Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

41–50 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#42

Earlier quoted context omitted.

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

While the us stance has resulted in savings on potential ransom, it has also lead to people being kept in prison for very long time until prisoner exchanges might be worked out. That cost to an individuals life being imprisoned is probably far in excess whatever the US might pay. Plus the US prints its own monopoly money and doesn’t really play by the rules of economics anyhow ever since getting off gold standard.

That ransoms today are denominated in USD and that the US might be printing too many USD has nothing to do with whether or not ransoms should be paid.

The day the USD falls, ransoms will simply be denominated in something else and the same underlying collective action problem will remain.

This is just way of avoiding the core issue by blaming something unrelated that you don't like.

A: U should clean your room, it would be better for you & the rest of your family

B: FU dad, everyone knows there's no such thing as a clean room under capitalism!!!!!

Re: Instructure pays ransom to Canvas hackers

#43

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

So, maybe we could consider a "White Hat" ransomware group that takes the money and also leaks the data, so that long term no one bothers to pay which ultimately disincentivizes ransomware attacks?

Re: Instructure pays ransom to Canvas hackers

#44

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

I'm not sure that attacker reputation is particularly meaningful. The group can rebrand into a new identity at any time. They're anonymous cybercriminals after all and there are lots of reasons they might need to do that beyond reputation laundering. The calculus for the victims doesn't seem to change much whether the same people are using a "new" name or an old one to hold their systems hostage.

The name ShinyHunters is currently quite well-known due to a number of high-profile hacks (Odido in the Netherlands this year was huge). Their brand has a significant value right now.

Re: Instructure pays ransom to Canvas hackers

#45

on one hand, every ransom paid encourages like-minded individuals to start or ramp up their ransomware game , which is not great. on the other hand, the ransomware groups that want to stay in business need to be honest (with respect to not releasing/deleting data) or they wont be 'credible' ransomware operators, which is kind of funny to think about. and in many cases, the victims would rather the ransomware operator…

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data.

For any individual within the ransom group, they can get a big payout by selling the data.

Re: Instructure pays ransom to Canvas hackers

#46

A good infotech public service project would be to maintain a public list of organizations that have succumbed to ransom demands, so that we can choose to take our business elsewhere. It would also be an act of bravery though in the face of potential liability for libel. I doubt disclaimers would evade much of that.

So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?

Both of them got hacked so... yes.

Re: Instructure pays ransom to Canvas hackers

#48

A good infotech public service project would be to maintain a public list of organizations that have succumbed to ransom demands, so that we can choose to take our business elsewhere. It would also be an act of bravery though in the face of potential liability for libel. I doubt disclaimers would evade much of that.

So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?

The customer data is already leaked, unless your threat model somehow includes trusting threat actors to keep said data confidential in perpetuity.

Re: Instructure pays ransom to Canvas hackers

#49

>The data was returned to us. It was my understanding that the data was copied[1]. You wouldn't "return" data unless it was encrypted or the originals were deleted. I am confused on this phrasing but maybe it is standard idk. This is bullish on Monero[2]. The January pump may have been from a hack as well[3]. Here is Shinyhunters website. Canvas was listed on it[4] and then removed[5]. [1] https://www.youtube.com/wat…

> You wouldn't "return" data unless it was encrypted or the originals were deleted

The very next line from what you quoted:

> We received digital confirmation of data destruction (shred logs).

Now, color me surprised if they didn't delete it, but I'm guessing this is why they call it "returned", since from their beliefs, the data was deleted after it was "returned".

Re: Instructure pays ransom to Canvas hackers

#50

What on earth does "returned the hacked personal data" mean?

I believe attacks like this often include copying data and then deleting it from the victim's servers.

Although of course returning is a weird term in the sense that the attackers will almost certainly keep the data as well.

Post reply on HN