Showing posts with label hackers. Show all posts
Showing posts with label hackers. Show all posts

Monday, May 18, 2026

The Canvas Ransomware Attack: Paint Us Insecure

  

Anyone even a little familiar with how higher education is done these days has dealt with what are called "learning management systems" (LMS for short).  Basically, an LMS is what has replaced paper homework, paper gradebooks, and in many cases, paper exams that used to be shuffled back and forth between students, graders, and faculty members. 

 

Like many other universities around the world, several years ago my university switched from the LMS they were using to something called Canvas.  Once I learned its ins and outs, it has proved to be a useful, flexible, and mostly easy-to-use tool.  I can send out emails to everyone in a particular class, I can record grades that instantly show up on students' phones, and while I don't personally use the test-administering feature, many professors do. 

 

Canvas is so good, in fact, that its parent company, a privately-held outfit called Instructure, now has a plurality of all LMS customers in the world, serving over 8,000 institutions in dozens of countries. 

 

A lot of confidential data is stored in Canvas.  For example, it turns out to be a violation of a Federal law for me to post a list of grades on my door, even if I anonymized them with Social Security numbers.  So if anybody other than the student concerned manages to find out what a person's grade is, a whole lot of people can be in trouble.

 

Last month, these facts plus a fairly behind-the-times security posture made Instructure a prime target for the loosely-organized but highly effective ransomware ring known as ShinyHunters.  These criminals are thought to be concentrated in Canada and France, and are known to have committed numerous ransomware attacks on organizations whose wide-ranging databases make them particularly juicy targets, such as Ticketmaster and AT&T.

 

According to a report on thenextweb.com and the Wikipedia website "2026 Canvas security incident," on April 30, ShinyHunters breached Instructure's security and posted a ransom note on May 3.  On May 6, Instructure, which had publicly acknowledged the breach on May 1, notified its users that everything was back to normal.

 

But according to ShinyHunters, Instructure ignored their ransom demand and simply doubled down on security measures.  In retaliation, ShinyHunters put their ransom notice on every user's webpage, prompting Instructure to pull most of the system down and replace it with an "under maintenance" notice on 8 PM May 7 Eastern Standard Time.

 

Unfortunately, this was just when a lot of schools were relying heavily on Canvas for exams, grading, and other end-of-semester activities.  I was fortunate to have my last necessary interaction of the semester with Canvas just a few hours before it crashed, but a lot of other professors and students weren't so fortunate.  Our provost sent out a notice during the outage asking toleration and understanding on the part of both students and faculty members.

 

According to Hacker News, Instructure eventually reached a ransom agreement with ShinyHunters on May 11, averting release of some 3.6 terabytes of stolen data.  Since then, Canvas has apparently been running normally, although after this experience one wonders how reliable it will be in the future.

 

The days when universities developed their own custom software for large-scale applications such as LMS are long past.  But farming out important tasks to vendors places the responsibility for security squarely on the vendor's shoulders.  And bigness, however attractive it is profit-wise, attracts the attention of hackers as well.  So we shouldn't be too surprised that an outfit like ShinyHunters picked Canvas for their next target.

 

Ransomware hackers are the modern pirates of the Internet.  During the heroic age of global exploration and trade from the 1200s AD onward to 1800 and later, the ocean became a network of trade routes over which the world's valuables flowed.  The prospect of siphoning off some of those valuables for their own purposes, or of extorting money to allow their uninhibited flow, attracted pirates such as the ones based on the Barbary Coast region of North Africa in the years leading up to and following the American Revolution.  In what was the United States' first major foreign military action, President Thomas Jefferson decided he was through with paying off the pirates, and sent the Marines in a series of expeditions that ultimately broke the stranglehold they held on U. S. maritime trade in regions they controlled.

 

Jefferson had the advantage that the pirates sailed physical ships and could be tracked back to specific ports, where plans could be made to attack them.  The power that the internet gives to put the world at your Ethernet port also makes it possible for criminals to hide literally anywhere there is an internet connection, which these days means pretty much anywhere.  Tracking them down is a costly, slow, and uncertain enterprise at best.  And as soon as some bad actors are rounded up and thrown in jail, their uncaught associates rise up to take their place.

