e-Literate

Present is Prologue

Tag: Phil Hill

  • The Tide is Turning – SOPA May Not Make It Out of Committee

    Over the past few days, there have been three significant developments that indicate the tide is turning on SOPA (and the Senate version, PIPA). As I have written previously, SOPA poses a threat to open education and educational technology in general, while most educational publishers are actively supporting this legislation. At the end of 2011, SOPA appeared to be likely to pass, with strong bipartisan support for the legislation. Since that time, there is a growing backlash, particular from technology companies as well as online communities such as Reddit. This backlash is having a real effect, and as of this weekend,  SOPA may not even make it out of the House Judiciary committee.

    (more…)

  • Four Key Questions for the Apple Education Announcement

    There is growing buzz online about Apple’s planned media event on January 19th in New York City. Most speculation is focused on Apple distributing textbooks through iTunesU, as described in a New York Times blog. The basis for most speculation seems to be the short comments in the Walter Isaacson official biography of Steve Jobs. This information, along with some additional inside sources have led the NYT blogger Nick Wingfield to suggest that textbooks might be offered for free. In a post on Mashable, Kate Freeman suggests a partnership with publishers such as Pearson Education.

    (more…)

  • Analysis of Instructure Security Testing

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities. Instructure also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified. Part 1 of this series of posts described the concept. Part 2 gave a mid-term update, describing the process involved and initial results. Part 3 described the full results of the security assessment. In this final post on the experience I’d like to address two subjects – my own impressions of the testing, and a call for more LMS vendors to follow suit and make their security testing more transparent.

    Results Themselves

    As described in part 3, the risk assessment found 10 vulnerabilities – 1 critical, 1 high, 4 moderate and 4 low risk – in the Canvas LMS system. I do not have a basis to judge the relative number of vulnerabilities found compared to Instructure’s competitors, as there is not an industry-specific standard on the depth and extent of penetration testing, but by all appearances the Canvas LMS system is a well-designed, generally secure application. I base this judgment on two factors:

    (more…)

  • Educational Publishers Appear to be Supporting SOPA

    UPDATE 12/23: Per the House Judiciary Committee, it is now confirmed that these companies are on the record supporting SOPA and the Protect IP companion legislation.

    Yesterday the House Judiciary Committee began the process of marking up the Stop Online Piracy Act (SOPA) bill. From all appearances, most of the amendments have been rejected, thus leaving SOPA essentially in its original form. While passage is not assured, it is certainly a possibility as described by CNET.

    After a marathon debate on the Stop Online Piracy Act, it’s clear that the Hollywood-backed bill enjoys enthusiastic support among key members of the U.S. House of Representatives and is one step closer to becoming law.

    That became obvious after every legislative attempt to defang, rewrite, or significantly alter SOPA over nearly a 12-hour period today ended in victories for large copyright holders–and defeat upon defeat for the bill’s critics.

    While the SOPA impacts are not fully understood, there are some real dangers to educational usage that we need to follow. As described in my first post on the subject, SOPA could have a major impact on institutions using any form of educational technology to share content outside of a tightly-controlled password-protected course site. As we saw at EDUCAUSE this year, much of the potential of educational technology is to facilitate sharing of content outside of the traditional “walled gardens” of traditional LMS solutions, and enabling collaboration more broadly.

    This year’s EDUCAUSE keynote speaker, Seth Godin, has a post up at The Domino Project that calls out many of the list of “companies behind one of the lobbying groups pushing for SOPA”. On this list, lo and behold, we find most of the educational publishing companies.

    Pearson Education, Cengage Learning, McGraw-Hill Education, Macmillan, Scholastic, etc. They are all on the list.

    (more…)

  • Instructure Security Assessment Results

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities.  Instructure has also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.  Part 1 of this series of posts described the concept.  Part 2 gave a mid-term update, describing the process involved and initial results.  In this post I’ll describe the full results of the security assessment.  I’ll add my actual analysis in the final post.

    The purpose of the testing was to validate and review the Canvas LMS design and implementation with respect to vulnerabilities that could be exploited by a motivated hacker.  Securus employed security experts to ethically hack, both manually and with automated tools, a test environment to try and identify specific vulnerabilities, working from the perspective of both an unauthorized user and an authorized user.  There was a range of exploits tested, but the basic idea is to find out if someone could access information or functionality that should be protected by system controls including role-based security.

    Summary of Findings

    The findings were presented to Instructure on November 29, 2011 in report form and with a conference call to discuss.

    (more…)

  • Instructure Security Mid-Term

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities.  Instructure has also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.  Part 1 of this series of posts describes the concept.  In this post, I’ll give a mid-term update, describing the process involved and initial results.  In the next post I’ll describe the full results of the security testing.  I’ll try to keep my actual analysis in the final post, after I have objectively described the process and results.

    The purpose of the testing was to validate and review the Canvas LMS design and implementation with respect to vulnerabilities that could be exploited by a motivated hacker.  Securus employed security experts to ethically hack a test environment to try and identify specific vulnerabilities, working from the perspective of both an unauthorized user and an authorized user.  There was a range of exploits tested, but the basic idea is to find out if someone could access information or functionality that should be protected by system functionality including role-based security.

    There are two particular viewpoints that have led to my interest in this independent observer role.

    • No enterprise software platform is perfect and you should always expect some vulnerabilities.  The issue should not just be on whether there are vulnerabilities, but perhaps more importantly, on how a company or organization responds to a security vulnerability or incident.
    • I have called for transparency from LMS vendors and open source communities, arguing that they should share information from their third-party security audits and tests.

    (more…)

  • Regulatory Barriers to Innovation for Ed Tech and Open Education

    Over the past few weeks there has been a significant backlash growing against SOPA (the anti-piracy bills introduced in Congress) – read here or here for background.  The biggest change since the bills were introduced is that big technology vendors (significantly including Microsoft and working through the Business Software Alliance) have either withdrawn support or gotten off the fence.  The BSA is now officially lobbying against SOPA as written.  In the world of strange bedfellows, there are also a number of politicians on both sides of the aisle publicly opposing the bill.  It does take some real legislative talent to help create a Pelosi – Paul – Issa common cause.

    Despite the growing opposition, there certainly appears to be a concerted effort in Congress to get the bill passed.  The outcome is far from clear at this point.

    While SOPA by itself remains a major threat to innovation for educational technology and open education in general, it may be helpful to step back and see the growing list of federal laws and regulations that could have a major impact on innovation in higher education.  While each issue is interesting in and of itself, a pattern is emerging.  This pattern suggests that organizations interested in preserving the status quo – are actively pushing back against the tide of change brought by online systems, online education, and digital content.