Earlier quoted context omitted.
Calm down, extremist. There's a difference between someone doing something vs someone paying someone else to stop doing something. If the latter were truly bad then the same should be applied to people handing over their wallet to muggers. The only difference in that scenario and the above is saving yourself vs saving a family member. Would you really deny people the ability to save their loved ones?
> then the same should be applied to people handing over their wallet to muggers Not really. Muggings are both more common and less traumatic than kidnappings. This is reflected in the fact that common and maximum sentences for kidnappings are universally more extreme than those for muggings. > Would you really deny people the ability to save their loved ones? ...yes. Because it means significantly fewer kidnappings.…
Instructure pays ransom to Canvas hackers
181–190 of 257 posts
Re: Instructure pays ransom to Canvas hackers
#182LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"
They said “received digital confirmation of data destruction (shred logs)” - is this supposed to fool users into thinking the hackers didn’t keep any of the data?
Re: Instructure pays ransom to Canvas hackers
#183Earlier quoted context omitted.
And that’s exactly why the incidence of kidnapping plummeted in Italy once ransom payments were made illegal
How does that work? I.e. say a kidnapping occurs and the ransom is paid. What kind of trouble does the paying party get into? A fine? Jail?
The real value though is enough people consider themselves honest and won't do anything they know is illegal. They already hate dealing with criminals, but so long as paying is legal they might do it, but as soon as it affects their moral code they won't. The whole system collapses because just a few people saying no to paying means the kidnappers lose money on too many operations.
Re: Instructure pays ransom to Canvas hackers
#184Earlier quoted context omitted.
> As bad and annoying as hackers are, I'm not familiar with any government recognizing any hacking group as a terrorist group. If you’re sending a large sum of money to $anonymoushacker, how do you ensure they’re not on some OFAC list? Or do your AML checks? Or make sure you’re not on the wrong side of Foreign Corrupt Practices act? The third party probably turns a blind eye to that cuz there’s no way of really check…
Cryptocurrency mitigates most of those concerns. That's why the flourishing of crypto payment systems has been an unalloyed blessing for cybercriminals.
Re: Instructure pays ransom to Canvas hackers
#185> Has law enforcement been engaged? Yes. We've notified law enforcement, including the FBI, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), and international law enforcement partners. Hmm. I thought all these agencies say NOT to pay a ransom.
Re: Instructure pays ransom to Canvas hackers
#186Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…
How is it not a violation of AML laws to pay a ransom like this? Surely they didn't verify that the recipient (a criminal) isn't sanctioned or associated with sanctioned organizations.
Re: Instructure pays ransom to Canvas hackers
#187Earlier quoted context omitted.
It can at a technical level but not at a legal level. Your BigCo accounting department is not going to be very understanding about acquiring cryptocurrency to send to ??? for a ransom.
Isn't this why in other comments people have said that companies use third parties to pay the ransom rather than paying directly?
An org’s Net30 terms aren’t going to work here…
Re: Instructure pays ransom to Canvas hackers
#188Earlier quoted context omitted.
> then the same should be applied to people handing over their wallet to muggers Not really. Muggings are both more common and less traumatic than kidnappings. This is reflected in the fact that common and maximum sentences for kidnappings are universally more extreme than those for muggings. > Would you really deny people the ability to save their loved ones? ...yes. Because it means significantly fewer kidnappings.…
And where does ransomware fall on that trauma scale? The maximum sentence is less than mugging after all..
Idk. That’s a step (sentencing guidelines) after we decide it should be criminalized.
> The maximum sentence is less than mugging after all..
They’re in the same ballpark, 2 to 6 years or so.
Re: Instructure pays ransom to Canvas hackers
#189>The data was returned to us. It was my understanding that the data was copied[1]. You wouldn't "return" data unless it was encrypted or the originals were deleted. I am confused on this phrasing but maybe it is standard idk. This is bullish on Monero[2]. The January pump may have been from a hack as well[3]. Here is Shinyhunters website. Canvas was listed on it[4] and then removed[5]. [1] https://www.youtube.com/wat…
Re: Instructure pays ransom to Canvas hackers
#190Earlier quoted context omitted.
And where does ransomware fall on that trauma scale? The maximum sentence is less than mugging after all..
> does ransomware fall on that trauma scale? Idk. That’s a step (sentencing guidelines) after we decide it should be criminalized. > The maximum sentence is less than mugging after all.. They’re in the same ballpark, 2 to 6 years or so.
You decide it should be criminalized before you identify any harms?
> They’re in the same ballpark, 2 to 6 years or so.
You can just look it up. Maximum sentence for mugging is 30 years, ransomware is 20.