Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

361–370 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#361

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

People who haven’t been hacked just haven’t been looked at. If someone wants to hack you, they will hack you. It’s really unfortunate that people have this level of confidence in their ability.

Here’s an example. https://hacks.mozilla.org/2026/05/behind-the-scenes-hardenin...

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#362

Earlier quoted context omitted.

Homegrown systems are expensive to maintain and usually still fail to match up to the commercial options available at this point. LMS's are also just really complicated pieces of software. I worked on my university's own version as an undergrad.

> LMS's are also just really complicated pieces of software it's MIT.

But it’s not like MIT gains anything from rolling their own LMS.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#363

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

Shouldn’t we be focusing on making it harder to pay overseas criminals in the first place? /ahem/ crypto platforms facilitating transfers to bad actors /ahem/

Criminals should focus on proven methods, like Steam Gift cards.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#364

At the same time, Aussie tech giant pauses work, devotes entire week to AI Design software giant Canva has halted normal operations across its 5300-strong global workforce for five days of nothing but AI learning and hackathons, bucking the global wave of technology giants that have slashed jobs, citing the technology. https://www.smh.com.au/technology/aussie-tech-giant-pauses-w...

Canvas is not Canva. Is this a bot reply

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#365

Earlier quoted context omitted.

It’s wild to me that people in this comment section are suggesting that schools should improve their security by rolling their own platform, which is bound to be filled with security holes, instead of using a popular, maintained, open source option.

Maybe. I still remember the Drupal community sneering at the New York Times when they unveiled their homegrown online news platform bitd. After 15 years of recursively scraping ad-hoc porn sites off of server hard drives when clients dragged their feet on migrating to latest versions I 'm less certain the assumption that homegrown == less secure is as valid as it sounds.

Could you explain the last sentence a bit more? I don’t follow

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#366

Earlier quoted context omitted.

Is there any internal data on where students are going instead?

You honestly don't wanna know If my peers are any indication, a whole lot of TikTok, Reels, Twitter, Discord, and other such mind-numbing platforms. The types of platforms I would consider 'substantive' (or, at least, more substantive than those platforms) are definitely on the way out. The few times friends have seen me browsing Hacker News or a certain Mongolian basket weaving form, the first thing they comment on…

Discord is just chat, I wouldn't call it mind-numbing, reminds me perfectly of IRC from a utility perspective.

That said, it's a commercial closed-source single point of failure.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#367

Earlier quoted context omitted.

I've never used Canvas before, but all the LMSes that I've used allow students to enable emails whenever anything is updated, including when grades are posted. This is off by default because it's often 10+ emails a day, because many teachers post notes once a day, and with 5 classes, that adds up pretty quick. I personally have it enabled because it's pretty manageable with some custom Outlook rules, but setting this…

> setting this up is well beyond the capabilities of most students. Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?

> What are they learning?

Exactly what is in their field of study, nothing more. That's a huge part of the problems created by treating academia as a degree mill mandatory to get a job able to feed yourself instead of a place only for those truly interested in actually studying a subject.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#368

Earlier quoted context omitted.

I've never used Canvas before, but all the LMSes that I've used allow students to enable emails whenever anything is updated, including when grades are posted. This is off by default because it's often 10+ emails a day, because many teachers post notes once a day, and with 5 classes, that adds up pretty quick. I personally have it enabled because it's pretty manageable with some custom Outlook rules, but setting this…

> setting this up is well beyond the capabilities of most students. Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?

Most people who have office jobs don't know how to do this either

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#369

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

I don't understand what's the panic and doomerism about. Any competent IT team has backups and will be up and running as they go back to a state before the breach. This is HN. I'm disappointed that everyone is talking about losing grades and going back to pen and paper. I don't see how that could happen in 2026. And from the hacker's message itself, it's clear they want money in exchange for not releasing private inf…

> Any competent IT team has backups

Backups can be sabotaged (turned off or schedules manipulated) or compromised (say, by lateral movement).

> Even if everything was hosted on Instructure's infrastructure, it's all AWS.

AWS Backup isn't foolproof. Get your hands on administrator credentials as an attacker and suddenly the only thing between everything being gone for good and unrecoverable even for AWS is remembering to have put a permanent deletion protection on all resources in AWS Backup.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#370

Earlier quoted context omitted.

I've never used Canvas before, but all the LMSes that I've used allow students to enable emails whenever anything is updated, including when grades are posted. This is off by default because it's often 10+ emails a day, because many teachers post notes once a day, and with 5 classes, that adds up pretty quick. I personally have it enabled because it's pretty manageable with some custom Outlook rules, but setting this…

> setting this up is well beyond the capabilities of most students. Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?

> Where will they be qualified to work?

Going by a certain story 2 years ago, their concern should be that they're overqualified for Meta.

It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers. So you can't really just put a filter that drags all the 100 low-priority alerts in what would count as a first degree abstraction of "place where things are sorted into". No, there are two layers of abstraction between point A and B of things, sorter and sorted things. The result? Muggles can't recognize the heck you're describing and refuse to even acknowledge the possibility.

Post reply on HN