Live data from Hacker News

Canvas online again as ShinyHunters threatens to leak schools’ data

theverge.com

91–100 of 690 posts

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#91

I remember circa 2010 a friend of mine at college was like “blackboard sucks, let’s build something new”. At the time I poo pood the idea and lo and behold canvas came out a year later. Outside looking in, they been crushing it.

As someone who has used both as a student and a TA I find blackboard miles better, much easier to find what i'm looking for and my professors seem to have better luck laying out their course on blackboard than canvas.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#92
post #74

My wife is in grad school at a major university and is dealing with this right now the week of midterms for spring quarter. I totally understand why a university wouldn’t want to bake their own learning portals but just feels like such a single point of risk to use third party solutions for something like this. Back in my day… all we had was a school email via on-premise services. I guess we registered for classes in…

Universities used to do this sort of stuff themselves. Then it became a business handled by purchasing rather than needs met by the department themselves.

In fairness in the era where universities did it themselves the tech requirements and expectations were dramatically lower.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#93
post #74

My wife is in grad school at a major university and is dealing with this right now the week of midterms for spring quarter. I totally understand why a university wouldn’t want to bake their own learning portals but just feels like such a single point of risk to use third party solutions for something like this. Back in my day… all we had was a school email via on-premise services. I guess we registered for classes in…

Universities used to do this sort of stuff themselves. Then it became a business handled by purchasing rather than needs met by the department themselves.

Because faculty didn’t want to do it anymore. They want it handled by others but also they want oversight and veto power but also they don’t want to be bothered. But it better always work, and if they make a mistake the software is broken because don’t tell them it’s a user error they used to write Fortran.

As a faculty member at a large university…I have a deep respect for the impossible job of university IT departments.

We originally rolled our on LMS decades ago. When we switched to canvas we kept the home brew running for five years past its expiration date because faculty refused to remove their files. Finally each one was manually moved by IT for the recalcitrant old faculty.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#94

I wonder when the public is going to start calling for corporate liability for malpractice in software development and corporate liability for malpractice in IT deployments. Even if the tech industry fights it, it probably won't be that much longer.

I'll never understand this point of view. If someone would please explain how to create perfectly secure software, I will gladly start writing perfectly secure software. Only after, if it's clear I ignored obviously correct advice, should there be malpractice penalties. Consider surgery instead of software development. There are general best practices, but the difference between a good surgeon and a poor one is a sma…

[deleted]

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#96
post #23

I hate Canvas. I would rather run a course on GitHub. But our university forces it on us. And now this.

Do you remember how Canvas was a gigantic improvement over Blackboard? And GitHub doesn't provide a way to record grades that remain private per student last I checked, much less sync them to the university, or 99% of other things Canvas does. I don't love Canvas, but it's far, far preferable to a world without it.

> remain private per student last I checked

last I checked it appears grades remain private per planet or so ...

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#97

What's in the files they've already released? Some of them are > 800GB.

Grades, records, etc I would assume. Someone else pointed out that they recently acquired https://www.parchment.com/ so they may have also been able to scoop up those records too

Also discussions between students and teaching staff.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#98
post #92
post #74

Earlier quoted context omitted.

Universities used to do this sort of stuff themselves. Then it became a business handled by purchasing rather than needs met by the department themselves.

In fairness in the era where universities did it themselves the tech requirements and expectations were dramatically lower.

Have these dramatically higher tech requirements and expectations improved the quality of education whatsoever?

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#99

1. It should be illegal for any company to pay ransomware attacks. Period. No pay out ever. 2. The penalty for being the attacker should be linked to the system they violated. If you do this to a hospital and someone dies you are life in prison / chair. The minimum sentence should be so painful that it deters the attack. No this will not stop this and companies need to be held accountable for their lack of security i…

Your "minimum sentence so painful" will certainly dissuade foreign nationals, even foreign governments.

Re: Canvas online again as ShinyHunters threatens to leak schools’ data

#100

So many universities used to run homegrown or on-prem student systems. This is the downside of consolidating in the cloud. If the infrastructure is compromised, it affects everyone, not just isolated or single installations. I wonder how they are feeling about that decision now? I guess they can say "not our fault" so they might be feeling better than if it was a vulnerability in their own system.

It's still more secure this way, especially with AI hacking making it harder to rely on obscurity.

Also yeah there is value in being able to blame another party, and also being down when everyone else is down.

Post reply on HN