Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

541–550 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#541

Earlier quoted context omitted.

They have not succeeded in forcing me, yet. But it's sad how many computing faculty apparently can't operate the basic online infrastructure needed to support their courses. Not that universities make it easy for us. And of course the other serious concern I have with Canvas is that they are likely using all the materials faculty upload to train their AI replacements. Many of my colleagues engage in dark humor about…

instructure/canvas-lms is open-source -- is there anything preventing universities from hosting it themselves?

A bunch of plugins running on canvas.instructure.com are proprietary, according to their FAQ: https://github.com/instructure/canvas-lms/wiki/FAQ.

I would guess these plugins are chosen so a majority of user won't want to live without them.

It also seems these plugins "link" to canvas-lms, so keeping the proprietary would be a GPL violation if anyone except Instructure holds part of the copyright to Canvas.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#542
post #525

Earlier quoted context omitted.

Homegrown systems are expensive to maintain and usually still fail to match up to the commercial options available at this point. LMS's are also just really complicated pieces of software. I worked on my university's own version as an undergrad.

The university I went to established has a rule that was essentially "student made software is not permitted to be used." Professors couldn't actually use student made software, the software had to be wrapped up by a "company" and a contract made. This meant that you couldn't just make a tool/utility/whatever and have it be used. I believe the same applied to the professors themselves, although that was hardly enforc…

Sounds like an opportunity for the business school to do a seminar on forming an LLC and writing contracts.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#543

Earlier quoted context omitted.

> LMS's are also just really complicated pieces of software it's MIT.

Maintaining an LMS doesn't seem like a good use of time. You should almost always outsource pieces that aren't your core business.

It's a university. Teaching and learning is their core business.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#544

Earlier quoted context omitted.

This analogy seems to be portraying 'ransomware hackers' as an unstoppable force of nature akin to gravity . I'm not sure that's a fair analogy.

I think it’s a very fair analogy. The _only_ way to stop them is to make your stuff secure. That’s literally the only way.

We do not generally hold victims of crimes accountable for failing to defend themselves adequately.

If someone threatens you with a knife and gets you to hand over your wallet, your bank doesn’t get to say ‘you should have hired better security’ when the mugger uses your credit card.

The problem here is the mugger, and that’s who the state goes after. Even if the victim walked into a bad area. Even if the victim could have defended themselves.

Same with ransomware attackers. They are the problem. We might encourage potential victims to behave in ways that make it less likely for them to be targeted. But if they are targeted, we should still focus our societal disdain on the criminal not the victim.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#545

Earlier quoted context omitted.

This analogy seems to be portraying 'ransomware hackers' as an unstoppable force of nature akin to gravity . I'm not sure that's a fair analogy.

Your analogy portrays gravity as a thing that buildings cannot be built to withstand. There are plenty of structurally sound buildings and while there are plenty of secure apps the problem is there’s no incentive to build the latter.

On the contrary.

My analogy would be: of course buildings have to be built to withstand gravity. That’s a natural part of the world that cannot be eliminated.

Buildings are built to stand up to natural forces. But not to, for example, the threat of a malicious actor crashing a plane into them. That isn’t typically considered a reasonable thing to architect civilian infrastructure for.

When you built IT infrastructure likewise you should build it to handle the natural forces it will be exposed to. But are you as accountable for securing it against the acts of malicious parties as a structural engineer is for securing a building against gravity, or as accountable for securing against those acts as the structural engineer is for securing that building against terrorists?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#548

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

Canvas is back up as of Friday US morning for me (HS student's parent). My kid got a few panicked emails yesterday from the teachers but it looks like Instructure got it resolved quickly.

Canvas does provide a lot of value (all courses, teachers', students', and parents' contact information, all learning plans, schedules, room numbers, all grades, a lot of tests and assignments themselves, all upcoming assignments and deadlines, a lot of other coursework is in there, as are the final grades) but it shows that with external SaaS you might be one attack away from not only losing all that convenience but also in a world of hurt 'cause you lost all the data and now have to figure out how to proceed without the data and the system.

US high schools are in the middle of the finals, and seniors are getting ready for college (the transcripts to be finalized and sent out in a few weeks) so that was a scary timing.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#549
post #505

Earlier quoted context omitted.

Most graduates aren't really qualified to work anywhere that they couldn't have worked before going to college in the first place.

I used LaTeX as a ugrad, it’s not that hard

It's not even standard in academia.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#550

Earlier quoted context omitted.

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

Has a corporate officer ever gone to jail or been meaningfully fined for a data breach?

Yes, many times.
Post reply on HN