Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

181–190 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#181
post #141

A friend who teaches at MIT said they were hit by this. I found it ironic and a little sad that a place like MIT doesn't have an IT staff that can maintain their own on-prem solutions for things like this. But it turns out that MIT used to have their own homegrown system, and recently switched to Canvas. Bet they're regretting that now. The build vs. buy decision seems to have swung very hard toward buy in the last d…

I started my tech career in EDU. I’m not at all surprised.

IT staff who are ambitious and talented don’t last long in education. The pay is very low compared to industry. Where I worked, you could retire with a comfortable pension after a number of service years, so the IT staff outsourced as much as possible so they needed to take zero risks to their nest egg. Blame all the problems on the consultants and do as little as possible.

It’s literally where dreams go to die.

MIT is known for the brilliant professors and students but at the end of the day, running a university is pretty standard stuff. They don’t need a genius rockstar to admin the courseware servers.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#183

My wife is in grad school at a major university and is dealing with this right now the week of midterms for spring quarter. I totally understand why a university wouldn’t want to bake their own learning portals but just feels like such a single point of risk to use third party solutions for something like this. Back in my day… all we had was a school email via on-premise services. I guess we registered for classes in…

I totally understand why a university wouldn’t want to bake their own learning portals They used to, in the pre-cloud/SaaS era; and they were much simpler and better UX than the slop that they're renting today, because the actual users were not far from the developers.

Counterpoint: I was a PhD student in 2004 and on the universities board* which oversaw the roll-out of the campus management system. It cost > 10m EUR to implement a shitty system with the worst UX and years of stabilizing to make it somewhat work.

The amount of corner cases and performance requirements during rush times (semester start) made it really infeasible for a university to roll their own.

* German universities have this funny system where 51% of such boards are controlled by the professors and the rest is made up of other employees/staff and students. They call it academic participation.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#186

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

> No this will not stop this and companies need to be held accountable for their lack of security investment.

I think in principle, its sound. Im also just baffled hearing anecdotes from friends that are in big corp world and hearing the type of incidents they have, and how they respond to it.. It makes me wonder if there is enough capable talent to go around for the "boring corp" crowd.

Hint: I don't think there is nearly enough talent to go round, but for these companies, its either that they think they have solid experts (and didn't), OR its not a real priority until you get hit.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#187

Earlier quoted context omitted.

How could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know? I do agree with the audit and punishments for clear failure to adhere to established standards.

This is a solved problem in pretty much every other domain of life - if you are following best practises but something that wasn't reasonably forseeable happens, then you're fine, but if the bad thing happens as a result of negligence then you are in trouble.

"Best practice" in cybersecurity is largely vendor-driven with little to no independent empirical validation.

That standard is likely to lock people into buying some pretty bad software, but it does little to ensure that they're running reasonably secure systems.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#189

I'm shocked universities don't host their own LMS? At least large universities have the IT departments to do this. They host compute clusters, so they can certainly host an LMS.

The same reason hospitals don't have their own Patient Information System but all use Epic. The amount of customization you need and continuous churn due to changing curricula and regulatory requirements makes it hard to keep up without scale.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#190
I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year.

Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, without exception, due to ADA compliance regulations. It is explicitly forbidden for professors to, e.g., refer to pdfs posted on a personal website.

Other commentators here seem not to understand that many faculty also do not enjoy being forced to use Canvas.

Post reply on HN