Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

21–30 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#21

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

... except that "policies" don't cut it. Criminal penalties for paying are what you need, and not just for payments to specific designated entities, either. The executive making the decision to pay has to have a real fear of personally spending time in actual prison.

Re: Instructure pays ransom to Canvas hackers

#22

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

You can also have the "excessive force" doctrine, where holding someone or something for ransom results in your entire country being a smoldering crater.

But just like fail2ban, this gives someone else decision-making control over your actions, which can be abused.

Re: Instructure pays ransom to Canvas hackers

#23

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering.

The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

Re: Instructure pays ransom to Canvas hackers

#24

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

Yeah but fewer ransomes would be paid out regardless of who is attacking. They could be spoiling their own market and am sure they would

Re: Instructure pays ransom to Canvas hackers

#25

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

While the us stance has resulted in savings on potential ransom, it has also lead to people being kept in prison for very long time until prisoner exchanges might be worked out. That cost to an individuals life being imprisoned is probably far in excess whatever the US might pay. Plus the US prints its own monopoly money and doesn’t really play by the rules of economics anyhow ever since getting off gold standard.

Re: Instructure pays ransom to Canvas hackers

#26

Given they were hacked multiple times, couldn’t they just be targeted again by the same or different group? Why would it stop here?

The same group has a reputation to uphold (i.e., that of 'honourable' criminals), so they just move on to the next target, who will, incidentally, know that they are absolutely true to their word. (This is why paying off ransomware hackers is being made illegal in a number of countries.) A different group? Certainly. I wouldn't want to be in the shoes of the infosec guys at Canvas right now.

So they hacker group could create an unregistered subsidiary and hack some more?

Re: Instructure pays ransom to Canvas hackers

#27

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

> on the other hand, the ransomware groups that want to stay in business need to be honest

I was thinking about that the other day. Honestly I'm not sure it matters. I feel like if a company didn't pay the ransom that would possibly open them up to lawsuits or something because they "tried nothing". At least paying it makes it look like they did something and could be some sort of legal defense. But again I'm not a lawyer.

Re: Instructure pays ransom to Canvas hackers

#28
post #16
post #5

LOL that's some super heavy duty optics framing on what basically amounts to "we paid out a ransom but don't worry the bad guys assured us things were okay"

If the bad guys get paid and release the info anyway, they not only make it less likely they'll get paid in the future, they make it less likely anyone will get paid in the future. Even other bad guys have an incentive to stop these bad guys from leaking the info after getting paid.

Why not wait a week and take the site down and ransom them again?

Re: Instructure pays ransom to Canvas hackers

#29

Earlier quoted context omitted.

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

Yeah but fewer ransomes would be paid out regardless of who is attacking. They could be spoiling their own market and am sure they would

That's a motivation to avoid tragedy of the commons, not because they're trying to maintain their own reputation to victims. It benefits the criminals even if they change their name.

Re: Instructure pays ransom to Canvas hackers

#30
post #16

Earlier quoted context omitted.

If the bad guys get paid and release the info anyway, they not only make it less likely they'll get paid in the future, they make it less likely anyone will get paid in the future. Even other bad guys have an incentive to stop these bad guys from leaking the info after getting paid.

Why not wait a week and take the site down and ransom them again?

Because why would anyone pay anyone if they were going to do what they threatened you with anyway?
Post reply on HN