 

It's hard to imagine a modern-day Jefferson scaring ransomware hackers enough for them to lay off an entire country.  As the ShinyHunters' actions showed, national borders mean little to them.  They were attracted to Instructure because it formed one of the largest data-holders on the planet, not because it was a particularly large or rich country. 

 

The only thing that may lead to something like what Jefferson did to the pirates of 1800 is if a particular organization goes after the hackers with determination and even a kind of vengeance.  Perhaps something along the lines of a trade organization of large data-holders could fund a multinational policing effort that would make every ransomware hacker sorry they ever messed with a company that is a member of the organization.

 

That may require international and inter-company cooperation that simply doesn't exist today.  But if the problem gets bad enough, maybe firms will overcome their reluctance to put their money and efforts together and do something truly effective.  Until then, however, outfits like Instructure can look forward to more attacks, and users will just have to deal with it. 

 

Sources:  I referred to reports at https://thenextweb.com/news/the-largest-education-data-breach-in-history-was-not-an-attack-on-a-school-it-was-an-attack-on-a-vendor, https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html, and the Wikipedia article "2026 Canvas security incident." 

Monday, April 05, 2021

In Facebook We Trust

 

Consider what may seem to be an odd comparison:  Facebook and God.  For purposes of discussion, we will compare Facebook to the traditional Judeo-Christian God of the Old and New Testaments.  And we will restrict the comparison primarily to two matters:  communication and trust (or faith).

 

Users of Facebook communicate with that entity by entering personal information into Facebook's system.  That act of communication is accompanied by a certain level of trust, or faith.  Facebook promises to safeguard one's information and not to reveal it to anyone else without your permission.  Users can set up various levels of security ranging from public (anyone can see it) to very private (only a selected list of people can see it).  In entrusting what is sometimes very personal data to Facebook, the user expects Facebook to safeguard it in accordance with Facebook's own promises.

 

According to most traditions, God will not tolerate being used.  In the book of Luke, when the Devil tempts Jesus to throw himself from the top of the temple to show that God the Father will keep him from being injured, Jesus replies, "Thou shalt not tempt (test) the Lord thy God." In throwing himself off the temple, Jesus would have been using God for the purposes of performing a stunt, and so Jesus rightly rejected the Devil's proposal.

 

But believers in God, those who trust in him, communicate with God by praying.  God has made promises regarding prayer, such as listening to those who call upon him, and in the person of Jesus, he has said such radical things as ". . . whatsoever ye shall ask in my name, that will I do, that the Father may be glorified in the Son."  So those who trust in God will certainly pray for things they want, but they also trust God that his vastly superior knowledge and insight will lead him to do things differently than our limited minds can conceive.  It is part of wisdom to ask God for things we want, but not to tell him how to get them done.

 

What do Facebook users expect from their communications with Facebook?  Well, nobody I know puts stuff on Facebook simply for the pleasure of seeing it show up there.  The hope is that other people will see it and react in some way that one hopes is personally gratifying, or at least useful.  (I'm ignoring the commercial and institutional uses of Facebook for the moment, and concentrating on the personal user only.)  And by and large, most Facebook users see that happen enough to keep them using it, although most people I know who have used Facebook have sworn off it for a while at least once, usually during election season.

 

How about the trust angle of Facebook?  Yesterday (Saturday, Apr. 3), a hacker published a list of some 500 million phone numbers and other personal data scraped from Facebook.  News reports say that anyone with rudimentary data skills can access this list.  Facebook says that the list was obtained through a fault that they patched back in 2019, and the data is two years old.  Still, not a lot has changed in the lives of many of those people since 2019, and the result is that everyone whose data is on that list has another increment of concern to add to the dangers of online existence. 

 

For most people, this particular breach will not have serious consequences, except to underline the fact that what Facebook promises and what Facebook delivers are two different things.  This is not a surprise to some Australians who used Facebook to share news items until Facebook decided last February that they couldn't, as a move in response to a proposal by the Australian government to make Facebook pay for news items it puts on its own platforms. 

