Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

291–300 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#291
post #220

Earlier quoted context omitted.

Not much overlap between students and HN these days, though? I’m an extremely rare outlier afaik :) The administration has so far opened with one “Canvas said” and then an hour later one “Canvas is down indefinitely” email noting that they’re aware it’s serious. (Canvas is a glorified wiki for teaching students, with quizzes and such, for those unaware.)

> Not much overlap between students and HN these days, though? That's my biggest fear.

Drop me an email if you like — it’s not really topical to Canvas but I’m happy to discuss further.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#292
post #220

Earlier quoted context omitted.

> Not much overlap between students and HN these days, though? That's my biggest fear.

Is there any internal data on where students are going instead?

You honestly don't wanna know

If my peers are any indication, a whole lot of TikTok, Reels, Twitter, Discord, and other such mind-numbing platforms.

The types of platforms I would consider 'substantive' (or, at least, more substantive than those platforms) are definitely on the way out.

The few times friends have seen me browsing Hacker News or a certain Mongolian basket weaving form, the first thing they comment on is how confusing the interface is, and how old the site looks.

I truly don't understand the mentality, but if your site doesn't take three seconds to buffer a simple text drop down menu, and have JavaScript elements load in mid-scroll that bump elements around the page making you just barely miss that button you were trying to click, then your site is seen as 'inferior' or 'sketchy'.

Perhaps I've just had a bad sample, but I've experienced a variety of different environments by this point, and by and large, I've seen more people in my generation act in that manner than not.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#293
post #289

https://status.instructure.com/ implies Canvas became available again about thirty minutes ago from the time of this post. Is this accurate? Or is this still an ongoing issue?

Ongoing. It is not "down" but purposefully offline for "maintenance." Main status does show the LMS (all the course stuff) down, and my instance shows "up" but that's because (I assume) you can reach it and the maintenance page. But that's not useful, if technically not "down."

Thanks

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#296

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

If someone robs a bank and someone inside dies of a heart attack, thats felony murder. I would be happy if the same applied to ransom attacks or other blackmail/leaking of info. If someone commits suicide because of it, its murder.

felony murder is pretty widely regarded as a leading factor in incredibly unjust prosecutions and sentencing decisions. perhaps not the best concept to build your ideas on top of.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#297

Earlier quoted context omitted.

Does signing really make this easily auditable from the professor’s perspective?

Exactly this, when was the last time a HN user had to interact with the prototypical 60-year-old set-in-their-ways professor? Extremely non-tech savvy, hates computers, and is gonna grumble "What the hell is a PGP? Better not be another one of those phone code things." as you try to pitch this highly-technological solution to a largely niche problem domain.

They don’t even need to not be tech savvy. This stuff just registers as “hassle” to most people so they do the bare minimum or search for ways to not deal with it at all. It’s easy to “tut tut” at them but ultimately we need to accept reality: privacy, security, these things take extra effort that isn’t strictly necessary for people to go about their daily lives even though the stakes can be super high. It’s not a problem until it is, so they aren’t really barriers that require people to do the work. It’s like convincing someone who just simply doesn’t want to go out and buy/install a lock on their door to go do it, except it’s not even a one-time thing. Their door works fine. They can come and go as they please. It’s not until something happens that they maybe change their tune (and even then!)

Hell just getting people to do secure passwords is a whole thing.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#298
One thing I remember from my days in the LMS world is that obfuscated copies of prod tenants were used for testing. Almost every dev had at least one tenant from prod on their local computer. So with some de-obfuscation at least some of the data is plausibly retrievable. Whether that data is also public depends on how the negotiations go.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#299
post #220

Earlier quoted context omitted.

> Not much overlap between students and HN these days, though? That's my biggest fear.

Is there any internal data on where students are going instead?

Not much, but I do ask the youngest founders what their friends read if they don't read HN, and the only consistent answer I hear is Twitter.

(and btw, they do say "twitter")

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#300
post #212

Earlier quoted context omitted.

Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.

DKIM signature could be used to verify that Canvas' server sent the email with the given content

And who exactly do you think is going to verify 100s of thousands of emails this way dude?
Post reply on HN