Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

121–130 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#121
post #110

Earlier quoted context omitted.

They could but also why would they? They can always just hack them again but with a different method this time. The ransom doesn't bind them from hacking the company multiple times. It just obligates them to destroy the data they collected from this attack. As a matter of kindness and good business they'll probably wait a few months or a year or so before poking around again but they'll almost certainly continue poki…

If you squint you can think of it as pen-testing done economically right: how much do you really value your data??

NGL that's pretty much what it is.

On the one side you have white hat hackers and pen-testers who you pay a contract or salary to prod your system. If you really piss them off (i.e. by stiffing them of their pay) some might just steal your data and threaten to leak it unless you pay them.

On the other side are black hat hackers who will drive by your system and if they find a way to break in they'll offer to keep your data private for a ransom fee. And maybe if you have some charisma, decent pay, and/or a good repertoire you might recruit them on/convert them into white hats for your org.

Re: Instructure pays ransom to Canvas hackers

#122

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.

Re: Instructure pays ransom to Canvas hackers

#123

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Thank goodness that no kidnapping of an American has ever happened since.

It is illegal to commit a crime. So no crimes will be committed. Duh.

Re: Instructure pays ransom to Canvas hackers

#124
post #113
post #102

Earlier quoted context omitted.

I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.

Wow. A lot of K-12 students probably don't even know their own SSN off the top of their head, much less understand the impact of having it stored in this way. I can't fathom why it would be necessary for the SSN to be tracked by the school. At most, the school district as a whole might want a record so they could make sure kids are getting schooled but putting that into Canvas doesn't make any sense to me.

Oh, it's insane and I recoiled when she mentioned that.

But it is 100% happening.

People do amazingly stupid things with systems, especially when they don't have enough people with the expertise to set them up properly, so they just throw things in there without stopping to think about whether or not it's a good idea.

Re: Instructure pays ransom to Canvas hackers

#125

Earlier quoted context omitted.

ShinyHunters has a vested financial stake in not leaking the customer data. If they did, nobody would ever pay a ransom to them again. I trust ShinyHunters to look out for themselves continuing to get paid.

Sure. Do you trust every member of ShinyHunters to remain a member of ShinyHunters in good standing, and to resist the temptation to exfiltrate the data in the process of exiting ShinyHunters?

I would expect ShinyHunters to understand that traitors pose an existential threat to the group and to take measures to prevent a lone wolf from selling them out easily. That they have existed for 7 years already indicates they are probably not so amateur as to allow any individual member to walk off with data that would compromise their operation.

Re: Instructure pays ransom to Canvas hackers

#126

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Isn't there still incentive because the data itself is valuable so attacks would continue?

Re: Instructure pays ransom to Canvas hackers

#127
post #52
post #39

Earlier quoted context omitted.

> Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. You're then a target known to be vulnerable and pay ransoms, so best focus on security.

If you have to pay, at least try to negotiate 1) a guarantee that the hackers won't just do it again sometime later, and 2) full disclosure / assistance in repairing your vulnerabilities so you have some kind of head start for the future. Outside of politically motivated hackers, this would probably be reasonably successful.

What possible type of guarantee could one ever hope to "negotiate" with someone who has just successfully blackmailed/ransomed/extorted?

Re: Instructure pays ransom to Canvas hackers

#128

Being that this is HN, do we know how they got hacked? Can we learn something about protecting our services?

This blog post[0] suggests that, based on their changelog after the incident, the hackers may have extracted session tokens using XSS in a support ticket. Then the ransom note was displayed using a custom theme.

[0]: https://cyber.acmucsd.com/canvas (disclosure: I was involved with this org when I was a student)

Re: Instructure pays ransom to Canvas hackers

#129

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

one issue is that modern ransomeware groups are also being hunted themselves - there are many ransomeware orgs that are themselves being ransomed so are not reliable.

even if you pay the ransom to the 1st group, the 2nd group will leak.

Post reply on HN