Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Instructure, the company that operates Canvas, has confirmed that it addressed the incident directly.

Instructure, the company that operates Canvas, has confirmed that it addressed the incident directly.

Scheduled Pinned Locked Moved Uncategorized
26 Posts 16 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • cr0w@infosec.exchangeC cr0w@infosec.exchange

    Instructure, the company that operates Canvas, has confirmed that it addressed the incident directly. Based on the information they have shared, the data involved was returned to Instructure. They also received assurances that the data will not be further shared and confirmation that any copies were deleted. Instructure has stated that no schools or districts will be extorted as a result of this incident.

    r0k@mastodon.socialR This user is from outside of this forum
    r0k@mastodon.socialR This user is from outside of this forum
    r0k@mastodon.social
    wrote last edited by
    #3

    @cR0w oh ffs... they paid a ransom?

    pa@hachyderm.ioP remywhisker@mastodon.socialR 2 Replies Last reply
    0
    • h2onolan@infosec.exchangeH h2onolan@infosec.exchange

      @cR0w how many assurances to equal one asshole?

      cr0w@infosec.exchangeC This user is from outside of this forum
      cr0w@infosec.exchangeC This user is from outside of this forum
      cr0w@infosec.exchange
      wrote last edited by
      #4

      @h2onolan Imagine the mindset that's satisfied with that assurance. What an enjoyable way to live as an individual.

      h2onolan@infosec.exchangeH 1 Reply Last reply
      0
      • cr0w@infosec.exchangeC cr0w@infosec.exchange

        @h2onolan Imagine the mindset that's satisfied with that assurance. What an enjoyable way to live as an individual.

        h2onolan@infosec.exchangeH This user is from outside of this forum
        h2onolan@infosec.exchangeH This user is from outside of this forum
        h2onolan@infosec.exchange
        wrote last edited by
        #5

        @cR0w “when we said criminal earlier, that was a regrettable mistake. What we meant was partner. A trustworty professional partner who knows where my kids go to school and where the nursing home my mom lives is located”

        cr0w@infosec.exchangeC 1 Reply Last reply
        0
        • h2onolan@infosec.exchangeH h2onolan@infosec.exchange

          @cR0w “when we said criminal earlier, that was a regrettable mistake. What we meant was partner. A trustworty professional partner who knows where my kids go to school and where the nursing home my mom lives is located”

          cr0w@infosec.exchangeC This user is from outside of this forum
          cr0w@infosec.exchangeC This user is from outside of this forum
          cr0w@infosec.exchange
          wrote last edited by
          #6

          @h2onolan you think people would do that dot png

          1 Reply Last reply
          0
          • r0k@mastodon.socialR r0k@mastodon.social

            @cR0w oh ffs... they paid a ransom?

            pa@hachyderm.ioP This user is from outside of this forum
            pa@hachyderm.ioP This user is from outside of this forum
            pa@hachyderm.io
            wrote last edited by
            #7

            @r0k Looks like it! Or maybe... they sent a really nice bouquet of flowers and it convinced SH to "assure" Canvas "the data will not be further shared and confirmation that any copies were deleted...?" 🤣 🤣 🤣 🎣
            @cR0w

            r0k@mastodon.socialR 1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              Instructure, the company that operates Canvas, has confirmed that it addressed the incident directly. Based on the information they have shared, the data involved was returned to Instructure. They also received assurances that the data will not be further shared and confirmation that any copies were deleted. Instructure has stated that no schools or districts will be extorted as a result of this incident.

              rossmadness@infosec.exchangeR This user is from outside of this forum
              rossmadness@infosec.exchangeR This user is from outside of this forum
              rossmadness@infosec.exchange
              wrote last edited by
              #8

              @cR0w I'll never understand this logic. "How do you know the morally bankrupt cybercriminals actually got rid of your data?"

              "They gave us a receipt."

