Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

221–230 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#221
Everyone's making a lot of good points about game theory and economic motivations, but there is a much more important and self-serving point: when you pay a ransom, hackers come after your shit x10.

Paying a ransom signals 3 things: 1) you are vulnerable to attack 2) you cannot recover from an attack 3) you've got cash

The result is that you get attacked much, much more. You could ask me how I know, but I wouldn't tell you :)

Re: Instructure pays ransom to Canvas hackers

#222

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

The issue is that anything a hacker can do publicly a state actor can do silently.

Its a boon to both the company and the country when a hacker makes a big public deal out of it. Because they get the chance to repair something before its intentional damaging misuse by a hostile state actor.

The hackers here deserve every cent plus possibly more.

And theres always the problem that the hackers would still get paid, they just wont report the payments making tracking difficult.

Re: Instructure pays ransom to Canvas hackers

#223

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

>but everyone would be better off if no one paid a ransom.

I doubt if everyone would be better off if state level actors found and used these vulnerabilities instead of ransom seekers.

Re: Instructure pays ransom to Canvas hackers

#225

Earlier quoted context omitted.

... except that "policies" don't cut it. Criminal penalties for paying are what you need, and not just for payments to specific designated entities, either. The executive making the decision to pay has to have a real fear of personally spending time in actual prison.

A criminal penalty is a form of policy

... but not the form of policy they actually have.

Except for payments to specifically sanctioned organizations, the policy is "we'd really rather you didn't do that, but whatever".

The specific sanctions don't cover most of the groups, either, and even when they do cover the group who got paid, you can't necessarily prove the people who got paid were the ones on the list. And there may be a scienter requirement even then; I don't know.

Making a list of specific criminals you can't pay is just stupid. No ransoms, ever, period, or it's da slammah.

Re: Instructure pays ransom to Canvas hackers

#226

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

Why don't someone pretend to be ransom hacker, take the money, and release the hacked data anyway?

This will progress the game theory to the point where nobody will pay ransom because the thieves won't honor the deals anyway.

Re: Instructure pays ransom to Canvas hackers

#227

Earlier quoted context omitted.

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.

Our PII is leaked all the time. I am fed up with various businesses sending me a free credit monitoring subscription in lieu of actually having proper security controls or damages that incentivize viewing the issue as a serious going concern risk.

Leaks are inevitable, but the current situation is absurd. The liabilities and incentives to do anything about them are virtually nonexistent and security is almost always viewed as a cost.

Re: Instructure pays ransom to Canvas hackers

#228

Earlier quoted context omitted.

This is the way to go. Instead of paying ransom, and creating a ransomware criminal industry out of thin air, its better to force companies to recover and restore from backups and remove monetary incentive for crime. and the executives who failed to carry regular backups obviously should face the music

Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.

Was it really a problem? Yes, voluntary release of that info by a school would normally likely be a FERPA violation, but this was a criminal act against a third party.

Infrastructure’s motivations must have lain elsewhere…

Re: Instructure pays ransom to Canvas hackers

#229

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

I’ve been wondering this too.

Extortion and terrorism seem similar in many ways except the latter involves physical harm.

I’d asssume a company paying money to terrorists shouldn’t be acceptable.

It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place.

Might as well use a bank whose safe deposit boxes are made of cardboard… They can just bribe the thieves to give some things back.

Re: Instructure pays ransom to Canvas hackers

#230

I've seen half a dozen comments in this thread suggesting that paying hacking ransoms should be illegal, but I strongly disagree, for multiple reasons. I'll just make this a top-level comment rather than picking one to reply to. (1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but expl…

If customers suffer when a company doesn’t pay ransom - that’s a good thing.

Those (now former) customers can the be patrons of a competitor that doesn’t let such happen again.

Post reply on HN