Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

181–190 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#181

Earlier quoted context omitted.

Calm down, extremist. There's a difference between someone doing something vs someone paying someone else to stop doing something. If the latter were truly bad then the same should be applied to people handing over their wallet to muggers. The only difference in that scenario and the above is saving yourself vs saving a family member. Would you really deny people the ability to save their loved ones?

> then the same should be applied to people handing over their wallet to muggers Not really. Muggings are both more common and less traumatic than kidnappings. This is reflected in the fact that common and maximum sentences for kidnappings are universally more extreme than those for muggings. > Would you really deny people the ability to save their loved ones? ...yes. Because it means significantly fewer kidnappings.…

And where does ransomware fall on that trauma scale? The maximum sentence is less than mugging after all..

Re: Instructure pays ransom to Canvas hackers

#182
post #58
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

They said “received digital confirmation of data destruction (shred logs)” - is this supposed to fool users into thinking the hackers didn’t keep any of the data?

maybe they were using quantum computers the whole time https://eprint.iacr.org/2022/1178 /s

Re: Instructure pays ransom to Canvas hackers

#183
post #88

Earlier quoted context omitted.

And that’s exactly why the incidence of kidnapping plummeted in Italy once ransom payments were made illegal

How does that work? I.e. say a kidnapping occurs and the ransom is paid. What kind of trouble does the paying party get into? A fine? Jail?

So long as the potential payer knows they will get something they are going to slow down. They might pay, but suddenly becomes harder because they have to hide what they are doing. Many won't figure out how to pay.

The real value though is enough people consider themselves honest and won't do anything they know is illegal. They already hate dealing with criminals, but so long as paying is legal they might do it, but as soon as it affects their moral code they won't. The whole system collapses because just a few people saying no to paying means the kidnappers lose money on too many operations.

Re: Instructure pays ransom to Canvas hackers

#184

Earlier quoted context omitted.

> As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If you’re sending a large sum of money to $anonymoushacker, how do you ensure they’re not on some OFAC list? Or do your AML checks? Or make sure you’re not on the wrong side of Foreign Corrupt Practices act? The third party probably turns a blind eye to that cuz there’s no way of really check…

Cryptocurrency mitigates most of those concerns. That's why the flourishing of crypto payment systems has been an unalloyed blessing for cybercriminals.

No it does not. It makes some things harder and some things easier. The public ledger means you can track where then money flowed - you might not know who had it but you know how it flows which is interesting. I don't know if it has happened, but I've heard of proposals to make any bitcoin the traces to some transaction illegal to have, and that means nobody who might get caught will have anything to do with those.

Re: Instructure pays ransom to Canvas hackers

#185
post #67

> Has law enforcement been engaged? Yes. We've notified law enforcement, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and international law enforcement partners. Hmm. I thought all these agencies say NOT to pay a ransom.

Not always. They have been known to give "marked bills" to pay with in the past. A lot can be learned by watching how ransom money moves around (bit coin is very traceable this way). Sometimes paying a ransom is an important part of finding and arresting the guilty.

Re: Instructure pays ransom to Canvas hackers

#186

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.

Probably not too relevant but off the top of my head, the New Zealand Government's guidance on ransomware payments is that you could technically be fined if you pay a ransom to an entity in a sanctioned country, although it doesn't go into specifics

Re: Instructure pays ransom to Canvas hackers

#187

Earlier quoted context omitted.

It can at a technical level but not at a legal level. Your BigCo accounting department is not going to be very understanding about acquiring cryptocurrency to send to ??? for a ransom.

Isn't this why in other comments people have said that companies use third parties to pay the ransom rather than paying directly?

That’s my theory too. Setting up payments to a new vendor is hard enough even for the most legitimate.

An org’s Net30 terms aren’t going to work here…

Re: Instructure pays ransom to Canvas hackers

#188

Earlier quoted context omitted.

> then the same should be applied to people handing over their wallet to muggers Not really. Muggings are both more common and less traumatic than kidnappings. This is reflected in the fact that common and maximum sentences for kidnappings are universally more extreme than those for muggings. > Would you really deny people the ability to save their loved ones? ...yes. Because it means significantly fewer kidnappings.…

And where does ransomware fall on that trauma scale? The maximum sentence is less than mugging after all..

> does ransomware fall on that trauma scale?

Idk. That’s a step (sentencing guidelines) after we decide it should be criminalized.

> The maximum sentence is less than mugging after all..

They’re in the same ballpark, 2 to 6 years or so.

Re: Instructure pays ransom to Canvas hackers

#189

>The data was returned to us. It was my understanding that the data was copied[1]. You wouldn't "return" data unless it was encrypted or the originals were deleted. I am confused on this phrasing but maybe it is standard idk. This is bullish on Monero[2]. The January pump may have been from a hack as well[3]. Here is Shinyhunters website. Canvas was listed on it[4] and then removed[5]. [1] https://www.youtube.com/wat…

This is a good time to point out that when there is a data breach, data is rarely stolen. The real threat and harm is when data that is stolen is used against you.

Re: Instructure pays ransom to Canvas hackers

#190

Earlier quoted context omitted.

And where does ransomware fall on that trauma scale? The maximum sentence is less than mugging after all..

> does ransomware fall on that trauma scale? Idk. That’s a step (sentencing guidelines) after we decide it should be criminalized. > The maximum sentence is less than mugging after all.. They’re in the same ballpark, 2 to 6 years or so.

> That’s a step (sentencing guidelines) after we decide it should be criminalized.

You decide it should be criminalized before you identify any harms?

> They’re in the same ballpark, 2 to 6 years or so.

You can just look it up. Maximum sentence for mugging is 30 years, ransomware is 20.

Post reply on HN