Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

271–280 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#271

Earlier quoted context omitted.

You forget things can be signed, with the key owned by the school. It can be done.

Does signing really make this easily auditable from the professor’s perspective?

Exactly this, when was the last time a HN user had to interact with the prototypical 60-year-old set-in-their-ways professor?

Extremely non-tech savvy, hates computers, and is gonna grumble "What the hell is a PGP? Better not be another one of those phone code things." as you try to pitch this highly-technological solution to a largely niche problem domain.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#272

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

Shouldn’t we be focusing on making it harder to pay overseas criminals in the first place? /ahem/ crypto platforms facilitating transfers to bad actors /ahem/

But, then, how would Trump’s family and cronies get paid?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#273
post #212

Earlier quoted context omitted.

> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)

Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.

> Students having records of what their score was doesn't prove to the professor / university what score they received

It's better than nothing. (And good training for the real world.)

Also, most universities (and many schools now) issue academic e-mail addresses to students. In those cases, the email is definitive proof.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#274
post #220

Earlier quoted context omitted.

> Not much overlap between students and HN these days, though? That's my biggest fear.

Is there any internal data on where students are going instead?

Perhaps some interest-related Discord servers. Tragically, Discord is just another locked down silo without publicly accessible front on the web.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#275
post #235
post #212

Earlier quoted context omitted.

Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.

As opposed to a screenshot of a website? Presumably the professor has a spreadsheet of all assignment grades that is submitted to the school?

> Presumably the professor has a spreadsheet of all assignment grades that is submitted to the school?

This would undermine Canvas's lock-in.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#276

Earlier quoted context omitted.

Backups are definitely helpful in ransomwares, but before systems can be restored and brought back online, victim organizations still need to assess the scope of the breach, find the initial access vector, identify compromised accounts, and evict the threat actor. That can take time.

I’m not certain, but it appears you’re giving Instructure a pass here, as if this is the first time they were hacked. But, it’s the second, by the same group. As a parent of kids who are impacted by this, I’m not super concerned about the data being held for ransom, but I sure as fuck am concerned about how much it’s going to cost the district to move to another provider.

Not at all; standard IR procedure is scope -> containment -> eradication -> recovery. There is a fog right now; we don't know all the details. It seems to me that it's just as likely they weren't fully kicked out before or that the initial vulnerability wasn't remediated. You can't recover until the threat actor has been removed.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#277

Earlier quoted context omitted.

Backups are definitely helpful in ransomwares, but before systems can be restored and brought back online, victim organizations still need to assess the scope of the breach, find the initial access vector, identify compromised accounts, and evict the threat actor. That can take time.

I’m not certain, but it appears you’re giving Instructure a pass here, as if this is the first time they were hacked. But, it’s the second, by the same group. As a parent of kids who are impacted by this, I’m not super concerned about the data being held for ransom, but I sure as fuck am concerned about how much it’s going to cost the district to move to another provider.

> I sure as fuck am concerned about how much it’s going to cost the district to move to another provider

Does Canvas have cybersecurity insurance?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#278
post #148

Earlier quoted context omitted.

Lot of experience dealing with Canvas/Instructure. Tech is o-k. Culture seems to be full of themselves due to market position.

Yeah like their page says "Scheduled Maintenance" which is total B.S. Talking to people at my university's IT side of things Canvas has said nothing to any clients.

The "scheduled maintenance" thing is likely just because that's the easiest maintenance page to throw up site wide, or at least it was back when I was on the Canvas deploy rotation back at Instructure ~10 years ago.

That doesn't excuse any of their other messaging though.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#279

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

> Incidents like this should be followed by an audit and charges being laid

What? Why? Who died? This whole thing is perfectly dealt with through civil process.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#280

Earlier quoted context omitted.

This is a solved problem in pretty much every other domain of life - if you are following best practises but something that wasn't reasonably forseeable happens, then you're fine, but if the bad thing happens as a result of negligence then you are in trouble.

Criminal law isn't about making things alright for the victim. That's what insurance is for. Even if you leave your door unlocked, if someone walks in and steals your stuff, it's a crime. The state has an interest in prosecuting crimes even if the victim didn't do everything they could to prevent it .

> Criminal law isn't about making things alright for the victim

Restitution and retribution are the components of justice [1] entirely about "making things alright for the victim."

[1] https://www.unodc.org/e4j/en/crime-prevention-criminal-justi...

Post reply on HN