Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

401–410 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#401
post #397

Earlier quoted context omitted.

> Where will they be qualified to work? Going by a certain story 2 years ago, their concern should be that they're overqualified for Meta. It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers. So you can't really just put a filter that drags all the 100 low-priority alerts in what would count as a first degree abstraction o…

I partially solve this by using Thunderbird on my laptop. When I get emails on my smartphone (on the Gmail app), they unfortunately all go to the inbox. But the moment I open Thunderbird, it nicely organizes them for me.

I use Thunderbird on both the desktop and Android. Love it.

Perhaps Outlook is difficult to configure. Thunderbird is intuitive.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#402

Earlier quoted context omitted.

Homegrown systems are expensive to maintain and usually still fail to match up to the commercial options available at this point. LMS's are also just really complicated pieces of software. I worked on my university's own version as an undergrad.

> LMS's are also just really complicated pieces of software it's MIT.

Computer science != software engineering.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#403

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

[dead]

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#404

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

Or maybe it should be mandatory for all companies to pay ransomware attackers. Think of it as an involuntary bounty program. Now they get to just say 'sorry (for your hurt feelings)' and suffer no consequences.

Apart from the 4% of the total worldwide annual turnover fine that theoretically could be levied under GDPR, but has never been imposed in full.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#405

Earlier quoted context omitted.

I don't think that criminal negligence is the most helpful legal tool for incentivizing improved security. It's too hard to prove negligence. Instead, there should be standard civil penalties for leaking various degrees of PII paid as restitution to the affected individual. Importantly, this must be applied REGARDLESS of "certification" or whether any security practices were "incorrect" or "insufficient". Even if the…

I feel like there’s a tendency here to seriously overestimate how damaging these leaks are to individuals. For most individuals impacted by these hacks, appropriate restitution would be $0. Anything more than that would go beyond making them whole.

It's not a popular opinion but I agree. I live in a country that has a very extensive principle of public records, and often times these leaks disclose much less than you would get by simply calling the authorities and ask. Now, whether that's good or bad is a different story.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#406

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

One of those eye opening moments for me was learning about how these criminals work on trust. They need to be trusted to not release the data or to unencrypt when paid, and by and large they do.

One way to weaken any group that works on trust would be to make them less trustworthy. That way victims wouldn't be as confident paying the criminals and thereby making the effort by the criminals less attractive.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#407

Earlier quoted context omitted.

If a CS graduate can't figure out some simple gmail labels and filters then they should not be awarded that degree. Plain and simple. It's not rocket science.

And there are no other students at any college other than CS students? I'm not sure why a biologist or a literature student would need to be au fait with Google's admittedly fairly unfriendly email management setup.

Digital literacy is important to every field. Email filters are not some arcane computer science concept, they are the modern equivalent of filing physical mail into the right folder/pidgeon hole/inbox/whatever.

Biology is a great example because of just how important digital record management is to experimentation in the field.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#408

Earlier quoted context omitted.

> setting this up is well beyond the capabilities of most students. Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?

> Where will they be qualified to work? Going by a certain story 2 years ago, their concern should be that they're overqualified for Meta. It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers. So you can't really just put a filter that drags all the 100 low-priority alerts in what would count as a first degree abstraction o…

> It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers.

While true, unless I'm mistaken, markers (I assume you're referring to tags) can be nested to provide a pseudo-folder hierarchy, and with proper filters you can remove the "inbox" tag and have the mail only show up under the specific tag.

TBH I don't fully mind it, it lets you classify an email in multiple ways (eg "See Later" as well as "Work related").

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#409
post #113

Earlier quoted context omitted.

When will countries start treating cyberattacks as an act of war? If the North Korean military came to America and robbed fort Knox of $200M in gold there would be retribution. But hack an American company for the same amount and the feds do nothing.

Ok, so we treat it as an act of war. Now what? Attack North Korea? Great, the entire city of Seoul gets shelled within five minutes of your attack and hundreds of thousands of innocent people die. It's very easy to play with lives that aren't yours.

Never retaliating is a great way to get people to attack you. Of course escalating to all-out war provokes the same in response, but there does need to be a proportionate response, because it needs to be stupid to hurt us, not good business. t’s a significant failure of the US government when half the world freely loots US citizens and businesses.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#410
post #399
post #383

Earlier quoted context omitted.

Just to add one more data point, we also use Canvas at my university. The deadline for submitting who are eligible (i.e. passed compulsory assignments and labs) to take the exam was yesterday, and I couldn’t meet that deadline because Canvas went down. I usually do corrections offline so I have backups of my own evaluations, but these are courses with many teachers and many TAs, so Canvas is the way we sync our asses…

I guess what surprises me the most is that it’s even legal for schools to outsource the core of what they do to some random tech company. Either way, they were under no obligation to adopt this garbage technology regardless of whether it’s available, so this is 110% on them.

The alternative would be that each school develop their own platform for this, which also isn't very good use of their time and money?

Edit: No idea why this was down voted so much. I'm not defending Canvas, just wondering what the alternative would be.

Post reply on HN