Live data from Hacker News

Illinois college, hit by ransomware attack, to shut down

nbcnews.com

81–89 of 89 posts

Re: Illinois college, hit by ransomware attack, to shut down

#81
post #54

My thoughts immediately went to a hypothetical ethical question. Suppose that a ransomware threat actor saw the NBC story, felt bad that this happened to Lincoln, and offered to make (anonymously) the "transformational donation" mentioned in the story, while making clear that the source of funds was ransom received from other victims. Should Lincoln accept the money? (In other words, there's a yin and yang situation…

Rephrased more generally, is it ethical to accept donations arising from criminal enterprises? I think most people would say that the answer is no. This topic has been widely discussed on HN with regards to the MIT Media lab accepting money from Epstein.

Agreed! It demonstrates how dramatically the answer changes depending on exactly how you ask the question. Suppose Lincoln could get $50 million (with those funds ultimately sourced from a criminal enterprise) in each of four different scenarios. I asked 8 people locally and here's how many would take the money.

(A) The government tracks down the ransomware guy, seizes his assets, and decides that $50 million is Lincoln's fair share to reimburse Lincoln's losses (8 of 8 would take the money).

(B) Lincoln tracks down the ransomware guy, takes him to court, and wins a civil judgment of $50 million (8 of 8 would take the money).

(C) Lincoln tracks down the ransomware guy, their lawyers show proof of Lincoln's losses and how much they could potentially win in a civil trial, and the parties agree to a $50 million out-of-court settlement (7 of 8 would take the money).

(D) A ransomware criminal proactively contacts Lincoln, the criminal won't comment on whether he had any role in harming Lincoln (and Lincoln doesn't know either), but the criminal offers to donate $50 million to Lincoln anyway (2 of 8 would take the money).

Re: Illinois college, hit by ransomware attack, to shut down

#83
post #14

Hey, I actually have experience with that school! I did some consulting with them about a decade ago. The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down. The actual reasons: (a) They filled a niche that didn't need to be filled anymore. They used to absorb students from other local universities (ISU, UIS, UIUC). Those schools have realized the…

I totally buy that it wasn't the only reason but it is a possibility that an already fragile institution would be brought down by such an attack, if not this one then some other one. Some constructs are on the edge and kicking them may cause them to collapse. It probably will only change the timing but it is still the kick that is the first order cause of the collapse. Plenty of institutions are being hit with a perf…

No post body was provided.

Re: Illinois college, hit by ransomware attack, to shut down

#84
post #61
post #37

Earlier quoted context omitted.

Large purchase, most customers choose one and leave the market, many possible consumers, seasonal. Residential solar or real estate agents? The crazy thing to me about higher ed is that there's large loans and everybody qualifies. We'd probably get a better skills/job match by including the major in interest rate calculations.

> We'd probably get a better skills/job match by including the major in interest rate calculations. This brings up the hairy issue that all education should not be focused on eventual income generation. We still need our English, History, and other majors out there in the real world even if we don't expect them to make a great ROI on their degrees. Their contributions to society are still worthwhile. I think a policy…

> This brings up the hairy issue that all education should not be focused on eventual income generation.

Why would anyone in the middle or lower income class spend money on a college degree that was not geared toward increasing their income?

There is a reason that journalism graduates predominantly come from wealthy families.

Re: Illinois college, hit by ransomware attack, to shut down

#85
post #67

Earlier quoted context omitted.

Don't assume loans are that simple. Everyone assumes they're that simple. They're deadly, it's the compound interest, the intrinsically runaway loan, the situation Hell is based on. It leads to gambling and prostitution for example. All sins.

> It leads to gambling and prostitution for example. That took a wild turn. Does allowing ice fishing on Lake Michigan also lead to prostitution?

[dead]

Re: Illinois college, hit by ransomware attack, to shut down

#86
post #61

Earlier quoted context omitted.

> We'd probably get a better skills/job match by including the major in interest rate calculations. This brings up the hairy issue that all education should not be focused on eventual income generation. We still need our English, History, and other majors out there in the real world even if we don't expect them to make a great ROI on their degrees. Their contributions to society are still worthwhile. I think a policy…

> This brings up the hairy issue that all education should not be focused on eventual income generation. Why would anyone in the middle or lower income class spend money on a college degree that was not geared toward increasing their income? There is a reason that journalism graduates predominantly come from wealthy families.

There are legions of starving artists that are probably better qualified to answer that than me :)

Re: Illinois college, hit by ransomware attack, to shut down

#87
> The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down.

I wrote a Blackmirror fanart script based on Hackers using Ransomware to threaten Universities to write down student debt, I got to Act II before I left it. I want to spend more time writing this year, but so far I have spent way too much time on HN than creative writing and that is unfortunate.

> For context, I worked with them on enrollment management and declining enrollment a decade ago.

What measures did they take? And what expertise cold you lend them to counter this?

Re: Illinois college, hit by ransomware attack, to shut down

#88
post #17

Earlier quoted context omitted.

The problem is that much (not all) the business important data is involved the public internet. Take this school for example - prospective students applied online. One could imagine sneaker-netting the application data to an airgapped network, but that introduces its own costs and risks. Email (or other messages systems like slack) are one of primary tools of business, facilitating communication within an organizatio…

I totally get it, but the internet hasn't been around that long. How did we handle this 30 years ago? I imagine students applied via snail mail, and then someone manually entered the information into a database. There's no reason to go back to paper applications, and that database should absolutely be digital—but I think we could do a lot more manual entry.

25 years ago: carefully hand-write half-page essays on pre-printed application forms, attach $50 checks for application fees, beg your mother to drive your procrastinating self to the downtown post office by 5pm on December 31.

Start receiving long-awaited envelopes around Spring Break, and speculate on whether said envelopes were thin because they contained simple rejection letters, or because the desired financial aid details would follow the next week.

Re: Illinois college, hit by ransomware attack, to shut down

#89

We were looking at "cyber insurance" for our college and found out that we would be disqualified because every network connected device (even those on isolated networks) needs to have 2FA. Well, we have a network connected CNC machine at it has no provision for it. Another institution has the same machine and was denied. They tried every a lot of gyrations but got nowhere. Even a previous security audit would not hel…

> We were looking at "cyber insurance" for our college and found out that we would be disqualified because every network connected device (even those on isolated networks) needs to have 2FA. Well, we have a network connected CNC machine at it has no provision for it. How enforceable is this? Why could you not just leave that machine out of your inventory?

Well, if something goes wrong and we do an insurance claim, they would take a look and not pay our claim. I am not quite good enough to hide the CNC machine. Ask any homeowner how good these folks are at avoiding paying claims.
Post reply on HN