Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

11–20 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#11
post #8
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…

[deleted]

Re: Instructure pays ransom to Canvas hackers

#13

Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?

Simple economic motivations from the hackers. They've hacked a lot of different companies. [1] If they didn't keep their word then companies would have no incentive to pay, and vice versa when they do keep their word.

[1] - https://en.wikipedia.org/wiki/ShinyHunters

Re: Instructure pays ransom to Canvas hackers

#14
post #8
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…

Not only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.

Re: Instructure pays ransom to Canvas hackers

#15

Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?

The same group has a reputation to uphold (i.e., that of 'honourable' criminals), so they just move on to the next target, who will, incidentally, know that they are absolutely true to their word. (This is why paying off ransomware hackers is being made illegal in a number of countries.)

A different group? Certainly. I wouldn't want to be in the shoes of the infosec guys at Canvas right now.

Re: Instructure pays ransom to Canvas hackers

#16
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

If the bad guys get paid and release the info anyway, they not only make it less likely they'll get paid in the future, they make it less likely anyone will get paid in the future.

Even other bad guys have an incentive to stop these bad guys from leaking the info after getting paid.

Re: Instructure pays ransom to Canvas hackers

#17

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma).

Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom.

This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing the individual victim to not pay, otherwise they will always be incentivized to pay and ransoms will continue to be profitable.

https://en.wikipedia.org/wiki/Collective_action_problem

https://en.wikipedia.org/wiki/Prisoner%27s_dilemma

Re: Instructure pays ransom to Canvas hackers

#18
post #8

Earlier quoted context omitted.

I thought it was illegal to pay ransom to hackers. I guess it is legal or maybe it isn't very clear? I thought that there were certain conditions that the company had to check together with law enforcement so that at least the ransom money doesn't go to a hacker group that is on a government payments sanctions list. Also, does anyone know the root cause of the attack? I read a rumor online (but it's not really confir…

Not only is it not illegal, there are insurance policies set up to take care of this very scenario. It's almost always handled by a third party, not the company themselves, that would deal with any such concerns.

It is illegal to pay terrorists. As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If they did, would they be able to send in SEAL Team 6 to handle the hackers?

Re: Instructure pays ransom to Canvas hackers

#19

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

If we assume a world where ransomware is continually existent and all your data is ransomed at anytime, we'd have a world designed to work around that.

We'd either end up with a Discworld "Ransomware Guild" that you pay "insurance" to and they murdicate anyone who dares do extracurricular data ransoming, or you'd have systems build on end-to-end encryption where the data is worthless.

Post reply on HN