that Blackboard was acquired by some ERPish rollup creation of a private equity company. I searched my soul to examine my deepest thoughts and feelings on that topic. Here’s what I came up with:

    • I’m happy that Bill Ballhaus finally got paroled. While he and I clashed once or twice, he seems like basically a nice guy. He didn’t deserve to be stuck trying to unload that company for five years.
    • I’m both happy and worried for the nice people who work at Blackboard. I hope this means that most of them will still have jobs.
    • I have similar feelings about Blackboard customers. I hope this works out for them.
    • I am deeply grateful that Phil Hill exists so that I don’t have to spend my time trying to make sense of this deal.

    That’s it. That’s all I’ve got. My therapist tells me this is good progress in recovering from the formative trauma that turned me into the blogger that I am today.

    No, I’m talking about Pearson suing Chegg for copyright infringement because Chegg has reconstructed Pearson’s back-of-chapter homework answers:

    Specifically, the suit revolves around Chegg Study, a subscription service that among its offerings features answers to end-of-chapter homework questions from various texts for $14.95 a month, with the textbook questions often copied nearly verbatim or with just slight changes, the suit alleges. Pearson lawyers told the court that “the majority” of Chegg’s roughly $644 million in total revenue in 2020 came from its sales of answers through Chegg Study, which reportedly counted some 6.6 million subscribers as of 2020.

    Pearson Education Sues Chegg, Alleging ‘Massive’ Copyright Infringement

    You may recall my post responding to the Forbes article about them, which was entitled “This $12 Billion Company Is Getting Rich Off Students Cheating Their Way Through Covid.” The main piece of new information I added was that most of the large publishers themselves had licensed these answers to Chegg a while back. Those contracts have expired. And now we have at least a hint of how much Pearson thinks their contract with Chegg may have cost them. While the numbers here don’t translate directly into Pearson losses, they do give us an order-of-magnitude sense of the amount of business here.

    More immediately interesting to me, though, is this paragraph from the complaint:

    As part of Pearson’s focus on pedagogy, Pearson and its authors devote
    significant creative effort to develop effective, imaginative, and engaging questions to include in the textbooks it publishes. Pearson’s end-of-chapter questions are strategically designed and carefully calibrated to reinforce key concepts taught in the textbooks, test students’ comprehension of these issues, enhance students’ problem-solving skills, and, ultimately, improve students’ understanding of the subject matter. Pearson’s textbooks can contain hundreds or thousands of end-of-chapter questions. These end-of-chapter questions form core components of the teaching materials contained in Pearson textbooks and are frequently hallmarks of Pearson titles. As such, the availability, quality, and utility of these questions are often important considerations when educators select which textbooks to adopt for their courses.

    Pearson v. Chegg complaint

    While the lawsuit doesn’t interest me, the core issue about the value of assessment question construction does. At first blush, it’s tempting to think that the answer to “Solve for x: x2 + 3x +9 = 0″ could not possibly be intellectual property. But, as Pearson’s complaint states further down,

    One of the points of my original post was that companies like Chegg exist in part because instructor grading policies put students in a position between wanting to learn and needing to pass. While that tension is unavoidable in some cases, it is largely avoidable in many cases. We simply haven’t taught instructors about productive ways to grade formative assessments (or even what formative assessments are).

    But the lawsuit brings up a separate and equally important angle. When we step back from the deforming effect of grading and simply look at the assessments themselves, we see teaching craft. Both the construction and the order of well-written questions are designed to probe the finer points of students’ understanding. And in some cases, it teaches those finer points. When students are asked to solve a problem that has one new twist from the previous one, sometimes they learn just by figuring out that twist in the moment.

    Pearson is arguing in their complaint that substantial teaching craft is built into their question construction. It has a financial value to the company because it’s part of the value proposition of their product. Setting aside the legal question of whether recreating homework answers constitutes copyright infringement under current US law, I agree with Pearson about the value. I also think that the publishers should not have a de facto monopoly on the craft that creates that value.

