Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

241–250 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#241

Earlier quoted context omitted.

How does everyone know its ShinyHunters and not someone pretending? I imagine they have some mechanism to authenticate, I'm curious what it is.

Because ShinyHunters published they hacked Canvas on their own website. They also redirected the canvas login pages to a ShinyHunters message, whilst this could be done by another group/person, its unlikely. You can also validate PGP keys and TOX accounts, etc via their website.

OK, I didn't realize they had a stable website all this time. I guess it's all out there in the open with these groups.

Re: Instructure pays ransom to Canvas hackers

#242

Earlier quoted context omitted.

Passed through where and how?

Canvas to schools to tax payers

Ah yep, well they might pass on as much of the cost as they can to their customers, but it still costs them in lost customers/prestige etc.

Re: Instructure pays ransom to Canvas hackers

#244

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

[deleted]

Re: Instructure pays ransom to Canvas hackers

#245
post #16

Earlier quoted context omitted.

If the bad guys get paid and release the info anyway, they not only make it less likely they'll get paid in the future, they make it less likely anyone will get paid in the future. Even other bad guys have an incentive to stop these bad guys from leaking the info after getting paid.

Why not wait a week and take the site down and ransom them again?

for the same reasons?

Re: Instructure pays ransom to Canvas hackers

#246

Years ago I attended a conference that had a "fireside chat" with a DoJ official on the topic of these types of ransom payments. He framed the issue as being similar to kidnapping ransoms: When an American is taken hostage each family is inclined to make payment but it fosters an industry around kidnapping Americans. Congress put a stop to it by making it illegal to pay the kidnappers. The industry shifted by ceasing…

This is doubtful.

Americans are more kidnapped globally when we look at a equal distribution of population (i.e. in the same pool in a generic country, Americans are more likely to be kidnapped (according to the James Foley Foundation).

Europeans are more likely targets in Africa due to our presence there (mostly NGOs).

The differences will be statistical, not motivated by a no-pay policy.

Re: Instructure pays ransom to Canvas hackers

#247
post #88

Earlier quoted context omitted.

How does that work? I.e. say a kidnapping occurs and the ransom is paid. What kind of trouble does the paying party get into? A fine? Jail?

So long as the potential payer knows they will get something they are going to slow down. They might pay, but suddenly becomes harder because they have to hide what they are doing. Many won't figure out how to pay. The real value though is enough people consider themselves honest and won't do anything they know is illegal. They already hate dealing with criminals, but so long as paying is legal they might do it, but…

I understand the mechanism and the point of making it illegal, that’s not the question.

What I want to know is what exactly are the lawful repercussions for the person who paid.

Re: Instructure pays ransom to Canvas hackers

#248

I wonder if, longer term, we're better off if a company like this were in some way destroyed as a result of getting hacked and paying a bribe. I think the stakes for getting hacked are far too low, especially at higher levels of management/executive where it's this abstract thing that has concrete time/resource costs.

Probably, but without government regulation to make ruinous fines for allowing your data to be breached, the thought experiment is moot.

Re: Instructure pays ransom to Canvas hackers

#249

Earlier quoted context omitted.

Backups were not Instructure’s problem. Hackers using the threat of exposing private information to extort Instructure’s customers was the problem.

Equifax and other companies routinely leak customers PII and financial information. the only outcome I got from their incidents is 1 year free "identity protection service" which I didnt use. Should be a lesson for Instructure to have proper architecture and do not store PII they dont need in their processes.

At least those are mainly going to be adults. In the case of Instructure, there are many K12 school districts using Canvas as well. They are potentially selling lists of underage children along with where they live, and contact info like email and phone number.

These are going to be people with clean credit histories to exploit, and ideal for using as ghost students.

Re: Instructure pays ransom to Canvas hackers

#250
Stop funding cyberterrorism.

>the deal means that the hackers have returned the compromised data of some 275 million users across more than 8,800 institutions.

Yea sure, they didn't keep the copy of stolen database. You know, criminals are very trustworthy people.

Post reply on HN