Live data from Hacker News

Instructure pays ransom to Canvas hackers

insidehighered.com

91–100 of 257 posts

Re: Instructure pays ransom to Canvas hackers

#91
I wonder if, longer term, we're better off if a company like this were in some way destroyed as a result of getting hacked and paying a bribe.

I think the stakes for getting hacked are far too low, especially at higher levels of management/executive where it's this abstract thing that has concrete time/resource costs.

Re: Instructure pays ransom to Canvas hackers

#92

Earlier quoted context omitted.

This is always the game theory of ransoms, and it is a classic example of a collective action problem (and is a form of a prisoner's dilemma). Each individual company is probably better off paying the ransom, but everyone would be better off if no one paid a ransom. This is why the United States, for example, has an official no-ransom policy, and why other no-ransom policies exist. You have to have something forcing…

There’s a similar dynamic from within the hacker group itself. For the ransom group, it is better for them to be perceived as trustworthy. Pay the ransom and we won’t leak your data. For any individual within the ransom group, they can get a big payout by selling the data.

> For the ransom group, it is better for them to be perceived as trustworthy.

They've already proved themselves to be untrustworthy simply by ransoming you in the first place.

Re: Instructure pays ransom to Canvas hackers

#93
post #87

Earlier quoted context omitted.

Backups do nothing to protect your customers from getting extorted to avoid their data being leaked.

What extortable content should schools be creating? And if they are it's crazy that they are trusting it to school SaaS.

I mean, something as simple as name + grades is extortable. There are plenty of students who would not want their bad grades to be public information, and who would be upset with their school if the school allowed that to be leaked, or who may personally pay an extortion if contacted directly.

I certainly do think it's crazy that schools are selling out education to SaaSification, but that is normal in the world we live in.

Re: Instructure pays ransom to Canvas hackers

#94

Earlier quoted context omitted.

So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?

Yes, particularly if they are transparent about it.

Yeah, sorry. I don't believe you :)

Re: Instructure pays ransom to Canvas hackers

#95
post #87

Earlier quoted context omitted.

Backups do nothing to protect your customers from getting extorted to avoid their data being leaked.

What extortable content should schools be creating? And if they are it's crazy that they are trusting it to school SaaS.

Enrollment or courses might not be generally super sensible, but financing/financial data, personal identification like phone numbers and emails, chat logs and such

Re: Instructure pays ransom to Canvas hackers

#97
post #65

> We received digital confirmation of data destruction (shred logs). This is shockingly naive

What's to say they didn't copy the data then shred a copy, or hell even just fabricate some shred logs.

In the abstract, it’s hilarious to imagine the hackers keeping the data, then some time from now leaking it accidentally (or another hacker group hacks them) then them having to issue a public apology for not having kept the stolen data secure and having lied about shredding it.

Re: Instructure pays ransom to Canvas hackers

#99

A good infotech public service project would be to maintain a public list of organizations that have succumbed to ransom demands, so that we can choose to take our business elsewhere. It would also be an act of bravery though in the face of potential liability for libel. I doubt disclaimers would evade much of that.

So you would rather take your business to somewhere that got hacked, didn't pay the ransom, and got customer data leaked?

Theoretically, if it happened before and the ransom wasn’t paid, there’s both an incentive by the service to improve their security practices and a disincentive on the hackers to target that business.

Re: Instructure pays ransom to Canvas hackers

#100
post #72

Earlier quoted context omitted.

A large percentage of hacking groups are state sponsored Russians. That seal response would be starting WW3 over some pii. Protecting pii is important, but it's not that important

we started the pretext to WW3 over someone wanting to move the focus of attention, so it's really not that much of a stretch.

Man, I don’t remember Putin wanting to move the focus of attention that bad.
Post reply on HN