Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

111–120 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#111
post #105

My wife is in grad school at a major university and is dealing with this right now the week of midterms for spring quarter. I totally understand why a university wouldn’t want to bake their own learning portals but just feels like such a single point of risk to use third party solutions for something like this. Back in my day… all we had was a school email via on-premise services. I guess we registered for classes in…

Moodle is an open-source LMS that can be self-hosted. https://moodle.org/

Another open-source LMS that can be self-hosted is... Canvas.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#112

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

How could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know?

I do agree with the audit and punishments for clear failure to adhere to established standards.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#113

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

When will countries start treating cyberattacks as an act of war? If the North Korean military came to America and robbed fort Knox of $200M in gold there would be retribution. But hack an American company for the same amount and the feds do nothing.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#114

I remember circa 2010 a friend of mine at college was like “blackboard sucks, let’s build something new”. At the time I poo pood the idea and lo and behold canvas came out a year later. Outside looking in, they been crushing it.

I worked in a college IT department around that time and the common belief was that all LMSes suck. There are just too many different ways that too many different people want to do things that it's just bound to be hated. Kind of like Jira / Asana for software dev project management.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#115
post #93
post #74

Earlier quoted context omitted.

Universities used to do this sort of stuff themselves. Then it became a business handled by purchasing rather than needs met by the department themselves.

Because faculty didn’t want to do it anymore. They want it handled by others but also they want oversight and veto power but also they don’t want to be bothered. But it better always work, and if they make a mistake the software is broken because don’t tell them it’s a user error they used to write Fortran. As a faculty member at a large university…I have a deep respect for the impossible job of university IT departm…

It is kind of funny when these LMS tools with 100+ functions are being used for little more than what email, a grades spreadsheet, and maybe a shared drive would do. University might even ask for the final grades in spreadsheet format by the end of the term anyhow, so data goes into the LMS just to come back out again.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#116
post #79

Earlier quoted context omitted.

I used both and could not tell you the major differences. I feel like they are equivalent in the bread and butter features. Most people don't use 99% of the functions they bake into these. Just use it to hold the syllabus, maybe hold the slides, submit assignments, and spreadsheet for grades. All stuff you can do with email + spreadsheet already. Maybe throw in a shared drive for larger files, which every university…

"Equivocal describes something ambiguous, uncertain, or open to multiple interpretations, often used to intentionally mislead or evade." do you mean equivalent ?.

yes

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#117

yep, i work for a major university and our canvas instance is down. this is really, really bad. edit: here's the list of impacted universities (unsure if they all have their canvas instances offline, but i'd be surprised if not): http://91.215.85.103/pay_or_leak/instructure_affected_school...

Here's an archive https://archive.is/eB2hE

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#118

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

We could also throw the CEOs of companies who don't properly secure their infrastructure and pay their security engineers enough in jail. A little justice on both ends.

Uh, who determines that the infrastructure wasn't properly secured? Who is willing to risk prison because some intern accidentally committed an API key or made a dumb mistake. Conversely, what's the chances that no one actually gets prosecuted regardless of how sloppy their security practices are?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#119
post #113

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

When will countries start treating cyberattacks as an act of war? If the North Korean military came to America and robbed fort Knox of $200M in gold there would be retribution. But hack an American company for the same amount and the feds do nothing.

Ok, so we treat it as an act of war. Now what? Attack North Korea? Great, the entire city of Seoul gets shelled within five minutes of your attack and hundreds of thousands of innocent people die.

It's very easy to play with lives that aren't yours.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#120
post #105

Earlier quoted context omitted.

Moodle is an open-source LMS that can be self-hosted. https://moodle.org/

Another open-source LMS that can be self-hosted is... Canvas.

Didn't realize that. Thanks for the info!
Post reply on HN