Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

231–240 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#231

Earlier quoted context omitted.

> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…

If Boeing claimed a plane was airworthy, but it crashed because basic engineering controls were skipped, we have collectively put our faith in the NTSB to preserve evidence, run an independent technical investigation, etc. There is no such authority for software - most security auditors (SOC2, HITRUST, etc) are just looking at self-reported data. Just take a look at the recent Epic vs. Health Gorilla lawsuit to see h…

Edit: I was incorrect / non-American, I was thinking of your FAA.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#232
post #212

Earlier quoted context omitted.

> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)

Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.

You forget things can be signed, with the key owned by the school. It can be done.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#233

Earlier quoted context omitted.

No building has a 100% chance of not caving in, yet somehow I think charges would be laid if a skyscraper caved in.

This analogy seems to be portraying 'ransomware hackers' as an unstoppable force of nature akin to gravity . I'm not sure that's a fair analogy.

The other side of that spectrum portrays the service providers as pure, negligence-free victims. The truth is probably somewhere in the middle.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#234
post #228

Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…

> let classes that normally count for a grade just submit grades as pass-fail. Because what else can you do? Schedule a single exam and that's your grade for that subject? That's how it should work anyway, credits for work during semester (or worse attendance) are not needed to evaluate if someone learned the material, give them an exam and done.

Exams have performance variance. Otherwise you're only getting a pass/fall signal in any case.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#235
post #212

Earlier quoted context omitted.

> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)

Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.

As opposed to a screenshot of a website? Presumably the professor has a spreadsheet of all assignment grades that is submitted to the school?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#236

I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, witho…

[flagged]

Accessibility regulations, implemented with feedback from faculty and with the support of university resources, are certainly a good thing. But that is not what is happening in my experience.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#237
post #132
post #65

Earlier quoted context omitted.

One of my mentors created Blackboard. It used to be very very good, but he sold it to private equity, and they immediately fired all of the customer support and developers, 3xd prices overnight leading to the 'blackboard sucks' problem. This gave the opening for Canvas to eventually come on to the scene and dominate.

I believe Canvas was also sold to private equity pretty recently too. https://www.instructure.com/press-release/instructure-to-be-...

canvas was bought by PE for the first time in 2020 https://www.thomabravo.com/portfolio/instructure

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#238

Earlier quoted context omitted.

How could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know? I do agree with the audit and punishments for clear failure to adhere to established standards.

This is a solved problem in pretty much every other domain of life - if you are following best practises but something that wasn't reasonably forseeable happens, then you're fine, but if the bad thing happens as a result of negligence then you are in trouble.

I like to relate it to operating an automobile. You can follow every traffic law and still be liable in an accident, because you owned the vehicle that caused the damage. This is why you have insurance.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#239
post #27

I wonder how much old data Canvas keeps around? Are students who graduated in 2016 going to be at risk of having their academic data leaked?

It wouldn't surprise me if most of it is still around. The amounts of data are probably fairly small, and thus unless intentionally deleted, it's probably still there (maybe unis in Europe are more likely to bother to click the relevant buttons as to comply with the GDPR?). I can't imagine storage becoming an issue unless you've got a huge uni or classes that deal with video (and even then, those probably end up on Youtube as private videos, or only as really small clips).

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#240
post #99

Earlier quoted context omitted.

Your "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.

Yeah, they identified themselves as ShinyHunters, and the IP they've put on the demonstration page is geocoded to Russia. Notice this is the same group responsible for the Infinite Campus hack last year. Really, though, if you want someone to blame, Instructure is not a particularly compelling target. Let's review: 1. Iran is intentionally targeting infrastructure due to a war started by the current administration. 2…

Having an IP in Russia means about zero regarding their location. Literally anyone doing anything like this is going to get a Chinese or a Russian IP for obvious reasons. Mostly decoy and people like you.
Post reply on HN