Earlier quoted context omitted.
There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.
Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.
Instructure pays ransom to Canvas hackers
111–120 of 257 posts
Re: Instructure pays ransom to Canvas hackers
#112Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime.
and the executives who failed to carry regular backups obviously should face the music
Re: Instructure pays ransom to Canvas hackers
#113Earlier quoted context omitted.
Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.
I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.
Re: Instructure pays ransom to Canvas hackers
#114I wonder if, longer term, we're better off if a company like this were in some way destroyed as a result of getting hacked and paying a bribe. I think the stakes for getting hacked are far too low, especially at higher levels of management/executive where it's this abstract thing that has concrete time/resource costs.
Customers never migrate on mass after a breach, 7000 underfunded and overworked education institutions are not migrating on mass.
So I feel safe to say there's no lasting impact to a company when a data breach occurs.
This will all be forgotten in a few months.
Re: Instructure pays ransom to Canvas hackers
#115I would love to know the amount of ransoms paid by large companies who've been compromised without the public being informed. How much that undisclosed amount impacts inflation and the economy today is not talked about nearly enough, imo.
Re: Instructure pays ransom to Canvas hackers
#116Earlier quoted context omitted.
There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.
> For the ransom group, it is better for them to be perceived as trustworthy. They've already proved themselves to be untrustworthy simply by ransoming you in the first place.
Re: Instructure pays ransom to Canvas hackers
#117Earlier quoted context omitted.
I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.
> I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. It is very meaningful. You seem to equate that "new" = "trust by default", but a new group is distrusted by default. Let's say that for a new group which is unproven t…
This is the same problem that crypto addresses in an unregulated market - it provides attestation and continuity, but not much else.
New actors are untrusted. Trust must be built through small transactions until someone trusts you enough for larger transactions. Survive long enough without major reputational harm and you can even offer to act as an escrow service for parties with less trust.
Re: Instructure pays ransom to Canvas hackers
#118Earlier quoted context omitted.
I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.
Wow. A lot of K-12 students probably don't even know their own SSN off the top of their head, much less understand the impact of having it stored in this way. I can't fathom why it would be necessary for the SSN to be tracked by the school. At most, the school district as a whole might want a record so they could make sure kids are getting schooled but putting that into Canvas doesn't make any sense to me.
Re: Instructure pays ransom to Canvas hackers
#119(1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but explicitly noted this did not apply to the victims. "The U.S. Department of Justice does not intend to add to families’ pain in such cases by suggesting that they could face criminal prosecution."
(1b) Despite this policy, the US pays ransoms anyways. Usually in the form of prisoner swaps, but in 2023 it released $6 billion in frozen Iranian funds in exchange for the release of 5 hostages[1].
(2) The belief that paying ransoms should be illegal is predicated on the belief that criminals will be less likely to commit the crime if there is no money to be made. This may be true for kidnapping, but that does not mean it would be true for hacking. Kidnapping is a high-stakes, high-commitment crime that requires physical presence and exposes the criminal to significant danger. If the criminal anticipates no reward, the risk-reward calculus skews them away from kidnapping. However, hacking is a low-risk crime. Even if the chance of reward is low, the risk is also low, so hackers are unlikely to be deterred from hacking. Many hackers will do it just for fun or to prove that they can. Moreover, hackers can profit in other ways, for example by selling the data on the black market, or by making use of the data themselves as a nation-state or corporate espionage actor. Hacking will undoubtedly continue as long as things can be hacked, regardless of whether ransoms are ilegal.
(3) Making ransoms illegal pushes the burden onto people who have no real ability to do anything about it. When a company fails to pay ransom, it is the customers who suffer. It does not materially affect the company in any way to have customer data leaked. The market has already shown, overwhelmingly, that it will not punish companies that leak user data. That a company pays a ransom to begin with indicates that they don't actually understand the market and/or have some small shred of a conscience. Rather than making it illegal to pay ransoms, I would rather see penalties for having a data breach in the first place, but once a data breach is assured, companies should be paying ransoms to try to mitigate the damage to their customers.
(4) The idea of trying to solve hacking by making it illegal to pay ransoms is ridiculous on its face. As long as systems are insecure, hackers will exist, so the legal emphasis should be on consequences for data security. The collection of PII that is not essential to providing a service to customers should be discouraged, and there should be real consequences for negligent security. There should be an investigative board similar to those for airline crashes and infrastructure collapse, which examines the circumstances in depth and identifies whether the company is at fault for negligent handling of PII.
[1]https://2021-2025.state.gov/briefings/department-press-brief...
Re: Instructure pays ransom to Canvas hackers
#120Being that this is HN, do we know how they got hacked? Can we learn something about protecting our services?
I don't know for sure, but I think it probably had to do with some kind of misconfiguration on an Salesforce Experience Cloud site. I have heard that ShinyHunters often exploits this type of service and that it is very easy for companies to forget to set the right permissions to data and they end up throwing a bunch of different data into Salesforce.