Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

71–80 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#71
There shouldn't have been a need to give into hackers, even highly successful hackers. If they're not doing air-gapped backups weekly, that's malpractice and hints at a substandard architecture and/or operations. On a short enough full backup schedule all of Canvas's customers should've been able to recover based on their own copies of assignments and test results. And a policy like that should've been in the SLAs.

In an education environment, there shouldn't be a need to trust software like Canvas for anything mission critical. In fact, if there's anything mission critical in a system like canvas it's an artificial need.

IOW Canvas had to have made themselves vulnerable to a ransom demand in the way that they designed their own product.

Re: Instructure pays ransom to Canvas hackers

#72

Earlier quoted context omitted.

Not only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.

It is illegal to pay terrorists. As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If they did, would they be able to send in SEAL Team 6 to handle the hackers?

A large percentage of hacking groups are state sponsored Russians. That seal response would be starting WW3 over some pii.

Protecting pii is important, but it's not that important

Re: Instructure pays ransom to Canvas hackers

#73

Earlier quoted context omitted.

... except that "policies" don't cut it. Criminal penalties for paying are what you need, and not just for payments to specific designated entities, either. The executive making the decision to pay has to have a real fear of personally spending time in actual prison.

US law has criminal penalties for paying a ransom to a designated criminal terrorist organization or under treasury sanctions.

Most hacking groups don't fall under that. Some, sure.

Re: Instructure pays ransom to Canvas hackers

#74

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

An idea I idly thought about is that of a "Benevolent Terrorist"[0]: one who does great harm to some number of people so that they may make it to a better world. Not entirely original, I suppose, since the Kwisatz Haderach from Dune is the trope definer. But a fun thought I had was what if you ran a ransomware company that just didn't pay? You'd screw a lot of people over but eventually you'd make ransomware a non-business the better you impersonated them and failed to deliver after taking the ransom.

What could go wrong? ;)

0: https://wiki.roshangeorge.dev/w/Benevolent_Terrorist#Poisoni...

Re: Instructure pays ransom to Canvas hackers

#75
post #67

> Has law enforcement been engaged? Yes. We've notified law enforcement, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and international law enforcement partners. Hmm. I thought all these agencies say NOT to pay a ransom.

Engaged != listened to.

Re: Instructure pays ransom to Canvas hackers

#76
post #71

There shouldn't have been a need to give into hackers, even highly successful hackers. If they're not doing air-gapped backups weekly, that's malpractice and hints at a substandard architecture and/or operations. On a short enough full backup schedule all of Canvas's customers should've been able to recover based on their own copies of assignments and test results. And a policy like that should've been in the SLAs. I…

Backups do nothing to protect your customers from getting extorted to avoid their data being leaked.

Re: Instructure pays ransom to Canvas hackers

#77
post #8

Earlier quoted context omitted.

I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…

Not only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.

It often is illegal to pay them. They are often on sanctions lists, or indeed in embargoed countries. And it's just generally not allowed to pay unidentifiable parties for basic anti-money laundering reasons. And a lot of countries are bringing in new legislation to make paying illegal, starting with public sector organisations. I'm sure that will only expand.

Frankly, you pay a ransom at your peril. If it turns out it was North Korea you may well go to jail for it.

Re: Instructure pays ransom to Canvas hackers

#78

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

> I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time.

Reputation is everything in a collective.

Re: Instructure pays ransom to Canvas hackers

#79
post #52
post #39

Earlier quoted context omitted.

> Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. You're then a target known to be vulnerable and pay ransoms, so best focus on security.

If you have to pay, at least try to negotiate 1) a guarantee that the hackers won't just do it again sometime later, and 2) full disclosure / assistance in repairing your vulnerabilities so you have some kind of head start for the future. Outside of politically motivated hackers, this would probably be reasonably successful.

Other hacking groups now know Instructure pays up.

Re: Instructure pays ransom to Canvas hackers

#80
post #64

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

Another way to view this calculation: if you keep your infrastructure secure and up to date, you (very likely) don't have to pay any ransom in the first place.

There is a line where the ransom price beats the capex of keeping a secure system, specially when the risk so nebulous

Kind of like the recall math auto makers do to see if it's more expensive to actually recall a manufacturing problem, or just deal with it and compensate those who seek it personally

Post reply on HN