Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

191–200 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#191

I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, witho…

(Comments were split across multiple threads and we've since merged them.)

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#193
post #155

My kids are in the middle of their finals week. What a mess. Universities know nothing, Canvas claims to be in a "scheduled maintenance", and one Prof claims to "not have any copies of material offline" which seems pretty negligent. Sounds like one section of a popular class will be doing paper exams while other sections had Canvas-based "half points for 2nd attempt"-type exams earlier today. How soon before names &…

The "Scheduled Maintenance" is just total B.S. and just honestly makes them look worse. Apparently according to their status pages this is what 99.996% uptime looks like. Pay attention lol.

Once again, an example of why corporations should not have free speech. Corporate statements that are transparent lies should be criminally actionable.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#194

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

Shouldn’t we be focusing on making it harder to pay overseas criminals in the first place? /ahem/ crypto platforms facilitating transfers to bad actors /ahem/

[dead]

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#195

Earlier quoted context omitted.

How could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know? I do agree with the audit and punishments for clear failure to adhere to established standards.

This is a solved problem in pretty much every other domain of life - if you are following best practises but something that wasn't reasonably forseeable happens, then you're fine, but if the bad thing happens as a result of negligence then you are in trouble.

Criminal law isn't about making things alright for the victim. That's what insurance is for.

Even if you leave your door unlocked, if someone walks in and steals your stuff, it's a crime. The state has an interest in prosecuting crimes even if the victim didn't do everything they could to prevent it.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#196

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

Backups are definitely helpful in ransomwares, but before systems can be restored and brought back online, victim organizations still need to assess the scope of the breach, find the initial access vector, identify compromised accounts, and evict the threat actor. That can take time.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#197
post #27

I wonder how much old data Canvas keeps around? Are students who graduated in 2016 going to be at risk of having their academic data leaked?

I bet it depends on the institution and the IT team behind said institution, but at least for my university we apparently don't delete old course shells or anything.

I'm friends with a professor who complained to me a couple times about how sometimes he will need to scroll through pages and pages of courses he taught in the past. He also mentioned that profs aren't able to delete their own course shells either.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#199
post #99

Earlier quoted context omitted.

Your "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.

Complete internet blockage of nations allowing the attacks. If foreign governments are you can always execute them. We are living in a different world where this is no longer a zero probability occurrence.

[dead]

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#200

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

[deleted]
Post reply on HN