Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

161–170 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#161

Earlier quoted context omitted.

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

While the us stance has resulted in savings on potential ransom, it has also lead to people being kept in prison for very long time until prisoner exchanges might be worked out. That cost to an individuals life being imprisoned is probably far in excess whatever the US might pay. Plus the US prints its own monopoly money and doesn’t really play by the rules of economics anyhow ever since getting off gold standard.

This is literally the exact point I am making, and the US policy isn’t about saving money.

Like you said (and like I said in my post), for an individual kidnap victim, the best option would be to pay the ransom. It is better to pay the money and be free.

However, that means a kidnap group now has more money, which will make them better able to kidnap another victim and demand more money.

The point of a “no ransom” policy is that it takes the choice away from the individual, who would choose to pay it, and changes the game theory to make kidnapping not worth it.

The whole reason you need a policy at all is BECAUSE it is better for the person to pay the ransom.

Re: Instructure pays ransom to Canvas hackers

#162

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Wouldn't that incentivise companies manufacturing media and backup facilities to finance ransomware operators?

Re: Instructure pays ransom to Canvas hackers

#163
post #97

Earlier quoted context omitted.

In the abstract, it’s hilarious to imagine the hackers keeping the data, then some time from now leaking it accidentally (or another hacker group hacks them) then them having to issue a public apology for not having kept the stolen data secure and having lied about shredding it.

However, they could use it as a last resort or as a final "gift" before getting arrested or switching identities. They might be considered "trustworthy" right now to get companies to pay them money, but no one will know what will happen in a few years when this strategy won't work anymore. Anyway, I hope this doesn't come at all, or as late as possible.

> but no one will know what will happen in a few years when this strategy won't work anymore.

Good point.

> Anyway, I hope this doesn't come at all, or as late as possible.

Same. As I said, I find the idea funny in the abstract, if it didn’t affect anyone or if it were a TV show, for example. But since it does affect real people…

Re: Instructure pays ransom to Canvas hackers

#164
post #134

Earlier quoted context omitted.

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

There's one more piece that matters. If no one pays the ransoms, but people believe that large ransoms are paid-- you still have the crime.

The obverse is true - because a ransom organization is dependent upon their reputation, a company claiming to have paid and received confirmation from the group could prevent them from releasing it as well.

The general public (including the next victims) don't have a way to confirm if payment was made. ShinyHunters would have to choose between arguing publicly that they were not paid or not releasing the data to protect their own reputation...

Re: Instructure pays ransom to Canvas hackers

#165
post #114

I wonder if, longer term, we're better off if a company like this were in some way destroyed as a result of getting hacked and paying a bribe. I think the stakes for getting hacked are far too low, especially at higher levels of management/executive where it's this abstract thing that has concrete time/resource costs.

I've never seen a company blame a data breach as the point where they started going bankrupt. Customers never migrate on mass after a breach, 7000 underfunded and overworked education institutions are not migrating on mass. So I feel safe to say there's no lasting impact to a company when a data breach occurs. This will all be forgotten in a few months.

To be fair, I don't think I've ever seen a company identify the inflection point after bankruptcy, accurately or not.

Re: Instructure pays ransom to Canvas hackers

#166
post #124

Earlier quoted context omitted.

Oh, it's insane and I recoiled when she mentioned that. But it is 100% happening. People do amazingly stupid things with systems, especially when they don't have enough people with the expertise to set them up properly, so they just throw things in there without stopping to think about whether or not it's a good idea.

So, a particular school system decided to add SSN to the student profile? Or Canvas requires it?

It's not required. I don't know precisely what her district is doing or why - I don't work there But she unprompted brought up that a lot of the minors' PII was in there including SSNs.

Re: Instructure pays ransom to Canvas hackers

#167
post #102

Earlier quoted context omitted.

I just spoke with a K-12 teacher I know, and she confirmed SSNs in the Canvas instance. Yikes.

They already have your SSN, as does anyone else who wants it.

True. It's more yikes about what this says about the technical knowledge in that school.

Re: Instructure pays ransom to Canvas hackers

#168
post #134

Earlier quoted context omitted.

There's one more piece that matters. If no one pays the ransoms, but people believe that large ransoms are paid-- you still have the crime.

The obverse is true - because a ransom organization is dependent upon their reputation, a company claiming to have paid and received confirmation from the group could prevent them from releasing it as well. The general public (including the next victims) don't have a way to confirm if payment was made. ShinyHunters would have to choose between arguing publicly that they were not paid or not releasing the data to prot…

Good/funny observation. Game theory and economics are fun. :D

I do think that the partial information problem relating to new entrants into this market is interesting though.

The number of potential threat actors with partial/no information but that might speculate based on grandiose visions of ransom or outdated history is high.

We see dumb attempts at real-world ransoms/extortion which don't get paid at a pretty high clip based on this kind of partial knowledge.

Re: Instructure pays ransom to Canvas hackers

#169
post #60

I suspected as much as it disappeared from the ShinnyHunters page and it recovered so fast. The main thing I'm interested in knowing was how much was paid. Also I don't really like their statement that the data is safe or destroyed, those promises seem a little questionable with regards to these incidents.

I'm interested in this, too. I found a tweet[1] listing a wallet address for shinyhunters, but there's only a small transaction from last week: https://www.blockonomics.co/#/search?q=bc1q5530apqz86eywm2f8...

[1] https://xcancel.com/search?f=tweets&q=1968412640398430555

Re: Instructure pays ransom to Canvas hackers

#170

Earlier quoted context omitted.

Cryptocurrency mitigates most of those concerns. That's why the flourishing of crypto payment systems has been an unalloyed blessing for cybercriminals.

It can at a technical level but not at a legal level. Your BigCo accounting department is not going to be very understanding about acquiring cryptocurrency to send to ??? for a ransom.

Isn't this why in other comments people have said that companies use third parties to pay the ransom rather than paying directly?
Post reply on HN