              Yeah...sure...

              ph_0x05@infosec.exchangeP rotopenguin@mastodon.socialR nyanbinary@infosec.exchangeN fuzzyfuzzyfungus@cyberplace.socialF 4 Replies Last reply
              0
              • pa@hachyderm.ioP pa@hachyderm.io

                @r0k Looks like it! Or maybe... they sent a really nice bouquet of flowers and it convinced SH to "assure" Canvas "the data will not be further shared and confirmation that any copies were deleted...?" 🤣 🤣 🤣 🎣
                @cR0w

                r0k@mastodon.socialR This user is from outside of this forum
                r0k@mastodon.socialR This user is from outside of this forum
                r0k@mastodon.social
                wrote last edited by
                #9

                @pa @cR0w those honorable criminals, always keeping their word... so adorable

                cr0w@infosec.exchangeC 1 Reply Last reply
                0
                • r0k@mastodon.socialR r0k@mastodon.social

                  @pa @cR0w those honorable criminals, always keeping their word... so adorable

                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchange
                  wrote last edited by
                  #10

                  @r0k @pa giggles in LockBit

                  1 Reply Last reply
                  0
                  • rossmadness@infosec.exchangeR rossmadness@infosec.exchange

                    @cR0w I'll never understand this logic. "How do you know the morally bankrupt cybercriminals actually got rid of your data?"

                    "They gave us a receipt."

                    Yeah...sure...

                    ph_0x05@infosec.exchangeP This user is from outside of this forum
                    ph_0x05@infosec.exchangeP This user is from outside of this forum
                    ph_0x05@infosec.exchange
                    wrote last edited by
                    #11

                    @rossmadness @cR0w it's never not amusing whenever i read about a big organisations suddenly becoming naive when dealing with morally bankrupt people.

                    As though as they somehow managed to get to become a multi-million company by just a bunch of "trust us bro"

                    1 Reply Last reply
                    0
                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                      Instructure, the company that operates Canvas, has confirmed that it addressed the incident directly. Based on the information they have shared, the data involved was returned to Instructure. They also received assurances that the data will not be further shared and confirmation that any copies were deleted. Instructure has stated that no schools or districts will be extorted as a result of this incident.

                      phil@fed.bajsicki.comP This user is from outside of this forum
                      phil@fed.bajsicki.comP This user is from outside of this forum
                      phil@fed.bajsicki.com
                      wrote last edited by
                      #12

                      @cR0w@infosec.exchange So... Instructure will be on the hook if it does happen? I'm not sure how exactly this works on the legal side.

                      cr0w@infosec.exchangeC 1 Reply Last reply
                      0
                      • rossmadness@infosec.exchangeR rossmadness@infosec.exchange

                        @cR0w I'll never understand this logic. "How do you know the morally bankrupt cybercriminals actually got rid of your data?"

                        "They gave us a receipt."

                        Yeah...sure...

                        rotopenguin@mastodon.socialR This user is from outside of this forum
                        rotopenguin@mastodon.socialR This user is from outside of this forum
                        rotopenguin@mastodon.social
                        wrote last edited by
                        #13

                        @rossmadness @cR0w hold onto that receipt, it's a deductible business expense

                        1 Reply Last reply
                        0
                        • rossmadness@infosec.exchangeR rossmadness@infosec.exchange

                          @cR0w I'll never understand this logic. "How do you know the morally bankrupt cybercriminals actually got rid of your data?"

                          "They gave us a receipt."

                          Yeah...sure...

                          nyanbinary@infosec.exchangeN This user is from outside of this forum
                          nyanbinary@infosec.exchangeN This user is from outside of this forum
                          nyanbinary@infosec.exchange
                          wrote last edited by
                          #14

                          @rossmadness @cR0w but but but... their business relies on being trustworthy! They need to, otherwise the industry suffers! And no one would ever act against their industries interest! All the cybertalkingheads told me!!!

                          rossmadness@infosec.exchangeR 1 Reply Last reply
                          0
                          • cr0w@infosec.exchangeC cr0w@infosec.exchange

                            Instructure, the company that operates Canvas, has confirmed that it addressed the incident directly. Based on the information they have shared, the data involved was returned to Instructure. They also received assurances that the data will not be further shared and confirmation that any copies were deleted. Instructure has stated that no schools or districts will be extorted as a result of this incident.

                            tati@eldritch.cafeT This user is from outside of this forum
                            tati@eldritch.cafeT This user is from outside of this forum
                            tati@eldritch.cafe
                            wrote last edited by
                            #15

                            @cR0w the terminator : 'i'll be back'

                            actually, wait, i'm still here

                            (brain: s/Free-for-T/hot for t/g)

                            #instructure #canvas

                            Link Preview Image
                            pa@hachyderm.ioP mccovican@infosec.exchangeM fritzadalis@infosec.exchangeF 3 Replies Last reply
                            0
                            • r0k@mastodon.socialR r0k@mastodon.social

                              @cR0w oh ffs... they paid a ransom?

