Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

231–240 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#231

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

I’ve been wondering this too. Extortion and terrorism seem similar in many ways except the latter involves physical harm. I’d asssume a company paying money to terrorists shouldn’t be acceptable. It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place. Might as well use a bank whose safe deposit boxes are made of cardboar…

>It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place.

You are paying an extra fee for not testing your own software and infrastructure. It was instead tested by a third party. Be glad it wasn't tested by a nation state actor or someone who wanted to do more harm to your customers than just asking for money.

Ideally they should now secure their infrastructure and take this as a gentle reminder that they should spend more on security.

>Might as well use a bank whose safe deposit boxes are made of cardboard… They can just bribe the thieves to give some things back.

You would hope they would then upgrade the cardboard.

Re: Instructure pays ransom to Canvas hackers

#232

Earlier quoted context omitted.

I’ve been wondering this too. Extortion and terrorism seem similar in many ways except the latter involves physical harm. I’d asssume a company paying money to terrorists shouldn’t be acceptable. It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place. Might as well use a bank whose safe deposit boxes are made of cardboar…

>It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place. You are paying an extra fee for not testing your own software and infrastructure. It was instead tested by a third party. Be glad it wasn't tested by a nation state actor or someone who wanted to do more harm to your customers than just asking for money. Ideally th…

When you frame it like that it sounds like the thieves are doing us a favor. Except it should be heavily fined and jailable for the entire executive team and maybe the board too.

Re: Instructure pays ransom to Canvas hackers

#233

Earlier quoted context omitted.

Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.

Was it really a problem? Yes, voluntary release of that info by a school would normally likely be a FERPA violation, but this was a criminal act against a third party. Infrastructure’s motivations must have lain elsewhere…

Does that really shield the schools? HIPAA wouldn't care.

Re: Instructure pays ransom to Canvas hackers

#234

I've seen half a dozen comments in this thread suggesting that paying hacking ransoms should be illegal, but I strongly disagree, for multiple reasons. I'll just make this a top-level comment rather than picking one to reply to. (1a) Multiple have suggested that the US made it illegal to pay kidnapping ransoms. This is a misconception. The US adopted a policy that the government itself would not pay ransoms, but expl…

If customers suffer when a company doesn’t pay ransom - that’s a good thing. Those (now former) customers can the be patrons of a competitor that doesn’t let such happen again.

That's just not reality. Not least of which because competitors are exactly the same when it comes to security. Even if they weren't, security isn't something the market can realistically select for because it's not verifiable from a customer's perspective. A customer can clearly see, say, a price difference or feature difference, but cannot see a security difference in any meaningful sense. This is something that needs to be enforced at a regulatory level, there are many problems the free market cannot solve, and in fact market forces actively incentivize neglecting security.

Re: Instructure pays ransom to Canvas hackers

#235

Earlier quoted context omitted.

>It also seems especially egregious to pay ransom as a “solution” to the failings that made the attack both possible and consequential in the first place. You are paying an extra fee for not testing your own software and infrastructure. It was instead tested by a third party. Be glad it wasn't tested by a nation state actor or someone who wanted to do more harm to your customers than just asking for money. Ideally th…

When you frame it like that it sounds like the thieves are doing us a favor. Except it should be heavily fined and jailable for the entire executive team and maybe the board too.

The thieves are doing us a favor.

And yes, the companies executive should be jailed.

Re: Instructure pays ransom to Canvas hackers

#236

Earlier quoted context omitted.

When you frame it like that it sounds like the thieves are doing us a favor. Except it should be heavily fined and jailable for the entire executive team and maybe the board too.

The thieves are doing us a favor. And yes, the companies executive should be jailed.

Except those payments are being passed through, are they not?

Re: Instructure pays ransom to Canvas hackers

#237

Earlier quoted context omitted.

Was it really a problem? Yes, voluntary release of that info by a school would normally likely be a FERPA violation, but this was a criminal act against a third party. Infrastructure’s motivations must have lain elsewhere…

Does that really shield the schools? HIPAA wouldn't care.

educational LMS should not store real patient health data, so thats the problem of whoever designed that system.

Re: Instructure pays ransom to Canvas hackers

#238

Earlier quoted context omitted.

The thieves are doing us a favor. And yes, the companies executive should be jailed.

Except those payments are being passed through, are they not?

Passed through where and how?

Re: Instructure pays ransom to Canvas hackers

#239

Earlier quoted context omitted.

Does that really shield the schools? HIPAA wouldn't care.

educational LMS should not store real patient health data, so thats the problem of whoever designed that system.

The question was whether the same transitive responsibility applies to FERPA, not whether HIPAA data is involved.
Post reply on HN