    Sometimes the questions don’t work as intended. It could be a flaw in the question construction, like an obvious correct answer or, conversely, confusing wording that trips up some students who understand the concept, causing them to give an answer that is considered “incorrect.” Or the sequencing could be off. If the order of questions can be carefully crafted for pedagogical reasons, then anti-cheating functions like question randomization or algorithmically generated questions can take away that tool. And sometimes the question may be written in a way that requires cultural or other context that not all students have in order to understand them. (IQ and other standardized tests were particularly notorious for their cultural biases in their early decades.)

    For a variety of reasons, good educators will tweak and invent assessment questions to fit the needs of the students in front of them. And yet, how many assessment EdTech tools can you think of that do a good job of helping instructors learn and share craft in this regard? It’s quite easy to break a good, psychometrically validated assessment design unintentionally by adding problems that are easier or harder than the instructor thinks they are, for example. On an even more basic level, nobody ever taught me how to write a good distractor or even what that term meant. I had to pick that craft up on my own, first by instinct and later by reading and by asking experts. (I am lucky enough to have had access to such experts.)

    There has to be a balance. On one hand, instructors should be taught how to recognize and analyze the embodied craft of the assessment questions that they use as part of a curricular product. On the other hand, we should not assume that those assessments are perfectly designed or even that there is any such thing as a single perfectly designed assessment for all teaching contexts in which a curricular product may be used.

    Instructors will very often use a mix of pre-made assessment questions and their own. And if they don’t have one tool that lets them do both, then they will mix bits of assessments from different tools with very little way to integrate the information usefully. No product I know of is currently doing a good job of helping instructors think through how to mix and match well. Even dedicated publisher homework platforms like Pearson Mastering or MHE ALEKS, which are theoretically intended for supporting exactly this use case, struggle to strike a balance between the features where the platform is making design- and data-driven decisions and the features where the instructors can insert their own problems. Product designers tend to think of the former as their real mission and the latter as something they have to accommodate because some instructors demand a measure of control.

    This is a market failure. Some of the consequences are as follows:

    • Instructors don’t make full and appropriate use of advanced curricular products.
    • Instructors often have no way, either functionally in the product or intellectually with the skills they have been taught, to appropriately modify a crafted assessment to make it better rather than worse.
    • There are not tools that enable instructors to look across their entire collection of assessments and easily evaluate how the pieces are working together.
    • There are no clear and easy means for instructors to collaborate with the designers of their curricular products, other adopters of the product who are master teachers, or even their campus faculty support staff, to help them upcycle the curricular product into a course design that is as good as or better than what they’re starting with.

    One way to look at copyrighted material is as embodied craft. We have gotten hung up on the idea that the particular embodiment is the locus of educational value. Hence, the lawsuit. Instead, we should really be working on how we can enable and encourage career educators to become expert practitioners and empower them with tools that enable them to practice their craft with more skill and precision. While they shouldn’t have to craft everything from scratch, neither should they be forced to live in a world where there’s a hard and opaque wall between the course design components that they are upcycling and the ones that they are crafting themselves.

  • Ed Tech Cybersecurity: Suppose they gave a data breach and nobody came

    Ed Tech Cybersecurity: Suppose they gave a data breach and nobody came

    It has now been four weeks since Chegg announced a data breach compromising personal information of up to 40 million users. Cue the crickets because the only coverage in ed tech press thus far is from EdWeek, which focuses on the K-12 market. That’s a shame, because if ed tech companies want a case study to help understand the implications of FBI warnings or the European Union’s new Global Data Privacy Regulations (GDPR), this example from Chegg should be illustrative. The same goes for institutions.

    As a recap, Chegg discovered on September 19th a data breach dating back to April that “an unauthorized party” accessed a data base with access to “a Chegg user’s name, email address, shipping address, Chegg username, and hashed Chegg password” but no financial information or social security numbers. The company has not disclosed, or is unsure of, how many of the 40 million users had their personal information stolen. On September 25th Chegg notified the SEC about the breach, focusing on guidance for company financials. The company then started notifying users and “certain regulatory authorities” on September 26th.

    A “hashed password” is a typical process where the entered password is converted to random-looking cryptographic characters not intended to be decrypted. Subsequent password entries use the same hash again and software compares not the passwords but the hashed passwords to see if they come out identical. While this practice of one-way hashes is well-known, there are far too many web sites (including in ed tech) using plain text, reversible hashes, or poor cryptography schemes.

