Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

631–640 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#631

Earlier quoted context omitted.

I already said it's not about common sense, it's about legal risk. It's about edge cases like someone set up your email to forward all your emails to their account without you knowing. Or other additional situations you could imagine. There is no benefit to not emailing grades directly, from the perspective of Instructure. There is no ulterior motive here. But universities are genuinely risk-averse and their lawyers…

Then the lawyers are incompetent morons. There's "no benefit" to telling the student their own grade at all when viewed from that perspective. You could just not give them any feedback. Or you could allow them to consent to it, which is what the law asks. It is a dodge. Society should not just say "oh those silly lawyers". These people are not being responsible. They are not doing their jobs.

As someone who transitioned from working in startups and technology to a university, it is hard to describe how different the environment is.

It looks very weird and is hard to understand from the outside, and unfortunately all technology vendors are on the outside.

Basically every technology has an impedance mismatch when brought into the university environment. And when you combine them together it keeps getting worse.

That's why you see things in this thread like CS professors who operate their class using pen and paper and maybe a spreadsheet.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#632
I tried to become a contributor to Canvas (it's open source), but I couldn't even get a development environment setup because of their storage space requirements.

https://github.com/instructure/canvas-lms/wiki/Quick-Start

> It is recommended that you have at least 150GB of available hard drive space, 8GB of RAM, and a quad-core CPU to use this script.

As far as I can tell, this is not for running a production environment with assets. This is just the development environment.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#633

I tried to become a contributor to Canvas (it's open source), but I couldn't even get a development environment setup because of their storage space requirements. https://github.com/instructure/canvas-lms/wiki/Quick-Start > It is recommended that you have at least 150GB of available hard drive space, 8GB of RAM, and a quad-core CPU to use this script. As far as I can tell, this is not for running a production environ…

I long for the days when FPGA development environments were an order of magnitude more bloated than software development environments. I've tried, on multiple occasions, to build an open-source Android application, and each time I've given up after a few hours of trying to get all the bloat working together well enough to even compile something already written.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#635

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

I don't think there should be an investigation. Data got leaked? That's a fine. Consequences happened? The people who stole it are accountable but so are the people who had the data in the first place. Just don't have the data. There are plenty of companies out there who don't have cyber security incidents despite being huge targets, what are they doing? Insurance is also a thing if companies are that worried about fines or getting sued.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#636

I remember circa 2010 a friend of mine at college was like “blackboard sucks, let’s build something new”. At the time I poo pood the idea and lo and behold canvas came out a year later. Outside looking in, they been crushing it.

I remember my university switched to Moodle around that time. I wonder if they're still popular.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#637
post #601

Earlier quoted context omitted.

FWIW, I'm a student, so there are at least a few still here. Feel free to ask me any questions (either via email or via replies to this post) and I'll try to answer them.

Ok! How many of your smart friends read HN? and of the ones who don't, what do they read instead?

> How many of your smart friends read HN?

I don't think that any of them do, but I'm a Canadian math/physics major, which is slightly outside the target audience for HN.

> of the ones who don't, what do they read instead?

For the social aspect: mostly medium-sized Discord servers. For the news aspect: nothing at all. Both of these do have some advantages, but it's still a bit of a shame, because the Discord servers aren't indexed by Google, so they're hard for outsiders to find, and not reading the news means that they're missing out on some of the cool new tech advances.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#638

Earlier quoted context omitted.

The world is complicated. Laws like FERPA are written with good intentions, but there are a lot of gray areas open to interpretation, and bad actors will take advantage of those gray areas to bring lawsuits for selfish purposes that universities have to spend money to defend themselves and possibly pay expensive penalties over. So lawyers advise how to follow laws in the most risk-free way. Blaming lawyers or Instruc…

It's not a misunderstanding of everything, especially for schools that are government funded. They have a mission, they receive resources from everyone else to do that mission. If they are then worried about penalties for some frivolous side distraction, and choose to not accomplish their mission for fear of that, then why are we funding them to start with ? Frankly it's a perspective that I've only developed as I go…

I really don't know what to tell you. You're literally calling for universities to either break the law or not worry so much about following it, and calling people who do want to be careful about following the law "incompentent and useless".

If you don't see how extreme that is, and how much society would break down if everyone started thinking laws were optional and ought to be ignored when they prevent you from accomplishing your "mission", I just don't know what to tell you.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#639

Earlier quoted context omitted.

FERPA allows emailing confidential information to a student email on record if the university controls the email account. Most universities offer their own email service (and require using it) for this exact reason. There is no more risk of access to email than there is to Canvas. They are usually secured by the same SSO, too. However, congratulations for finding the exact dodge around implementing a useful feature.…

I already said it's not about common sense, it's about legal risk. It's about edge cases like someone set up your email to forward all your emails to their account without you knowing. Or other additional situations you could imagine. There is no benefit to not emailing grades directly, from the perspective of Instructure. There is no ulterior motive here. But universities are genuinely risk-averse and their lawyers…

Have you ever worked in an environment where you were responsible for building systems that complied with FERPA and you worked with your school's general counsel and compliance team on that?

What you are saying about e-mail is simply not factual. Student e-mail is inside the FERPA environment, and is considered private to the student. It was designed to be that way. If a student sets up forwarding to go to someone else, that's their problem. The student e-mail uses the same SSO as the LMS, so it's nonsense to act like someone else could have access to e-mail.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#640

Earlier quoted context omitted.

I already said it's not about common sense, it's about legal risk. It's about edge cases like someone set up your email to forward all your emails to their account without you knowing. Or other additional situations you could imagine. There is no benefit to not emailing grades directly, from the perspective of Instructure. There is no ulterior motive here. But universities are genuinely risk-averse and their lawyers…

Then the lawyers are incompetent morons. There's "no benefit" to telling the student their own grade at all when viewed from that perspective. You could just not give them any feedback. Or you could allow them to consent to it, which is what the law asks. It is a dodge. Society should not just say "oh those silly lawyers". These people are not being responsible. They are not doing their jobs.

I worked with a lawyer who was the on-staff general counsel for a mid size private university who was not an incompetent moron.

One thing I really appreciated that she did was refuse to put e-mail disclaimers in the bottom of e-mails, because she said they had zero legal weight and actually were negative from a legal perspective, since it means people might think they have legal weight (when they don't).

Overzealous e-mail admins would periodically want to do it because it's what everyone else does, not to mention vendors of frankly B.S. software whose only value prop was adding a disclaimer to all the email that went out of Exchange or Google Workspace.

Post reply on HN