Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

571–580 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#571

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

I think you're 100000% correct.

These problems will continue as long as it is legal to operate in an unsafe way.

We've learned this in every other industry, but we can't seem to accept it in software. One of my hopes for AI is that it reduces the cost to behave responsibly to a level where this absurd resistance to acting responsibly erodes.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#572

So many universities used to run homegrown or on-prem student systems. This is the downside of consolidating in the cloud. If the infrastructure is compromised, it affects everyone, not just isolated or single installations. I wonder how they are feeling about that decision now? I guess they can say "not our fault" so they might be feeling better than if it was a vulnerability in their own system.

Running on prem or homegrown systems used to be considered a core competency of having a computer science department and a campus-wide IT/networking staff at a university. In the environment that exists today in academia, for instance, BSD would never be created because somebody could just pay a third party external vendor for some packaged product. What happened in the past 20 years to change that? I really wonder.

But you don't extend that same argument for an agricultural research department by asking them to have a homegrown farm for supplying the university with food!

I dont think a competent CS department requires their being a homegrown or on-prem system for use in the university. That could happen, but if resources could be better spent by purchasing rather than building, then that should be the correct choice.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#573

Earlier quoted context omitted.

...then all those clicks juice engagement and utilization numbers; why would someone want to just know their grade when they can use more clicks and custom apps to get the same info? The party line is probably something about "a lack of data security" with email, which would almost be funny given the current situation if it wasn't so stressful for those impacted...

No, students are already forced to use Canvas enough as is. This is enterprise software, it's not a consumer phone app. This is nothing to do with "engagement". This is to do with FERPA which requires that student grades be kept private. There is a small but still a significant legal risk that someone else such as a parent or roommate could have access to a student's email. And so to avoid even the possibility of a c…

FERPA allows emailing confidential information to a student email on record if the university controls the email account. Most universities offer their own email service (and require using it) for this exact reason.

There is no more risk of access to email than there is to Canvas. They are usually secured by the same SSO, too.

However, congratulations for finding the exact dodge around implementing a useful feature. Back when I worked at a university, it was apparent we had a “toolbox” of reasons to deny requests we didn’t want to do: HIPAA, FERPA, ERISA, PCI, GLBA, Title IX, ADA.

“We can’t do that integration with student health services due to HIPAA concerns.”

“We can’t implement that sign up form due to FERPA.”

“We can’t update that site because we’d have to do so and be ADA compliant and that would cost too much.”

“Due to Dining Services’ server being in scope for PCI, we can’t run reports off of it.”

“Adding that ability to Student Affairs’ portfolio app would raise Title IX concerns.”

It was great. You had endless excuses to say why you can’t email a student their grade.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#574
post #534

Earlier quoted context omitted.

you're at the other end of the spectrum; unless you get work in academia this is not an advantange.

I use it to filter recruiters, if they can’t accept (a well typeset) PDF résumé, and insist on Word I know to skip them.

They only ask for Word because they plan to edit it to remove your contact info. Or worse.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#575
For a more technical write up https://www.dataminr.com/resources/intel-brief/shinyhunters-...

I'm a software dev who was affected by the outage. I was working on an app that connects to the Canvas SAML endpoints. One minute I was able to run my code, the next I couldn't. This was a little after 17:00 EST.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#576

I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, witho…

[flagged]

It's like the situation with HIPAA rules in electronic health records: It wouldn't be impossible to write your own EHR system but if you do you have to spend a lot of money proving it meets HIPAA regulations or accept substantial liability. So companies just pay Epic $$$ because they promise HIPAA compliance.

Likewise with classroom software if you just use the "industry standard" enterprise crapware you've outsourced the accessibility liability to somebody else. If the software is hot garbage from a usability perspective, that's irrelevant.

And this is why we cannot have nice things in the enterprise space.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#577

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

Think they will end paying the ransom quietly.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#578
post #93
post #74

Earlier quoted context omitted.

Universities used to do this sort of stuff themselves. Then it became a business handled by purchasing rather than needs met by the department themselves.