 

Both God and Facebook share the characteristic of inscrutability.  One never knows quite what either entity is going to do.  The believer explains that God is inscrutable to us because God knows everything and we don't.  The Facebook user explains Facebook's inscrutability because Facebook is a large, physically distributed organization whose inner workings and leading personalities are obscured from the general public, and even governments have a hard time figuring out what Facebook is up to. 

 

The comparison breaks down completely when we ask about the moral character of each entity.  By definition, God is the ultimate perfection of every virtue:  all-wise, all-knowing, and all-loving.  Facebook, on the other hand, is composed of fallible human beings, and exists primarily to make money, while staying enough within the law to operate profitably in the various jurisdictions around the world where it has a presence, which is essentially everywhere on earth.  To expect perfection from Facebook, or any other human organization, is to set oneself up for disappointment.

 

So while my sympathy goes out to everyone who uses Facebook (including my wife, who called my attention to this matter) and is now that much more concerned that their use will lead to unintended negative consequences, I can't say that I'm very surprised.  Facebook data represents such a juicy target to hackers that occasional breaches are well-nigh inevitable.  Facebook spends enough money on data security to ensure that whatever breaches occur are infrequent enough not to scare most of its users away, and spending a lot more than that would probably cut into their profits severely.  The only way to make Facebook perfectly unhackable would be if it had no users at all, and that's not going to happen any time soon.

 

It may seem that I've taken 900 words to say only that Facebook isn't God.  But even the obvious bears repeating every now and then.  If we listen only to what social media organizations tell us about themselves, it is tempting to attribute God-like qualities to them:  omniscience and omnipotence, for example.  And when they inevitably mess up, such as with the latest data breach, we rightly feel a sense of betrayal.  But the Psalmist advises us to "put not your trust in princes," even princes named Zuckerberg.  And that advice is still good today.

 

Sources:  Business Insider carried a story about the Facebook phone-number data breach at https://www.businessinsider.com/stolen-data-of-533-million-facebook-users-leaked-online-2021-4.  The story of Jesus's temptation by the Devil is in Luke 4, and Psalm 146:3 advises us not to trust princes. 

Monday, August 21, 2017

Cyber Command Gets a Promotion


On Friday, Aug. 18, President Trump announced that the Defense Department's U. S. Cyber Command would be elevated to the status of a "unified combatant command," joining the nine other commands such as the U. S. Central Command (CENTCOM) that oversees all military operations in the Middle East, and the U. S. Strategic Command in charge of nuclear weapons.  The heads of these commands are just below the Secretary of Defense in the chain of command, and each unified combatant command cuts across the traditional armed-services divisions of army, navy, and air force. 

According to a report at the website Politico, the promotion of the Cyber Command has been in the works for years, but carrying out this promotion is in line with the President's campaign promises to bolster the Cyber Command.  Currently that Command is headed by Admiral Mike Rogers, who also heads the National Security Administration (NSA).  The Senate must confirm a new Cyber Command leader before the reorganization is fully implemented, but no particular problems are expected on that score.

After taking an initial leadership position, the U. S. has appeared lately to be lagging in the recognition that cyberwarfare is no longer some science-fiction pipe dream.  The nature of cyberwarfare makes it difficult to state with certainty exactly who is responsible for what.  But most experts agree that, for example, Russia has been plaguing the Ukraine with cyberattacks of many kinds for the last few years, ranging from invading servers used by news media to causing widespread power blackouts in large cities such as Kiev in the middle of the winter.

Probably the first cyberattack that became widely known and has definite attribution was called Stuxnet.  Developed by the U. S. NSA, possibly with cooperation from Israel, it was a clever attack on Iran's uranium centrifuges in 2010 that caused numbers of them to self-destruct.  Stuxnet was the last major focused cyberattack we know of that the U. S. has committed, but by the nature of the business, there may be others we don't know about yet. 

In conventional warfare, the enemy is in a clearly defined geographical area, and even wears uniforms and puts insignia on their equipment so you can tell who are the good guys and who are the bad guys.  Alas, such formality is long gone in many battlefields, and in the anonymous world of cyberspace it is next to impossible to identify the source of an attack in terms of a physical location and which people are doing the bad stuff.  In this regard cyberwarfare borrows from the world of espionage the mysteries and guesswork that makes spy novels so interesting, and makes actual espionage work so frustrating. 

