Earlier quoted context omitted.
> It should be illegal It should be illegal to host insecure services, especially when you're dealing with PII. Breaches keep happening and nobody gives a fuck, because the worst that'll happen is you might lose a handful of customers and buy some "credit monitoring". Incidents like this should be followed by an audit and charges being laid. Send corp officers to jail for negligent security failures. If you can go to…
If Boeing claimed a plane was airworthy, but it crashed because basic engineering controls were skipped, we have collectively put our faith in the NTSB to preserve evidence, run an independent technical investigation, etc. There is no such authority for software - most security auditors (SOC2, HITRUST, etc) are just looking at self-reported data. Just take a look at the recent Epic vs. Health Gorilla lawsuit to see h…
Canvas online again as ShinyHunters threatens to leak schools’ data
231–240 of 690 posts
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#232Earlier quoted context omitted.
> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)
Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#233Earlier quoted context omitted.
No building has a 100% chance of not caving in, yet somehow I think charges would be laid if a skyscraper caved in.
This analogy seems to be portraying 'ransomware hackers' as an unstoppable force of nature akin to gravity . I'm not sure that's a fair analogy.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#234Perspective from the trenches: I teach at a university that uses Canvas. We are in our final exams period right now. We got our first email (from Academic Affairs) notifying us that it was down at 5:17pm EDT this afternoon, with little info; followup emails were sent at 6:24 and 6:57 with more info, but mostly about how we would be compensating for it and not about what actually was going on (other than, "nationwide…
> let classes that normally count for a grade just submit grades as pass-fail. Because what else can you do? Schedule a single exam and that's your grade for that subject? That's how it should work anyway, credits for work during semester (or worse attendance) are not needed to evaluate if someone learned the material, give them an exam and done.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#235Earlier quoted context omitted.
> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)
Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#236I'm surprised how few comments there are on this thread. This is probably affecting millions of students at the most stressful time of the year. Incidentally I've always hated Canvas and probably every other LMS provider, but what is particularly amusing about this current outage is that it is occurring at exactly the time when universities are demanding that all professors put all of their materials on Canvas, witho…
[flagged]
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#237Earlier quoted context omitted.
One of my mentors created Blackboard. It used to be very very good, but he sold it to private equity, and they immediately fired all of the customer support and developers, 3xd prices overnight leading to the 'blackboard sucks' problem. This gave the opening for Canvas to eventually come on to the scene and dominate.
I believe Canvas was also sold to private equity pretty recently too. https://www.instructure.com/press-release/instructure-to-be-...
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#238Earlier quoted context omitted.
How could you possibly make it illegal to host insecure services? Is any service 100% secure? And if it were how would we know? I do agree with the audit and punishments for clear failure to adhere to established standards.
This is a solved problem in pretty much every other domain of life - if you are following best practises but something that wasn't reasonably forseeable happens, then you're fine, but if the bad thing happens as a result of negligence then you are in trouble.
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#239I wonder how much old data Canvas keeps around? Are students who graduated in 2016 going to be at risk of having their academic data leaked?
Re: Canvas online again as ShinyHunters threatens to leak schools’ data
#240Earlier quoted context omitted.
Your "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.
Yeah, they identified themselves as ShinyHunters, and the IP they've put on the demonstration page is geocoded to Russia. Notice this is the same group responsible for the Infinite Campus hack last year. Really, though, if you want someone to blame, Instructure is not a particularly compelling target. Let's review: 1. Iran is intentionally targeting infrastructure due to a war started by the current administration. 2…