Because faculty didn’t want to do it anymore. They want it handled by others but also they want oversight and veto power but also they don’t want to be bothered. But it better always work, and if they make a mistake the software is broken because don’t tell them it’s a user error they used to write Fortran. As a faculty member at a large university…I have a deep respect for the impossible job of university IT departm…

This is a lot of it.

I used to work in academia and am now an LMS admin (in private industry). I've interviewed for LMS admin positions at educational institutions and each time I've ended up walking away. The questions I was asked at the last interview revealed what a ridiculously unplanned, spiraling mess their system was and that I would have no agency over it. No, thanks. And it was clear the reason for this was faculty recalcitrance and an inability to tell them no. Each one wanted a special plugin/special way of doing things, causing a giant mess of insecure bloat, and a fair amount of interview questions always amount to 'how do you wheedle faculty into doing things/placate their egos to keep things running?'

I'm not a rockstar candidate either: I'm a disabled, geographically-constrained, self-taught(ish) sort-of techie. The disability means I have substantial holes in my resume/work history, etc. I don't have a CS degree or any kind of formal IT education. If people at my level of knowledge are looking at these jobs and passing because they're not worth it, I can't imagine the actual pool of people who get hired is great.

LMS admins in particular are going to be harder to find/retain because we tend to have options we can jump to that would be less onerous than doing LMS admin for a dumpster fire. I could go straight IT or full Instructional Design, for example.

In private industry, I can tell people to kick rocks if they want to do something that the system doesn't support/is a really bad idea. And if I can't, I'm not held responsible for the consequences.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#579

Earlier quoted context omitted.

What? What makes Canvas accessible in a way that HTML and PDF files are not? It's true that PDF readers aren't the best for screenreaders, but surely you can just upload a .html copy as well.

Why does everything have to be 100% accessible? I'm a prof. When I have a student with special needs in my class, the administration tells me ahead of time. I make the necessary allowances - and those differ from case to case, anyway: whether it's extra time in exams, or someone who is deaf, or someone who is blind, or whatever. When it happens, I make the necessary allowances. When I don't, then...I don't. The obses…

Universalizing statements like "100% accessible" are usually bad ideas. In this case, it's driven not by administrators but the Department of Justice, which is rulemaking accessibility via consent decrees. I think a lot of people miss that and just blame the administrators. Rulemaking is a long process, and the rules being made are stuck in a time before AI could reliably read a book to a blind person: the rules shift the onus onto the content creators, when we've created a whole new ecosystem of ways to eliminate the onus. The DOJ should probably step back and stop trying to regulate this, because the market has already solved it.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#580

Earlier quoted context omitted.

No, students are already forced to use Canvas enough as is. This is enterprise software, it's not a consumer phone app. This is nothing to do with "engagement". This is to do with FERPA which requires that student grades be kept private. There is a small but still a significant legal risk that someone else such as a parent or roommate could have access to a student's email. And so to avoid even the possibility of a c…

FERPA allows emailing confidential information to a student email on record if the university controls the email account. Most universities offer their own email service (and require using it) for this exact reason. There is no more risk of access to email than there is to Canvas. They are usually secured by the same SSO, too. However, congratulations for finding the exact dodge around implementing a useful feature.…

I already said it's not about common sense, it's about legal risk.

It's about edge cases like someone set up your email to forward all your emails to their account without you knowing. Or other additional situations you could imagine.

There is no benefit to not emailing grades directly, from the perspective of Instructure. There is no ulterior motive here. But universities are genuinely risk-averse and their lawyers tell them that not including the grade in the email simply shuts down one more avenue for some potential lawsuit. Which costs money to defend even if a university wins it.

This isn't some kind of "dodge". This is literally just Instructure doing what university lawyers demand.

I agree with you that the email address is generally always also controlled by the school and has the same login authentication. It doesn't matter. I told you this isn't about common sense. This is about lawyers saying that it could reduce legal risk. And that is a true thing that is coming from real lawyers. Even if you disagree with those lawyers.

And Instructure isn't going to try to disagree with lawyers for its own potential customers. It's going to give the schools what they want, which is not revealing grades via email.

It's not a "dodge."

Post reply on HN