Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

221–230 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#221

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

Backups are definitely helpful in ransomwares, but before systems can be restored and brought back online, victim organizations still need to assess the scope of the breach, find the initial access vector, identify compromised accounts, and evict the threat actor. That can take time.

I’m not certain, but it appears you’re giving Instructure a pass here, as if this is the first time they were hacked. But, it’s the second, by the same group.

As a parent of kids who are impacted by this, I’m not super concerned about the data being held for ransom, but I sure as fuck am concerned about how much it’s going to cost the district to move to another provider.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#222

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

[deleted]

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#224

Earlier quoted context omitted.

It has been over 5 hours now and there has not been any communication about this being an attack, despite many of us seeing the ShinyHunters message on the login page. There is a lot of people who likely are unaware the latest outage is because they were compromised again. Them marking the incident as 'Under Maintenance' means the status page isn't reporting this as an outage and adding to downtime%.

Compromised again? This is a separate in ident to the one seen yesterday?

Correct.

The incident yesterday was technically from April 28th, with most communications coming out on the 2nd and 3rd, with it being "Resolved" yesterday.

This incident is the second attack, because they failed to secure their infra again. Everything being reported is a bit delayed, which makes it seem like this is a single attack, not technically two instances.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#225
post #212

Earlier quoted context omitted.

> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)

Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.

If only we had some way of signing messages

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#226

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

> they have airgapped backups and can be working as soon as they can spin up new servers

... and assuming they have a documented, tested, and trusted restore process.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#227

Earlier quoted context omitted.

> who determines that the infrastructure wasn't properly secured An investigative body, the same kind that determines the who, the why, and the how when an airliner crashes or a bridge collapses. Obviously a lot of work needs to be done to get from point A to point B, and it won't happen overnight, but software development is currently a deeply unserious profession and at some point a genuine software engineering pra…

Pretty famously, aviation incident investigations are almost always not done with prosecutorial intent, and more about truth finding. It leads to people involved being cooperative to prevent future problems instead of ass covering to prevent jail. Aviation’s safety record is not coincidental.

In a darker reading; strong aviation safety is mostly motivated by not killing customers. An airline or plane maker who kills more customers than others will rapidly bleed those same customers and lose them to less lethal competitors. If no one cared about dying people I imagine aviation safety wouldn’t be so impressive.

As someone else here said, software, for the most part, is a deeply unserious industry. The stakes are so comparatively low and the consequences less obvious that it’s a lot easier for companies like intuit to maintain their supremacy simply by being entrenched, having strong sales teams, and the hearts & minds of non-technical managers.

In recent times it seems Boeing has been flirting with enshitification and half-assery but critics are not quiet and not falling on deaf ears

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#228

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

> let classes that normally count for a grade just submit grades as pass-fail. Because what else can you do?

Schedule a single exam and that's your grade for that subject? That's how it should work anyway, credits for work during semester (or worse attendance) are not needed to evaluate if someone learned the material, give them an exam and done.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#229

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

> they have airgapped backups and can be working as soon as they can spin up new servers ... and assuming they have a documented, tested, and trusted restore process.

Ah yes the “recovery” part of the continuity plan. We tested that right? Right?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#230

Earlier quoted context omitted.

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

I don't think that criminal negligence is the most helpful legal tool for incentivizing improved security. It's too hard to prove negligence. Instead, there should be standard civil penalties for leaking various degrees of PII paid as restitution to the affected individual. Importantly, this must be applied REGARDLESS of "certification" or whether any security practices were "incorrect" or "insufficient". Even if the…

[deleted]
Post reply on HN