                              remywhisker@mastodon.socialR This user is from outside of this forum
                              remywhisker@mastodon.socialR This user is from outside of this forum
                              remywhisker@mastodon.social
                              wrote last edited by
                              #16

                              @r0k @cR0w I doubt it. They probably just said they did. They just shift blame if anything or anyone contradicts their narrative.

                              1 Reply Last reply
                              0
                              • rossmadness@infosec.exchangeR rossmadness@infosec.exchange

                                @cR0w I'll never understand this logic. "How do you know the morally bankrupt cybercriminals actually got rid of your data?"

                                "They gave us a receipt."

                                Yeah...sure...

                                fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                fuzzyfuzzyfungus@cyberplace.social
                                wrote last edited by
                                #17

                                @rossmadness @cR0w It turns out that seeing a way to pretend to solve your problem by spending other people's money and letting other people bear the ongoing risk just gives you a warm feeling of childish trust.

                                Plus, when you are lawful evil seeing chaotic evil probably just reminds you of your carefree younger days; when you would have been frolicking on the intertubes not being a saashole who has to do earnings calls.

                                1 Reply Last reply
                                0
                                • phil@fed.bajsicki.comP phil@fed.bajsicki.com

                                  @cR0w@infosec.exchange So... Instructure will be on the hook if it does happen? I'm not sure how exactly this works on the legal side.

                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchange
                                  wrote last edited by
                                  #18

                                  @phil IDK how it works either but I highly doubt they will be held responsible.

                                  phil@fed.bajsicki.comP 1 Reply Last reply
                                  0
                                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                    @phil IDK how it works either but I highly doubt they will be held responsible.

                                    phil@fed.bajsicki.comP This user is from outside of this forum
                                    phil@fed.bajsicki.comP This user is from outside of this forum
                                    phil@fed.bajsicki.com
                                    wrote last edited by
                                    #19

                                    @cR0w@infosec.exchange Sad. There is a definite deficit of accountability.

                                    cr0w@infosec.exchangeC 1 Reply Last reply
                                    0
                                    • tati@eldritch.cafeT tati@eldritch.cafe

                                      @cR0w the terminator : 'i'll be back'

                                      actually, wait, i'm still here

                                      (brain: s/Free-for-T/hot for t/g)

                                      #instructure #canvas

                                      Link Preview Image
                                      pa@hachyderm.ioP This user is from outside of this forum
                                      pa@hachyderm.ioP This user is from outside of this forum
                                      pa@hachyderm.io
                                      wrote last edited by
                                      #20

                                      @tati @cR0w Oh that's nice to know! So I suppose Paid-for-Teachers can be leveraged instead now?

                                      1 Reply Last reply
                                      0
                                      • phil@fed.bajsicki.comP phil@fed.bajsicki.com

                                        @cR0w@infosec.exchange Sad. There is a definite deficit of accountability.

                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchange
                                        wrote last edited by
                                        #21

                                        @phil Isn't that the whole point of becoming a publicly traded company in America? It sure seems that way.

                                        1 Reply Last reply
                                        0
                                        • nyanbinary@infosec.exchangeN nyanbinary@infosec.exchange

                                          @rossmadness @cR0w but but but... their business relies on being trustworthy! They need to, otherwise the industry suffers! And no one would ever act against their industries interest! All the cybertalkingheads told me!!!

                                          rossmadness@infosec.exchangeR This user is from outside of this forum
                                          rossmadness@infosec.exchangeR This user is from outside of this forum
                                          rossmadness@infosec.exchange
                                          wrote last edited by
                                          #22

                                          @nyanbinary @cR0w I was discussing the Instructure hack with a friend who works for a school district and he stated that almost exactly. I told him that yes, that makes sense if we believe they care about "organization reputation" in the same economic incentive driven context as a regular business. Which I highly doubt. But let's assume they do follow this logic.

                                          What keeps them from selling a copy quietly to another criminal and then THAT criminal actions the data somewhere else without directly saying "Instructure". TAs double dip and keep their "reputation" intact.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups