Sam Eaton is a junior studying EECS and political economy. He is interested in the sociopolitical dimensions of digital tech and wrote a research project on Canvas this past fall.

Infrastructure should be invisible.

When the services and facilities we depend on for our daily lives work properly, they should disappear from our conscious perception, fulfilling the need for a stable foundation to build a life upon.

When Canvas-maggedon toppled our learning systems during RRR week, students reacted with a mix of divine relief and academic dread, but they became keenly aware of the systems on which UC Berkeley education is built.

Instructure, Canvas’ parent company, obviously failed to secure our educational infrastructure. Even more concerning is the way Canvas enables unjust data extraction — they themselves have been profiting off our data this entire time.

In North America, nearly half of higher educational institutions use Canvas, alongside tens of thousands of high schools and elementary schools. This centralization fosters a large array of third-party integrations and interoperability, quelling the need for reentering data and organizing data across different platforms.

Yet, it is this same centralization that creates a mouthwatering target for threat actors like ShinyHunters, the black-hat hacker group responsible for the recent Canvas hack.

The learning management system, or LMS, though not the most foundational of all infrastructures, reflects the wider realities of how we are approaching our digital futures. Breaches like this are not just sporadic occurrences; they are enabled through how these systems are built and operated.

First and foremost, Canvas is not an educational strategy. It is a product. All major LMS providers offer the same thing: a convenient way to centralize all of an educational institution’s information systems. After all, the LMS is a “management” system — more a bureaucratic tool than one that improves teaching.

Instructure is different from other LMS providers, in that it was an early adopter of the “software-as-a-service” business model, which separates the ownership of software from its usage. In other words, anyone using Canvas is outsourcing control over the software, subjecting Canvas users to an LMS dictated by an external corporation.

Moreover, Canvas uses a cloud provider to store student data and run Canvas instances or programs. Canvas argues that using Amazon Web Services, or AWS, a service which rents out technological infrastructure capable of collecting and storing an abundance of user information, allows them to be “creative in a very frictionless way.”

By using AWS, Canvas outsources all of its security and reliability concerns to Amazon. This by no means guarantees security, as even Amazon has experienced many high-profile security breaches. And as we saw this past fall semester, Canvas was rendered unavailable due to an AWS outage: It does not have perfect uptime either. That even the world’s largest cloud provider has these failures reminds us that these services are still relatively immature and very much contested.

Through the tracking of student enrollment, communication chains, assignment submissions and general site activity, this data storage fuels Canvas’s analytics environment. Canvas even offers an Application Programming Interface, a mechanism that enables communication between different software, through which you can export “event-level data” for the creation of custom Canvas dashboards.

This large data collection apparatus operates in the absence of meaningful consent — teachers and students are often required to use Canvas by their organization. The apparatus poses serious risks to student and teacher privacy. In a searing commentary, Roxana Marachi and Lawrence Quill, professors of education and political science, respectively, at San Jose State University, argue that “institutions of higher education are currently ill-equipped to protect students and faculty required to use Canvas LMS from data harvesting or exploitation.” This data harvesting is enabled by Canvas’’s configuration, which allows for an interoperability of applications and “frictionless” transfer of data between them.

One such application familiar to UC Berkeley students is Turnitin, a plagiarism checker that requires a non-exclusive, royalty-free, perpetual, worldwide and irrevocable license for anything you submit to it. Essentially, everything you submit to Turnitin, the company now owns.

When I spent a semester researching this topic last fall, there were already a host of others concerned with these problems. Common Sense Media gave Canvas a “warning” rating in a 2022 privacy report for selling personal information to third parties. Some parents even filed a class action lawsuit against Canvas, claiming their massive data collection scheme transcends any legitimate educational purposes and prioritized motives “unaligned with, and are even adversarial to, children’s privacy and healthy development.”

Amidst all of these concerns, I am most confused by UC Berkeley’s choice to use Canvas when we have so much custom digital infrastructure and IT know-how on our campus.

Sure, Canvas may be convenient, but it has also barely changed in the last decade. It contains known pedagogical problems and more obvious security vulnerabilities and privacy risks. Can’t we think of anything better?

I think we can, and professors and lecturers are already doing so at the course level. Past the most common use of Canvas that I see — uploading assignments and a syllabus — the amount of variation in digital learning infrastructure is massive: I’ve taken technical courses with custom websites and grading schemes to classes that operate entirely through a Google Doc. I believe teachers build and choose these tools because they understand that specific learning requirements necessitate specific infrastructure.

We don’t need to “manage” learning; we need to imagine what it might look like. We don’t need “seamless” data transfer and revealing analytics; we need barriers that protect student and teacher privacy.

We need more people thinking like teachers, not bureaucrats, when it comes to education technology. Once this happens, I believe our digital learning environments will look much different, much safer and much better.