Earlier quoted context omitted.
This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…
Famously summarized by Kipling https://www.kiplingsociety.co.uk/poem/poems_danegeld.htm
Instructure pays ransom to Canvas hackers
101–110 of 257 posts
Re: Instructure pays ransom to Canvas hackers
#102Earlier quoted context omitted.
There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.
Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.
Yikes.
Re: Instructure pays ransom to Canvas hackers
#103Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
Re: Instructure pays ransom to Canvas hackers
#104on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…
If we assume a world where ransomware is continually existent and all your data is ransomed at anytime, we'd have a world designed to work around that. We'd either end up with a Discworld "Ransomware Guild" that you pay "insurance" to and they murdicate anyone who dares do extracurricular data ransoming, or you'd have systems build on end-to-end encryption where the data is worthless.
Re: Instructure pays ransom to Canvas hackers
#105> We received digital confirmation of data destruction (shred logs). This is shockingly naive
Re: Instructure pays ransom to Canvas hackers
#106Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
Thank goodness that no kidnapping of an American has ever happened since.
Re: Instructure pays ransom to Canvas hackers
#107Earlier quoted context omitted.
It is illegal to pay terrorists. As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If they did, would they be able to send in SEAL Team 6 to handle the hackers?
> As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If you’re sending a large sum of money to $anonymoushacker, how do you ensure they’re not on some OFAC list? Or do your AML checks? Or make sure you’re not on the wrong side of Foreign Corrupt Practices act? The third party probably turns a blind eye to that cuz there’s no way of really check…
Re: Instructure pays ransom to Canvas hackers
#108Re: Instructure pays ransom to Canvas hackers
#109Being that this is HN, do we know how they got hacked? Can we learn something about protecting our services?
https://www.instructure.com/incident_update
It worries me they've only committed to making it available to their customers and not the public.
Re: Instructure pays ransom to Canvas hackers
#110Earlier quoted context omitted.
So they hacker group could create an unregistered subsidiary and hack some more?
They could but also why would they? They can always just hack them again but with a different method this time. The ransom doesn't bind them from hacking the company multiple times. It just obligates them to destroy the data they collected from this attack. As a matter of kindness and good business they'll probably wait a few months or a year or so before poking around again but they'll almost certainly continue poki…