Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

351–360 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#351
post #243

I'm a student at Stanford — this is hitting the whole school hard. Unlike a lot of schools on the east coast that are affected (Brown, Harvard, MIT) we are on the quarter system so we're just ending Midterms right now. We're also lucky enough to have our CS department entirely independent from Canvas, but most of my humanities classes are not so lucky. One art history class is having us submit our midterm papers by u…

And what's your opinion on the em dash?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#352

So many universities used to run homegrown or on-prem student systems. This is the downside of consolidating in the cloud. If the infrastructure is compromised, it affects everyone, not just isolated or single installations. I wonder how they are feeling about that decision now? I guess they can say "not our fault" so they might be feeling better than if it was a vulnerability in their own system.

Is there a good self-hostable FOSS version of Canvas/Blackboard?

Canvas is open-source and can be self-hosted.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#353

Earlier quoted context omitted.

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

I don't think that criminal negligence is the most helpful legal tool for incentivizing improved security. It's too hard to prove negligence. Instead, there should be standard civil penalties for leaking various degrees of PII paid as restitution to the affected individual. Importantly, this must be applied REGARDLESS of "certification" or whether any security practices were "incorrect" or "insufficient". Even if the…

And this strict liability will come with an expectation of insurance. The insurance policies will necessitate audits, which will actually improve security.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#354

I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, witho…

[flagged]

Not GP, Incompetent policy makers are the bad thing.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#355
post #141

A friend who teaches at MIT said they were hit by this. I found it ironic and a little sad that a place like MIT doesn't have an IT staff that can maintain their own on-prem solutions for things like this. But it turns out that MIT used to have their own homegrown system, and recently switched to Canvas. Bet they're regretting that now. The build vs. buy decision seems to have swung very hard toward buy in the last d…

Homegrown systems are expensive to maintain and usually still fail to match up to the commercial options available at this point. LMS's are also just really complicated pieces of software. I worked on my university's own version as an undergrad.

> LMS's are also just really complicated pieces of software

it's MIT.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#356

https://status.instructure.com/ implies Canvas became available again about thirty minutes ago from the time of this post. Is this accurate? Or is this still an ongoing issue?

Federated logins appear to now be broken for the campus I’m affiliated with. So more action is needed.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#357

Earlier quoted context omitted.

I've never used Canvas before, but all the LMSes that I've used allow students to enable emails whenever anything is updated, including when grades are posted. This is off by default because it's often 10+ emails a day, because many teachers post notes once a day, and with 5 classes, that adds up pretty quick. I personally have it enabled because it's pretty manageable with some custom Outlook rules, but setting this…

> setting this up is well beyond the capabilities of most students. Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?

I have been using email for as long as email was a thing and I still managed to blackhole important emails with filters not too long ago.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#359
post #228

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

> let classes that normally count for a grade just submit grades as pass-fail. Because what else can you do? Schedule a single exam and that's your grade for that subject? That's how it should work anyway, credits for work during semester (or worse attendance) are not needed to evaluate if someone learned the material, give them an exam and done.

Then you're testing how good someone is at exams as much as anything

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#360

Earlier quoted context omitted.

> they have airgapped backups and can be working as soon as they can spin up new servers ... and assuming they have a documented, tested, and trusted restore process.

Reminds me of the incident last year when a South Korean government's server room caught fire, which contained the government equivalent of Google Drive, and the only backup was in the same room , and they all burnt down together. Some data was permanently lost, and then officers told reporters that multi-regional backup was not yet built because it was too hard at such a massive scale... of 858 TB.

> it was too hard at such a massive scale... of 858 TB

There are probably many S3 buckets in existence that are bigger than that.

Not saying that they should've used S3, but it's definitely possible configure multi-regional backup (and a government can afford it).

Post reply on HN