Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

171–180 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#171

Earlier quoted context omitted.

Thank goodness that no kidnapping of an American has ever happened since.

Hmm, there was once fraud so I guess we should repeal any prohibitions on fraud, huh? Same for murder.

Calm down, extremist. There's a difference between someone doing something vs someone paying someone else to stop doing something. If the latter were truly bad then the same should be applied to people handing over their wallet to muggers. The only difference in that scenario and the above is saving yourself vs saving a family member. Would you really deny people the ability to save their loved ones?

Re: Instructure pays ransom to Canvas hackers

#172
post #166

Earlier quoted context omitted.

So, a particular school system decided to add SSN to the student profile? Or Canvas requires it?

It's not required. I don't know precisely what her district is doing or why - I don't work there But she unprompted brought up that a lot of the minors' PII was in there including SSNs.

It would be nice if system owners stopped thinking "we'll just ask for all the info in case we need it" and instead "we might get sued (or ransomed, or both) because we are collecting this."

Re: Instructure pays ransom to Canvas hackers

#173

I'm curious about the open source competition ( https://github.com/moodle/moodle is my first find, there are likely others) and what they could've made happen with that money if they had received it instead as an investment re: not worrying about future ransomware attacks.

Canvas itself is also open source ( https://github.com/instructure/canvas-lms ), which was the big appeal of it originally in a world where Blackboard had a stranglehold on the LMS market.

Huh, neat! I had just assumed otherwise because everything else my university uses is nine kinds of proprietary.

Like, they recently tried to sell me to McMillian who then tried to sell me the "submit homework" button for $20. I complained and got exempted from having to submit homework, but that's par for the course in edtech right now.

Re: Instructure pays ransom to Canvas hackers

#174

Earlier quoted context omitted.

Hmm, there was once fraud so I guess we should repeal any prohibitions on fraud, huh? Same for murder.

Calm down, extremist. There's a difference between someone doing something vs someone paying someone else to stop doing something. If the latter were truly bad then the same should be applied to people handing over their wallet to muggers. The only difference in that scenario and the above is saving yourself vs saving a family member. Would you really deny people the ability to save their loved ones?

> then the same should be applied to people handing over their wallet to muggers

Not really. Muggings are both more common and less traumatic than kidnappings. This is reflected in the fact that common and maximum sentences for kidnappings are universally more extreme than those for muggings.

> Would you really deny people the ability to save their loved ones?

...yes. Because it means significantly fewer kidnappings. "Deny people the ability to save their loved ones" is tantamount to "help others to lose their own."

Re: Instructure pays ransom to Canvas hackers

#175

Earlier quoted context omitted.

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Wouldn't that incentivise companies manufacturing media and backup facilities to finance ransomware operators?

> Wouldn't that incentivise companies manufacturing media and backup facilities to finance ransomware operators?

No, for the same reason fence manufacturers aren't financing burglers.

Re: Instructure pays ransom to Canvas hackers

#176

Earlier quoted context omitted.

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Wouldn't that incentivise companies manufacturing media and backup facilities to finance ransomware operators?

There is enough competition that if word gets out you can move to someone honest. At this size you can't keep a secret.

Re: Instructure pays ransom to Canvas hackers

#177

Earlier quoted context omitted.

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Wouldn't that incentivise companies manufacturing media and backup facilities to finance ransomware operators?

It may be that the ideal number of ransomware operators is non-zero

Re: Instructure pays ransom to Canvas hackers

#178
post #160

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Not sure sanctions are a relevant reason not to pay here. We don’t know where everyone involved with ShinyHunters is located, but those arrested in the past have been American and French.

Americans and French (and most other "first world") countries will investigate and arrest anyone involved. It doesn't matter if foreigners are the only victim, most countries do not want their citizens involved with this and will send anyone caught to whatever country was affects for criminal prosecution.

Russia, and North Korea are the main names that come up as exceptions, they will protect their own people.

Re: Instructure pays ransom to Canvas hackers

#179

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Isn't there still incentive because the data itself is valuable so attacks would continue?

How much value is in the data. It is embarrassing if some kid gets a D in class, and shouldn't be public - but most of the people who care already know or have ways to find out.

Re: Instructure pays ransom to Canvas hackers

#180
post #111

Earlier quoted context omitted.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.

I have trouble imagining that a ransomware group would care about a regulation like FERPA when they've already done something criminal that would more than enough for prosecution if they got caught.

Those laws reduce the value though - "honest" people who are interested in such data won't be interested it from ransomware because they need to have legally obtained data. That is there are a lot of "honest but shady" uses of this data that are stopped by these laws.
Post reply on HN