Item bank for new quizzes is a huge security risk

chris_zimmer
Community Explorer

I am a noob to the new quizzes feature and how it does item banks. With that out of the way...

When I open the Item Banks link to build a new bank or look at existing banks, and I select "All Banks" I see ALL the banks from across my entire university. Hundreds of banks that are not mine that I did not create, and have nothing to do with my content area.

Worse yet, I can share, copy, edit, and delete any one of these banks.

This is a HUGE security risk and surely this isn't the way Instructure intends for item banks to work. I'm not finding much about it. This is a new thing to my local Canvas admins as well. This renders the new quizzes completely useless to me. All it takes is one unethical individual and thousands of banks are compromised. I'm not going to waste any more time building banks knowing that anyone can delete, edit, or share them.

I'm an IS professor and teach basic computer security, and this just can't be real. This is just mind boggling.

0 Likes
Users who also had this question