A friend who teaches at MIT said they were hit by this. I found it ironic and a little sad that a place like MIT doesn't have an IT staff that can maintain their own on-prem solutions for things like this. But it turns out that MIT used to have their own homegrown system, and recently switched to Canvas. Bet they're regretting that now. The build vs. buy decision seems to have swung very hard toward buy in the last d…
Canvas online again as ShinyHunters threatens to leak schools’ data
511–520 of 690 posts
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#512Earlier quoted context omitted.
Lot of experience dealing with Canvas/Instructure. Tech is o-k. Culture seems to be full of themselves due to market position.
Yeah like their page says "Scheduled Maintenance" which is total B.S. Talking to people at my university's IT side of things Canvas has said nothing to any clients.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#513Canvas is handling this terrible. No communication, no status updates, etc. Also looks pretty bad their whole platform was compromised and not a single real report for the breach that already had happened. Wonder how long it will take for SLA violations and lawsuits to manifest, especially with most U.S. schooling having finals right now.
Also looks pretty bad their whole platform was compromised by the same hacker group again.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#514Earlier quoted context omitted.
I don't understand what's the panic and doomerism about. Any competent IT team has backups and will be up and running as they go back to a state before the breach. This is HN. I'm disappointed that everyone is talking about losing grades and going back to pen and paper. I don't see how that could happen in 2026. And from the hacker's message itself, it's clear they want money in exchange for not releasing private inf…
I'm sure you're right. Across tens (hundreds?) of thousands of institutions worldwide, each one is exercising its well-written incident runbook that not only gets updated regularly but also is rehearsed constantly, just in case something like this happens. After all, what university IT department DOESN'T prepare obsessively for the moment when they need to restore all grades on all assignments for all courses from ba…
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#515I believe FERPA's PII provisions apply to Canvas and contractors handing PII in general (at least as interpreted by the Department of Education). Now, will Canvas be held accountable by ED in this administration? Hah – DOGE probably ran that through the shredder as well.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#516Earlier quoted context omitted.
> setting this up is well beyond the capabilities of most students. Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?
I'd hope/assume that any Computer Science students would be able to do this, but most Biology/Education/English/Art students probably couldn't. I mean, anyone smart enough to attend university could probably figure it out if they really wanted to, but there are hundreds of other useful things that they could learn too. There are only so many hours in the day, and given that most students don't get that many emails, I…
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#517I'll be shocked if Canvas ever gets held publicly accountable for this. I believe FERPA's PII provisions apply to Canvas and contractors handing PII in general (at least as interpreted by the Department of Education). Now, will Canvas be held accountable by ED in this administration? Hah – DOGE probably ran that through the shredder as well.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#518Earlier quoted context omitted.
It’s wild to me that people in this comment section are suggesting that schools should improve their security by rolling their own platform, which is bound to be filled with security holes, instead of using a popular, maintained, open source option.
To be fair to the idea, though, while this would make individual instances less secure, it would drastically decrease the leverage for the work bad actors put in. There is a saying in the software security industry that (I'm paraphrasing from rusty memories) a system is secure if the cost of hacking it is higher than the value it protects. Each system being completely distinct from another means that the cost of hack…
But also, the cost is much, much higher to the institutions, which is the salient point. You're going to spend years developing a system, deploying it, training staff and students, supporting it. I see mentions here of in-house systems being developed much more cheaply and I don't believe it. The economies of scale are at work.
I worked at a university for many years and I can't recall anyone I'd consider to be a competent software architect working for the IT department. Hell, we had students writing major webapps that kinda sorta worked well enough.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#519Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#520Earlier quoted context omitted.
Universities are not going to write their own software, and no they can’t use ‘agents’ to write and maintain it for them either.
It's somewhat ironic... if a University's CS department was charged with developing and maintaining the system, what an awesome learning tool it would be. CS students would maybe even be invested in the outcome by having to eat their own dogfood and then really appreciate it what it's like in the real world.