Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

151–160 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#151

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.

Money laundering is the action of obfuscating the origin of criminal proceeds; victims or clients of criminals do not generally commit money laundering, for example buying drugs is not a form of AML violation regardless of the legality of the purchase itself or the fact that the funds will later be laundered by the traffickers.

KYC is a tool to prevent money laundry and it's typically an obligation of financial institutions. Sending money to an anonymous (to you) recipient is generally not a KYC violation if you are not in the money transmitting business and you aren't doing the payment on behalf of someone else.

There are infinite shades of gray in this topic, of course, but I can't see AML being relevant in this particular case.

Re: Instructure pays ransom to Canvas hackers

#152

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Not that I disagree but it also incentives attackers to steal and resell data to other nefarious actors.

After all a lot of the data companies have isn't their own, it's their customers. They are the ones who suffer because businesses don't bother securing their crap.

Re: Instructure pays ransom to Canvas hackers

#153

Earlier quoted context omitted.

It is illegal to pay terrorists. As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If they did, would they be able to send in SEAL Team 6 to handle the hackers?

> As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If you’re sending a large sum of money to $anonymoushacker, how do you ensure they’re not on some OFAC list? Or do your AML checks? Or make sure you’re not on the wrong side of Foreign Corrupt Practices act? The third party probably turns a blind eye to that cuz there’s no way of really check…

the people who do "AML checks" are the ones processing the transaction.

i don't do that every time i want to send money. private individuals don't just "run checks" - it would make commerce untenable and possibly unconstitutional.

say you get a passport, an address, a photo, a signature, a phone call - how do you verify any of this is real?

Re: Instructure pays ransom to Canvas hackers

#154
post #72

Earlier quoted context omitted.

A large percentage of hacking groups are state sponsored Russians. That seal response would be starting WW3 over some pii. Protecting pii is important, but it's not that important

we started the pretext to WW3 over someone wanting to move the focus of attention, so it's really not that much of a stretch.

Aye, I meant more in the sense of "it would be a bad idea", than "that's definitely not going to happen".

Predictions are hard, especially about the future!

Re: Instructure pays ransom to Canvas hackers

#155

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

That operates on the idea that hacker organizations use long term strategic thinking, something the US government and a good number of corporations don’t even practice. I wouldn’t put my money on that.

while i am not about to bet the farm on the long-term strategic thinking ability of extortion groups, they are much smaller than most corporations and the US government, thus its much easier to think strategically and execute on longer-term goals.

shinyhunters, for example, has been active and acted as a cohesive unit for the past 7 years.

Re: Instructure pays ransom to Canvas hackers

#156

Earlier quoted context omitted.

ShinyHunters has a vested financial stake in not leaking the customer data. If they did, nobody would ever pay a ransom to them again. I trust ShinyHunters to look out for themselves continuing to get paid.

This is a really silly take. Instructure also had a financial incentive not to get hacked. And yet…

No, it actually doesn't, which is the problem. The market has shown that there are no financial consequences to any company that gets hacked. Instructure could have just as well not paid the ransom, as many companies don't, and continued to be fine. Even if they do pay the ransom, it is likely that it is less than it would have costed them to engineer secure systems, so even if you take paying ransoms as necessary market incentives still steer you to ignoring security.

Re: Instructure pays ransom to Canvas hackers

#157

Earlier quoted context omitted.

How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.

Money laundering is the action of obfuscating the origin of criminal proceeds; victims or clients of criminals do not generally commit money laundering, for example buying drugs is not a form of AML violation regardless of the legality of the purchase itself or the fact that the funds will later be laundered by the traffickers. KYC is a tool to prevent money laundry and it's typically an obligation of financial insti…

Thank you! That's basically what I was asking.

Re: Instructure pays ransom to Canvas hackers

#158

Earlier quoted context omitted.

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

... except that "policies" don't cut it. Criminal penalties for paying are what you need, and not just for payments to specific designated entities, either. The executive making the decision to pay has to have a real fear of personally spending time in actual prison.

A criminal penalty is a form of policy

Re: Instructure pays ransom to Canvas hackers

#159

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Thank goodness that no kidnapping of an American has ever happened since.

Hmm, there was once fraud so I guess we should repeal any prohibitions on fraud, huh? Same for murder.

Re: Instructure pays ransom to Canvas hackers

#160

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Not sure sanctions are a relevant reason not to pay here. We don’t know where everyone involved with ShinyHunters is located, but those arrested in the past have been American and French.
Post reply on HN