Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

441–450 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#441

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

I don't understand what's the panic and doomerism about. Any competent IT team has backups and will be up and running as they go back to a state before the breach. This is HN. I'm disappointed that everyone is talking about losing grades and going back to pen and paper. I don't see how that could happen in 2026. And from the hacker's message itself, it's clear they want money in exchange for not releasing private inf…

I fully agree. What really pisses me off is that these "hacker" groups always spout off how they are doing it to screw the man but then threaten the average person. Millions of them. It just goes to show how uneducated, low-class, and simple these people really are.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#442

Earlier quoted context omitted.

> Where will they be qualified to work? Going by a certain story 2 years ago, their concern should be that they're overqualified for Meta. It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers. So you can't really just put a filter that drags all the 100 low-priority alerts in what would count as a first degree abstraction o…

> It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers. While true, unless I'm mistaken, markers (I assume you're referring to tags) can be nested to provide a pseudo-folder hierarchy, and with proper filters you can remove the "inbox" tag and have the mail only show up under the specific tag. TBH I don't fully mind it, it…

People in my work and personal life experience do not understand the concept of labels in a Google inbox and misname them folders 100% of the time. Google allows you to drag-n-drop emails "into" labels like you would files in folders conflating the issue even more as the logic to automate this behaviour with a filter isn't leveraged. Even the layout of a default inbox is setup in a way that the average user has difficulty understanding what happens when an email drops off the "front page" of their inbox.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#443
post #405

Earlier quoted context omitted.

I feel like there’s a tendency here to seriously overestimate how damaging these leaks are to individuals. For most individuals impacted by these hacks, appropriate restitution would be $0. Anything more than that would go beyond making them whole.

It's not a popular opinion but I agree. I live in a country that has a very extensive principle of public records, and often times these leaks disclose much less than you would get by simply calling the authorities and ask. Now, whether that's good or bad is a different story.

We use to hand out whole books of this information to as many people as possible. (phone books)

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#444

Earlier quoted context omitted.

Former Instructure engineer here. Ive been gone almost 10 years at this point, but some of the best engineers I've ever worked with were at INST. I'm not sure where your stereotype even comes from, because Canvas is not trivial software. You can see for yourself as it's AGPL and I assume you looked at the code before criticizing it because any good engineer would do that.

I've been using Canvas for years and it's some of the worst written software I've ever used. It's slow, buggy, with an atrocious 2001-era UI. It's a CRUD app that has no excuse for being so cumbersome. I'm not surprised at all that their security is just as bad as the rest of the product. A bright undergrad could build a superior replacement in a few months, even without AI.

I won't disagree on usability. It has some sharp edges for sure. But

> A bright undergrad could build a superior replacement in a few months, even without AI.

Is quite naive. Canvas is not at all just a crud app. You can view the code yourself as it's AGPL

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#445

Earlier quoted context omitted.

> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)

I've never used Canvas before, but all the LMSes that I've used allow students to enable emails whenever anything is updated, including when grades are posted. This is off by default because it's often 10+ emails a day, because many teachers post notes once a day, and with 5 classes, that adds up pretty quick. I personally have it enabled because it's pretty manageable with some custom Outlook rules, but setting this…

Canvas will send emails when grades are posted, but not what the grade is. Or at least that’s the way in the configurations I’ve seen. So, that wouldn’t help in a case where no one can access the canvas gradebook.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#446

Earlier quoted context omitted.

The alternative would be that each school develop their own platform for this, which also isn't very good use of their time and money? Edit: No idea why this was down voted so much. I'm not defending Canvas, just wondering what the alternative would be.

The alternative is FOSS.

If your line is GPL rather than AGPL there's Moodle.

But you do then have to have a sysadmin capable of managing an enterprise grade LAMP stack.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#447

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

> “My gut feeling on this is that this is either resolved in hours (they have airgapped backups and can be working as soon as they can spin up new servers)

What good is having airgapped backups and spinning them up, if they are instantly vulnerable to the same attack again?

It does depend on what the attack is, but how do people approach that scenario?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#448
post #430

Earlier quoted context omitted.

I think you completely misread my comment.

I understood your comment perfectly fine. I'm asking which graduates of which colleges you were referring to. It looked like you were generalizing about US HS and colleges. If so, plenty of other countries' HS and college education systems work better, so your comment doesn't extend.

I didn't even reply to you.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#449

Earlier quoted context omitted.

That's just bad outdated practice. It leads to cramming and less remembering than of the demand is for students to do work and show learning and effort throughout the year.

It has been my observation that most of the better students were the ones who would not put in work during the semester/year and cram at the end.

[deleted]

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#450
Hundreds of 1,000s of students affected by this hack in Australia ( and no doubt other countries around the world ...) Its more than the 10,000s Australian students mentioned in article below ...

https://www.abc.net.au/news/2026-05-08/students-lose-access-...

Post reply on HN