    This 2016 article in Wired gives a good overview of hashing and data breaches and notes that the level of compromise depends on the details.

    In theory, no one, not a hacker or even the web service itself, should be able to take those hashes and convert them back into passwords. But in practice, some hashing schemes are significantly harder to reverse than others. The collection of 177 million LinkedIn accounts stolen in 2012 that went up for sale on a dark web market last week, for instance, had actually been hashed. But the company used only a simple hashing function called SHA1 without extra protections, allowing almost all the hashed passwords to be trivially cracked. The result is that hackers were able to not only access the passwords, but also try them on other websites, likely leading to Mark Zuckerberg having his Twitter and Pinterest accounts hacked over the weekend.

    By contrast, a breach at the crowdfunding site Patreon last year exposed passwords that had been hashed with a far stronger function called bcrypt, the fact of which likely kept the full cache relatively secure in spite of the breach.

    What is problematic with the Chegg data breach is that no further information has been made public and there has yet to be any interest from the broader ed tech press to dig up answers. We have no idea how serious this breach is, and I do not believe that the users with compromised personal information have had any updates since the initial email blast and associated post.

    Less than one week before the Chegg discovery of the data breach, the FBI put out a warning about ed tech and K-12 schools, but the details could easily be applied to higher education.

    The FBI is encouraging public awareness of cyber threat concerns related to K-12 students. The US school systems’ rapid growth of education technologies (EdTech) and widespread collection of student data could have privacy and safety implications if compromised or exploited.

    EdTech can provide services for adaptive, personalized learning experiences, and unique opportunities for student collaboration. Additionally, administrative platforms for tracking academics, disciplinary issues, student information systems, and classroom management programs, are commonly served through EdTech services.

    There is also the GDPR angle described in the EdWeek article.

    One of the first to call attention to the Chegg breach was Hill, an education consultant and market analyst for the company MindWires Consulting who posted a blog and a tweet about the SEC disclosure. [snip]

    One of the more pressing questions is whether the breach will draw the scrutiny of data-privacy regulators, said Hill in an interview. He pointed to the new rules put in place as part of GDPR, the sweeping European data privacy regulation that took effect earlier this year.

    The European policy has come into focus recently with the admission by social media giant Facebook — which has a major presence in schools — that hackers gained access to 50 million of its accounts. European authorities have said they are investigating how many users on the continent were affected, and whether it would trigger GPDR enforcement.

    The Facebook breach was no doubt more problematic, as its breach exposed far more personal information as well as access to Facebook Login, thus compromising third-party platforms. But both data breaches involve consumer-based systems and similar numbers of users. In legal terms, however, GDPR is based on protecting citizens of the European Union. When I asked a Chegg spokesman about the GDPR-based notifications, they replied in general terms.

    We actually do have an office in Berlin. Chegg’s customer base is principally US-based, and the core focus of our business is the United States. We are providing notice to the particular regulatory agencies, in the US and Internationally- including Europe.

    GDPR has been criticized as creating impossible to fully comply requirements, and there are two aspects worth covering here – Supervisory Authority and Notification of Data Breach. This article gives a good summary and whom to notify – the Supervisory Authority.

    For most companies, choosing a GDPR Lead Supervisory Authority is a straightforward decision. A company based in Paris, France would appoint the supervisory authority in France as the lead supervisory authority. A UK-based company would choose the Information Commissioner’s Office (ICO), which is the supervisory authority for the UK.

    For companies that operate in multiple EU member states, the lead supervisory authority would normally be the supervisory authority in the country where the company’s headquarters is or where its main business location is in the EU. More specifically, it would be the Supervisory Authority in the country where the final decisions are made about data collection and processing.

    A U.S. company that does not have a base in an EU member state has a problem. If it does not have a base in an EU member state where data procession decisions are made, it will not benefit from the one-stop-shop mechanism. Even if a company has a representative in an EU member state, that does not trigger the one-stop-shop mechanism.

    The company must therefore deal with the supervisory authority in every member state where the company is active, through its local representative.

    In Chegg’s case, presumably the Berlin office allows them to use the one-stop mechanism of a lead authority. But smaller ed tech companies may not have this benefit and require interactions with many different country regulators ((Genius system – make the process much more difficult for smaller companies.)).

    What about notification requirements in the case of a data breach? The relevant section is Article 33 of GDPR where Chegg would be a “controller” [emphasis added].

    • In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. 2Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
    • The processor shall notify the controller without undue delay after becoming aware of a personal data breach.
    • The notification referred to in paragraph 1 shall at least:
      1. describe the nature of the personal data breach including where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal data records concerned;
      2. communicate the name and contact details of the data protection officer or other contact point where more information can be obtained;
      3. describe the likely consequences of the personal data breach;
      4. describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

    In this case, Chegg would have had to notify its Lead Supervisory Authority by September 22 the details described above. According to the SEC form, initial notifications to regulators beyond the SEC started September 26.

    Would there be a lawsuit based on this delayed notification? We don’t know yet, but one important distinction is that in the EU the process must go through the official data regulators. Article 77 of GDPR specifies these actions.

    Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.

    In other words, a country regulator must decide whether it wants to pursue action against Chegg. In the US, similar complaints or lawsuits can be filed by individuals against the company with a data breach. The intention of GDPR is to go after the big tech companies – Google, Facebook, etc – and Chegg may be too low-profile to warrant close attention. Despite the large numbers involved of up to 40 million users, it is unknown how many are EU citizens.

    Will there be further fallout for Chegg than the initial flurry of financial news that helped drive down its stock price by 21 percent since the notification? It looks like the biggest issue is job security for US lawyers, as there have been at least four dozen lawsuits seeking class-action status filed with the general theme of the company not securing its systems properly or not notifying investors of the risks of data security. I have no idea if any of these will stick ((These types of lawsuits come out of the woodworks when stock prices drop.)), but Chegg’s initial focus on SEC and financial notifications seems well-placed.

    In the meantime, other ed tech companies would do well to view this data breach as a case study and opportunity to figure out how secure their systems are, and if they would be able to comply with GDPR regulations (or if they would be required to do so). More broadly, how many companies collecting personal information use adequate protection of hashed passwords? How many know what to do in the case of a data breach? Now is the time to find out and take action, before the next event occurs.

    I will repeat my call that Chegg needs to more fully disclose the details of the incident to the general public. There has been no new information shared by Chegg based on its investigation. I would add that this subject should get more attention from ed tech press.

    Update: Based on interaction with executive director of OpsecEdu, the description of common password security approaches has been changed to not state that most use one-way hashing.

  • Chegg Data Breach May Affect Up To 40 Million Users

    Chegg Data Breach May Affect Up To 40 Million Users

    Chegg – a publicly-traded provider of digital textbooks, tutoring and study guides – notified the SEC yesterday that they learned a week ago about a security breach dating back to April 2018. In their 8-K filing:

    On September 19, 2018, Chegg learned that on or around April 29, 2018, an unauthorized party gained access to a Company database that hosts user data for chegg.com and certain of the Company’s family of brands such as EasyBib. The Company understands that the information that may have been obtained could include a Chegg user’s name, email address, shipping address, Chegg username, and hashed Chegg password. The investigation into the incident, which is supported by third-party forensics, is ongoing. To date, the Company understands that no social security numbers or financial information such as users’ credit card numbers or bank account information were obtained. The Company expects to start notifying approximately 40 million active and inactive registered users and certain regulatory authorities on September 26, 2018.

    Chegg takes the security of its users’ information seriously and will be initiating a password reset process for all user accounts.

    Note that the company learned of the data breach a week ago, and the notifications appear to be centered on calming investors (their stock price dropped 12% based on the news). The only way that I discovered this news was through financial market notifications and their 8-K filing:

    In connection with the disclosure of the security incident discussed in Item 8.01 below, on September 25, 2018, Chegg, Inc. (the “Company” or “Chegg”) reaffirmed its previous guidance for the third quarter of 2018 as most recently stated in the press release issued on July 30, 2018 and furnished as an exhibit to a Current Report on Form 8-K filed that day with the Securities and Exchange Commission (the “SEC”) (the “July Guidance”). Chegg also announced that it currently believes that the security incident discussed in Item 8.01 below will not have a material impact on its financial results for the full year ending December 31, 2018.

    According to their filing, Chegg is notifying current and former users starting today, but as yet there has been no public notification. I do not know why it took the company a full week for notifications to begin, but I suspect it is due to internal investigations to fully understand the nature of the breach – what was compromised and what was not.

    For reference, California privacy laws do not stipulate exactly how quickly companies must notify users of a data breach. The law stipulates:

    The disclosure shall be made in the most expedient time possible and without unreasonable delay, consistent with the legitimate needs of law enforcement, as provided in subdivision (c) [ed. section on cooperation with law enforcement], or any measures necessary to determine the scope of the breach and restore the reasonable integrity of the data system.>

    What is missing thus far is useful information for the public. What happened, how did this happen, what steps Chegg has taken to mitigate the risk, whether there remains a security vulnerability. I suspect it was wise to only disclose this breach to public equity markets based on guidance for financial losses, and not to the general public.

    Chegg needs to more fully disclose the details of the incident to the general public, and do this very soon.

    Update 1: I have modified post title to more accurately reflect that it is unknown how many user accounts were accessed. Here is a ZDNet article with additional descriptions.

    Update 2: I contacted Chegg for additional information. Their spokesperson said the company “a lot of obligations of how and when disclosures of non-public information can be made”, and that a public post is now available with further descriptions.

    We recently discovered that some user account data from Chegg.com, or of one of its family of student services, may have been acquired by an unauthorized party. Our understanding is that the data that may have been obtained could include names, email addresses, shipping addresses, Chegg usernames, and hashed Chegg passwords. Our current understanding is that no financial information such as credit card numbers, bank account information, or social security numbers was obtained. As a result, we are prompting users to change their Chegg.com or Chegg affiliate passwords upon login.

    [snip]
    For more information, please review the FAQs below.

    FAQ:

    1. What happened?
      • We recently discovered that some user account data from Chegg.com, or of one of its family of student services, may have been acquired by an unauthorized party.
      • While our investigation into this matter continues, we are letting users know what we know now because we value our relationship with them.
      • An investigation, supported by a third-party forensics firm, was commenced.
    2. What information was affected?
      • Our understanding is that the names, email addresses, shipping addresses, Chegg usernames, and hashed Chegg passwords of some of our users may have been obtained as a result of this incident.
      • Our current understanding also is that no financial information such as credit card numbers, bank account information, or social security numbers was obtained.

    There are six additional questions addressed in the FAQ section. This post is a good step forward in transparency, although I believe it was a mistake not to have this available at the same time as notifications to the SEC and financial markets. We will update as we get new information.

  • A Big Reason That Digital Textbooks Are Misunderstood

    Chegg, which is in the midst of a dramatic change in their business model by moving from textbook rentals to digital student services, got slammed last week in the stock market. After reporting mixed results of better-than-expected earnings yet worse-than-expected revenues, their stock price lost 35% in one day (Feb 22). But this is not a story about Chegg or stock prices. What I find fascinating is an explanation that Chegg CEO Dan Rosensweig provided about e-textbooks in his discussion with analysts.

    Far too often people assume that digital equals low costs, even for textbooks. Then we get reports and surveys looking at digital textbooks as a method to “save money”, where it is almost assumed that digital textbooks do save money; it’s just a question of whether faculty take this fact into consideration. Or stock market analysts make the same assumption, which was the topic of Rosenweig’s discussion on Mad Money. In this conversation, as described at Seeking Alpha, Rosenweig made a very interesting observation.

    Another misunderstanding is how e-textbooks affect Chegg’s revenue. Chegg has historically recognized 100% of the revenue from e-textbook sales. Interestingly, Rosensweig claims that e-textbooks used to be growing at 60% a year but have since slowed to 0%. In his Mad Money interview, Rosensweig explained that this decrease does not actually stem from volume, rather it is due to an unforeseen imbalance in the price of textbooks.

    Students are choosing to rent textbooks in print rather than e-textbooks because the former are far cheaper. Rosensweig exemplifies this with Chegg’s most popular textbook, Campbell’s Biology. The price to rent this book in print is $20, compared to $107 for the e-book version. Who would purchase an e-book when he or she could rent the paper version for one-fifth the price?

    (more…)

  • The Massive Decline In Larger Education Company Market Caps

    After our coverage of Blackboard’s CEO change last week, we were both interviewed by the Washington Business Journal, with the following lede:

    Analysts and sources I spoke with Monday, both on and off the record, said the decision to bring on Bill Ballhaus as CEO was a combination of Bhatt failing to make progress building the company’s business and lacking the experience needed to successfully run a company of that scale. And that means at least several years before Providence Equity Partners, which owns a majority of the company after paying $1.64 billion for it in July 2011, begins actively marketing the company for sale, according to industry experts.

    Earlier this week I wrote about Apollo Education Group, parent of the University of Phoenix, putting itself up for sale due to its weakening financial position. I also noted that I doubt that McGraw-Hill Education is going to be able to go public in the near-term. Part of the reason for this latter observation is the dramatic fall of Pearson in the stock market, triggered by its warnings that it would miss earnings estimates. In Audrey’s excellent year-end post on the business of ed tech, she noted:

    Private equity firms sure love buying ed-tech companies. Perhaps because the stock market’s sorta “meh” about them.

    (more…)

  • Pitchbook Lists Most Valuable Ed Tech Companies

    Update: Jeez – sorry about the multiple typos (mistakenly showed in thousands instead of millions). Fixed now.

    Pitchbook – a database service for M&A, private equity and venture capital – listed in Hot Topics what they saw as the top ten most valuable ed tech companies based on public valuations ((Note that estimates are as of the end of 2014.)). The definition of startup is a little loose, as one company (D2L) was founded in 1999 and public companies are excluded.

    Below are the market valuation estimates, to which I have added the year each company was founded along with the total funding by each company in parentheses, according to Crunchbase data.

    Company (year founded, funding total)  Market Valuation

    1. Pluralsight (2004, $169m)            $1.0 billion
    2. Instructure (2008, $79m)               $554 million
    3. Lynda.com (1995, $289m)             $456 million
    4. Coursera (2012, $85m)                   $367 million
    5. Open English (2006, $120m)        $350 million
    6. Craftsy (2010, $106m)                   $339 million
    7. D2L (1999, $165m)                        $330 million
    8. Lumos Labs (2005, $68m)           $265 million
    9. Clever (2012, $44m)                      $247 million
    10. Edmodo (2008, $88m)                 $236 million

    (more…)

  • Links to External Articles and Interviews

    Last week I was off the grid (not just lack of Internet but also lack of electricity), but thanks to publishing cycles I managed to stay artificially productive: two blog posts and one interview for an article.

    Last week brought news of a new study on textbooks for college students, this time from a research arm of the  National Association of College Stores. The report, “Student Watch: Attitudes and Behaviors toward Course Materials, Fall 2013″, seems to throw some cold water on the idea of digital textbooks based on the press release summary [snip]

    While there is some useful information in this survey, I fear that the press release is missing some important context. Namely, how can students prefer something that is not really available?

    March 28, 2014 may well go down as the turning point where Big Data lost its placement as a silver bullet and came down to earth in a more productive manner. Triggered by a March 14 article in Science Magazine that identified “big data hubris” as one of the sources of the well-known failures of Google Flu Trends,[1] there were five significant articles in one day on the disillusionment with Big Data. [snip]

    Does this mean Big Data is over and that education will move past this over-hyped concept? Perhaps Mike Caulfield from the Hapgood Blog stated it best, including adding the education perspective . . .

    This is the fun one for me, as I finally have my youngest daughter’s interest (you made Buzzfeed!). Buzzfeed has added a new education beat focusing on the business of education.

    The public debut last week of education technology company 2U, which partners with nonprofit and public universities to offer online degree programs, may have looked like a harbinger of IPO riches to come for companies that, like 2U, promise to disrupt the traditional education industry. At least that’s what the investors and founders of these companies want to believe. [snip]

    “We live in a post-Facebook area where startups have this idea that they can design a good product and then just grow, grow, grow,” said Phil Hill, an education technology consultant and analyst. “That’s not how it actually works in education.”