Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

191–200 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#192

Earlier quoted context omitted.

> does ransomware fall on that trauma scale? Idk. That’s a step (sentencing guidelines) after we decide it should be criminalized. > The maximum sentence is less than mugging after all.. They’re in the same ballpark, 2 to 6 years or so.

> That’s a step (sentencing guidelines) after we decide it should be criminalized. You decide it should be criminalized before you identify any harms? > They’re in the same ballpark, 2 to 6 years or so. You can just look it up. Maximum sentence for mugging is 30 years, ransomware is 20.

> You decide it should be criminalized before you identify any harms?

No. We have a measure of the harms. We haven’t balanced them for sentencing. Again, deciding something should be illegal doesn’t require obsessing over the sentence ex ante.

> Maximum sentence for mugging is 30 years

Not the norm, either for maximums [1] or usual sentences.

[1] https://en.wikipedia.org/wiki/Robbery_laws_in_the_United_Sta...

Re: Instructure pays ransom to Canvas hackers

#193

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Is it illegal to pay kidnappers in the united states? I've never heard of this and I can't seem to find anything that says any such law has actually been passed.

Re: Instructure pays ransom to Canvas hackers

#194

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Is it illegal to pay kidnappers in the united states? I've never heard of this and I can't seem to find anything that says any such law has actually been passed.

It's technically not illegal, but often is. You can't pay terrorist organizations or specially sanctioned orgs. See https://sanctionssearch.ofac.treas.gov

Probably should consult an attorney before paying a ransom (whether for kidnapping or other purposes).

Re: Instructure pays ransom to Canvas hackers

#196
post #52

Earlier quoted context omitted.

If you have to pay, at least try to negotiate 1) a guarantee that the hackers won't just do it again sometime later, and 2) full disclosure / assistance in repairing your vulnerabilities so you have some kind of head start for the future. Outside of politically motivated hackers, this would probably be reasonably successful.

What possible type of guarantee could one ever hope to "negotiate" with someone who has just successfully blackmailed/ransomed/extorted?

If the ransomware operator believes that breaking their word might make it harder to get money out of future victims, they'll keep their word.

They might not believe that, but if you're at the point where you're paying anyway, you might as well try to get that commitment from them.

Re: Instructure pays ransom to Canvas hackers

#197

Earlier quoted context omitted.

Depends on what they actually got. Names and email addresses? Considered public and are not so valuable. Universities usually publish those in a directory anyway. Messages between students and instructors? Likely pretty boring, but possibly embarassing or confidential for a given individual. Grades? Could be a FERPA violation. Critical PII such as SSNs? Probably not in the LMS to begin with.

SSNs have been used as student IDs by particularly stupid educational institutions. The 'nice' thing about getting SSNs from students is the likelihood they'll live for a long time after the breach and thus be subject to identity theft for many years to come.

My university stopped putting SSNs on student IDs more than 25 years ago. I'd be surprised if there are many who still do that.

Though I wouldn't be surprised if some 40 year old university IT system requires its use as an identifier, regardless of whether or not it gets printed anywhere.

Re: Instructure pays ransom to Canvas hackers

#198

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Who would of thought paying teenagers millions of dollars in crypto was a good idea?

They'll just use it on more exploits, more nonsense. It's a race to the bottom. Sister group, Lapsus$ (parent group ShinyHunters) has published on their website they will pay for inside access to company networks. The group says they don't want data, they just want an avenue.

This is what happens when we keep paying these criminals millions in hard-to-trace crypto.

I do find it all a bit funny though.

Re: Instructure pays ransom to Canvas hackers

#199

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

Who would of thought paying teenagers millions of dollars in crypto was a good idea? They'll just use it on more exploits, more nonsense. It's a race to the bottom. Sister group, Lapsus$ (parent group ShinyHunters) has published on their website they will pay for inside access to company networks. The group says they don't want data, they just want an avenue. This is what happens when we keep paying these criminals m…

[deleted]

Re: Instructure pays ransom to Canvas hackers

#200

Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?

I think Instructure has made themselves a target. I'm a professor at a college that uses Canvas and I'm going to be making sure I download the gradebook for my classes more often from now on.
Post reply on HN