Some colleagues at another university are lobbying to get a WeBWorK server installed (this is a large university in Ontario with more than enough resources to handle it). They have directed their director of IT to me with questions, as someone they know who runs a WeBWorK server.
It seems that the general concern they are getting from IT is that since WeBWorK is open source, it must be full of security holes. We've never had any issues, and I've never heard of anyone else having issues either. Is there any sort of reference page I can point them to that explains how things are handled with WeBWorK, and that could help ease these concerns?
The specific questions that were sent to me are:
- How often the open-source community releases security updates for WebWorK? And how the WebWorK administrators like you are being informed about any security updates. What is the process to install them?
- How are the risks with maintaining 24/7 server operations mitigated when there is only one person responsible for supporting the application. For example, the server goes down during off hours and the students have an assignment or exam to complete.
I believe that I've signed up for a WeBWorK security updates mailing list, but I don't recall receiving any emails, perhaps because there have not been any security threats.
The second question doesn't really sound like a risk to me; more of an inconvenience. Downtime is rare, but when it happens we turn things back on when we arrive in the morning, and if an assignment was due, the instructor gives an extension.