But just because the enemy can't always be clearly identified, that doesn't mean we can ignore what they can do.  There is an old saying that generals always prepare to fight the last war, meaning that military thinkers are slow to deal with combat innovations.  The elevation of the Cyber Command to a level equal to the Strategic Command says that, organizationally at least, we are taking the threat of cyberattacks and the damage they could cause at least as seriously as we are taking the threat of nuclear attacks, which are far less likely but have a higher potential for damage.

Or maybe not.  At any given time, there is probably a maximum amount of damage that a determined cyberattacker could do with the capabilities they have and the nature of the target.  One advantage that the U. S. has compared to smaller and more tightly organized countries is that we have a lot of diversity in our technical infrastructure.  For example, in the recent flap about Russia's attempt to sway U. S. elections, no one has found any convincing evidence that Russian hackers were able to manipulate electronic vote counting.  Even if they had wanted to, the hackers face the difficulty that votes are counted in literally thousands of different jurisdictions using a wide variety of systems.  Anybody wanting to mess with a voting district that was big enough to make a difference would probably have to have a spy physically present for some time in order to gather enough information to give a cyberattack even a chance of success.  Something of the same principle applies to our electric grid, which is a congeries of old and new technology with a bewildering variety of SCADA (supervisory, control, and data acquisition) systems.  Again, a determined cyberattacker would have to focus on one system that is particularly vulnerable and large enough to make a terrorist attack worthwhile in terms of headlines.

Despite these built-in defenses, the U. S. should not be complacent with regard to the possibility of a crippling cyberattack, and the promotion of the U. S. Cyber Command to the board of Unified Combatant Commands is a step in the right direction.  As I mentioned not long ago in a blog on ransomware, one of the U. S. government's primary responsibilities is to defend the nation against attacks, and this includes cyberattacks.  The spectacle of private companies, even small ones, getting held up for ransom by hackers is morally equivalent to a cross-border raid by physical invaders.  What would normally be a domestic police matter then becomes an international incident, and the intervention of the U. S. military would be appropriate in both cases.

But a lot is yet to be defined about the responsibilities of the military on the defense side.  Historically, the computer industry has held consumers responsible for cybersecurity to the extent of installing patches and upgrades promptly and following good cybersecurity "hygiene."  But as attacks become more sophisticated, there may have to be closer cooperation among private technology developers, their customers, and the military, which up to now has not had much input into the business except as a good customer. 

If history is any precedent, not much will change in a major way until a foreign cyberattack succeeds with a truly crippling blow that costs many billions of dollars, affects millions of people, or results in multiple deaths and injuries.  Then we will get serious about how the military can fight the next war—a cyberwar—and not the last one.

Sources:  Politico.com carried a story entitled " Trump elevates U.S. Cyber Command, vows 'increased resolve' against threats" on Aug. 18, 2017 at http://www.politico.com/story/2017/08/18/trump-us-cyber-command-elevated-unified-combatant-command-241783.  I referred to an article in Wired Magazine published June 20, 2017 at https://www.wired.com/story/russian-hackers-attack-ukraine/ and the Wikipedia article on Unified Combatant Command.  My blog on ransomware appeared on Mar. 27, 2017 at http://engineeringethicsblog.blogspot.com/2017/03/ransomware-comes-to-heartland.html.

Monday, December 01, 2014

Will Remote Car Hacking Stop Before It Starts?


The bomb exploded as the car reached the intersection of Park Place and Forest Park Boulevard in Fort Worth, Texas.  The explosion was loud enough to be heard at an elementary school a couple of blocks away, and I was one of several students who got to the scene before emergency crews had cleaned it up.  From the front doors rearward the car looked nearly normal, but there was just a blackened pile of junk where the front end used to be.  The driver was killed instantly.  From what I recall, later investigation of this mid-1960s incident turned up ties to organized crime, and I'm not sure but what the criminals put the bomb in the wrong car.  Even the Mafia makes mistakes.

To commit that crime, someone had to make a powerful time bomb and gain physical access to the car in order to plant it.  In the near future, it will be logically possible to wreck a car and kill the driver without ever laying a finger on either one.  Once wireless networking and Bluetooth communications are integrated in new models of automobiles, a sufficiently dedicated hacker might be able to wrest control of the car from the driver and do anything he likes, including driving the car off a cliff or into a gravel truck.

