e-Literate

Present is Prologue

Tag: ed tech vendors

  • Editorial Policy: Notes on recent reviews of CBE learning platforms

    Oh let the sun beat down upon my face, stars to fill my dream
    I am a traveler of both time and space, to be where I have been
    To sit with elders of the gentle race, this world has seldom seen
    They talk of days for which they sit and wait and all will be revealed

    – R Plant, Kashmir

    Over the past half year or so I’ve provided more in-depth product reviews of several learning platforms than is typical – Helix, FlatWorld, LoudCloud, Bridge. Understanding that at e-Literate we are not a review site nor do we tend to analyze technology for technology’s sake, it’s worth asking ‘why the change?’. There has been a lot of worthwhile discussion in several blogs recently about whether the LMS is obsolete or critical to the future of higher ed, and this discussion even raised the subject of how we got to the current situation in the first place.

    An interesting development I’ve observed is that the learning environment of the future might already be emerging on its own, but not necessarily coming from the institution-wide LMS market. Canvas, for all its market-changing power, is almost a half decade old. The area of competency-based education (CBE), with its hundreds of pilot programs, appears to be generating a new generation of learning platforms that are designed around the learner (rather than the course) and around learning (or at least the proxy of competency frameworks). It seems useful to get a more direct look at these platforms to understand the future of the market and to understand that the next generation environment is not necessarily a concept yet to be designed.

    (more…)

  • Instructure Releases 4th Security Audit, With a Crowd-sourcing Twist

    In the fall of 2011 I made the following argument:

    We need more transparency in the LMS market, and clients should have access to objective measurements of the security of a solution. To paraphrase Michael Feldstein’s suggestions from a 2009 post:

    • There is no guarantee that any LMS is more secure just because they say they are more secure
    • Customers should ask for, and LMS vendors should supply, detailed information on how the vendor or open source community has handled security issues in practice
    • LMS providers should make public a summary of vulnerabilities, including resolution time

    I would add to this call for transparency that LMS vendors and open source communities should share information from their third-party security audits and tests.  All of the vendors that I talked to have some form of third-party penetration testing and security audits; however, how does this help the customer unless this information is transparent and available?  Of course this transparency should not include details that would advertise vulnerabilities to hackers, but there should be some manner to be open and transparent on what the audits are saying. [new emphasis added]

    Inspired by fall events and this call for transparency, Instructure (maker of the Canvas LMS) decided to hold an public security audit using a white hat testing company, where A) the results of the testing would be shared publicly, and B) I would act as an independent observer to document the process. The results of this testing are described in two posts at e-Literate and by a post at Instructure.

    Instructure has kept up the process, this year with a crowd-sourcing twist: (more…)