e-Literate

Present is Prologue

Tag: Security

  • Instructure Releases 4th Security Audit, With a Crowd-sourcing Twist

    In the fall of 2011 I made the following argument:

    We need more transparency in the LMS market, and clients should have access to objective measurements of the security of a solution. To paraphrase Michael Feldstein’s suggestions from a 2009 post:

    • There is no guarantee that any LMS is more secure just because they say they are more secure
    • Customers should ask for, and LMS vendors should supply, detailed information on how the vendor or open source community has handled security issues in practice
    • LMS providers should make public a summary of vulnerabilities, including resolution time

    I would add to this call for transparency that LMS vendors and open source communities should share information from their third-party security audits and tests.  All of the vendors that I talked to have some form of third-party penetration testing and security audits; however, how does this help the customer unless this information is transparent and available?  Of course this transparency should not include details that would advertise vulnerabilities to hackers, but there should be some manner to be open and transparent on what the audits are saying. [new emphasis added]

    Inspired by fall events and this call for transparency, Instructure (maker of the Canvas LMS) decided to hold an public security audit using a white hat testing company, where A) the results of the testing would be shared publicly, and B) I would act as an independent observer to document the process. The results of this testing are described in two posts at e-Literate and by a post at Instructure.

    Instructure has kept up the process, this year with a crowd-sourcing twist: (more…)

  • Instructure releases their third public security audit

    In the fall of 2011 I made the following argument:

    We need more transparency in the LMS market, and clients should have access to objective measurements of the security of a solution.  To paraphrase Michael Feldstein’s suggestions from a 2009 post:

    • There is no guarantee that any LMS is more secure just because they say they are more secure
    • Customers should ask for, and LMS vendors should supply, detailed information on how the vendor or open source community has handled security issues in practice
    • LMS providers should make public a summary of vulnerabilities, including resolution time

    I would add to this call for transparency that LMS vendors and open source communities should share information from their third-party security audits and tests.  All of the vendors that I talked to have some form of third-party penetration testing and security audits; however, how does this help the customer unless this information is transparent and available?  Of course this transparency should not include details that would advertise vulnerabilities to hackers, but there should be some manner to be open and transparent on what the audits are saying. [new emphasis added]

    Inspired by fall events and this call for transparency, Instructure (maker of the Canvas LMS) decided to hold an public security audit using a white hat testing company, where A) the results of the testing would be shared publicly, and B) I would act as an independent observer to document the process. The results of this testing are described in two posts at e-Literate and by a post at Instructure.

    Instructure has kept up the practice and just released their third public security audit.

    (more…)

  • Analysis of Instructure Security Testing

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities. Instructure also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified. Part 1 of this series of posts described the concept. Part 2 gave a mid-term update, describing the process involved and initial results. Part 3 described the full results of the security assessment. In this final post on the experience I’d like to address two subjects – my own impressions of the testing, and a call for more LMS vendors to follow suit and make their security testing more transparent.

    Results Themselves

    As described in part 3, the risk assessment found 10 vulnerabilities – 1 critical, 1 high, 4 moderate and 4 low risk – in the Canvas LMS system. I do not have a basis to judge the relative number of vulnerabilities found compared to Instructure’s competitors, as there is not an industry-specific standard on the depth and extent of penetration testing, but by all appearances the Canvas LMS system is a well-designed, generally secure application. I base this judgment on two factors:

    (more…)

  • Instructure Security Assessment Results

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities.  Instructure has also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.  Part 1 of this series of posts described the concept.  Part 2 gave a mid-term update, describing the process involved and initial results.  In this post I’ll describe the full results of the security assessment.  I’ll add my actual analysis in the final post.

    The purpose of the testing was to validate and review the Canvas LMS design and implementation with respect to vulnerabilities that could be exploited by a motivated hacker.  Securus employed security experts to ethically hack, both manually and with automated tools, a test environment to try and identify specific vulnerabilities, working from the perspective of both an unauthorized user and an authorized user.  There was a range of exploits tested, but the basic idea is to find out if someone could access information or functionality that should be protected by system controls including role-based security.

    Summary of Findings

    The findings were presented to Instructure on November 29, 2011 in report form and with a conference call to discuss.

    (more…)

  • Instructure Security Mid-Term

    Instructure has engaged Securus Global to test the Canvas LMS product for security vulnerabilities.  Instructure has also invited me to be an independent observer – participating in the process and independently reporting on the testing and Instructure’s response to any vulnerabilities identified.  Part 1 of this series of posts describes the concept.  In this post, I’ll give a mid-term update, describing the process involved and initial results.  In the next post I’ll describe the full results of the security testing.  I’ll try to keep my actual analysis in the final post, after I have objectively described the process and results.

    The purpose of the testing was to validate and review the Canvas LMS design and implementation with respect to vulnerabilities that could be exploited by a motivated hacker.  Securus employed security experts to ethically hack a test environment to try and identify specific vulnerabilities, working from the perspective of both an unauthorized user and an authorized user.  There was a range of exploits tested, but the basic idea is to find out if someone could access information or functionality that should be protected by system functionality including role-based security.

    There are two particular viewpoints that have led to my interest in this independent observer role.

    • No enterprise software platform is perfect and you should always expect some vulnerabilities.  The issue should not just be on whether there are vulnerabilities, but perhaps more importantly, on how a company or organization responds to a security vulnerability or incident.
    • I have called for transparency from LMS vendors and open source communities, arguing that they should share information from their third-party security audits and tests.

    (more…)

  • Analysis of Blackboard Response to Recent Disclosure of Security Vulnerabilities

    There’s been an interesting set of public relations based on the recent news of Blackboard security vulnerabilities.  SC Magazine’s Australian edition broke a story on September 16 about an investigation by two or more anonymous Australian universities working with a security firm, Securus Global.  In conjunction with the magazine, this investigation exposed a number of security vulnerabilities with Blackboard Learn 8.0, 9.0 and 9.1 (the mainline legacy LMS from Blackboard, but not the WebCT or ANGEL acquired LMS product lines).  Blackboard has confirmed the majority of the issues are valid and issued a security advisory on September 16, subsequently updated on September 22.

    That is where the agreements stop, however.  Blackboard took issue with the tone of the article in a blog post from September 23, subsequently updated on September 27.  Blackboard disputes the assertions that they were not responsive to customer requests, and further, they are trying to downplay the significance of the vulnerabilities. (more…)