So far as anyone knows, no one has committed a successful crime by hacking into a car's software.  On the other hand, automotive software hacking for benign purposes has been around for a decade or more.  While teens of an earlier generation would get greasy in a garage staying up till midnight to hop up a '57 Chevy for drag racing, today's hot-rodders hack into the valve-control software and tune up the timing to suit their purposes.  The keyhole for this activity is the OBD-II port—the place an auto tech plugs a computer into your car to diagnose why your check-engine light is on. 

In a demonstration for the U. S. military, cyberhackers showed how they could use the port to exert virtually total control over a current-model car, locking the brakes or even killing the engine.  This kind of hacking requires extensive knowledge of the car's software and a good deal of reverse engineering, so it is currently not cost-effective for the bad guys to do it.  And with non-networked cars, it still requires physical access to the car.  But automotive-industry leaders are trying to anticipate the day when new cars are totally networked and become part of the Internet, which will open them up to attacks from anywhere in the world.

According to recent press reports, automakers are organizing an automotive version of an Information Sharing Advisory Center (ISAC), similar to the ones that the banking and other information-critical industries have formed to promote the sharing of news about cyber-threats among competing firms and to develop countermeasures fast.  Just as significant as their actions is the fact that they are publicizing their actions.  One could speculate that the car companies are trying to send a signal to potential automotive cyber-attackers that the industry is not sitting idly by, waiting for the first fatality before something is done to prevent such attacks.  Instead, they are putting defenses in place well before any attack occurs—a sound military tactic.

There may be a lesson here about the tendency of organizations to lose effectiveness with time.  Computers have been used in cars for less than a generation.  But cars have had ignition keys for close to three generations.  The GM ignition-switch failures, with their resulting fatalities and massive recalls, stem from the negligence of engineers who have been doing basically the same thing since the 1930s, although the details have certainly changed over the years.  But the engineers in charge of computer security have grown up in an environment where hacking and cyberattacks are an ordinary part of life, and to pretend otherwise would be a mark of incompetence.  So it is no great surprise to hear that car companies are trying to get ahead of computer criminals by forming an ISAC.

Even so, you can imagine situations in which the mere threat of such an attack would be profitable for criminals.  Say you're the CEO of UPS, and one day near the peak Christmas-shipping season you get an email instructing you to deposit two million dollars in a certain Swiss bank account by a certain time.  If you don't, the sender promises to throw a digital monkey wrench into your entire fleet of trucks, all at once.  The CEO would at least have to take such a threat seriously. 

I feel like taking a mental bath after putting myself into the mindset of a cybercriminal that way, but unfortunately, that is what competent computer-security people have to do in order to come up with ways to thwart such attacks.  The only sure defense against such blackmail is to have enough encryption and other measures in place so that no conceivable attack will stand a good chance of working.  There is always a chance that some evil super-genius will figure out a way to hack the best defenses, but statistically, such people are rare and most cyber-threats involve only the average amount of cleverness. 

The organizers of the first automotive ISAC are to be congratulated for their foresight in anticipating what could be a really messy and dangerous problem, and I hope that automotive cyberattacks are prevented before they can even get off the ground.  But no one knows exactly how cars will interact with the Internet in the future, and depending on how the systems develop, the best efforts of the good guys may be foiled sooner or later by a bad guy.  Let's hope that day is a long way off.

Sources:  Justin Pritchard's report on the organization of an automotive ISAC and successful test attempts at automotive cyberattacks was distributed by the Associated Press and carried by numerous news outlets such as ABC News on Nov. 25, 2014 at http://abcnews.go.com/Technology/wireStory/computer-hackers-dissect-cars-automakers-react-27132494.  The online edition of Auto News carried another report from a Society of Automotive Engineers conference announcing the formation of the industry's first ISAC, at http://www.autonews.com/article/20141021/OEM11/141029957/auto-industry-forming-consortium-to-fight-hackers.  My blog on the GM ignition switch recall appeared on June 9, 2014 at http://engineeringethicsblog.blogspot.com/2014/06/the-switch-from-hell-gms-barra-and.html.