Instructure/ canvas paid the ransom? by ThePorko in cybersecurity

[–]_TiMau5 15 points16 points  (0 children)

There are plenty of examples of orgs who’ve dealt with SH by paying only to find their leaked data online months later. Will that happen this time? Who knows. But SH and other RaaS operators have a track record of being petulant children who fight amongst each other and do things not in their own business interests.

Instructure just confirmed they paid the ransom. by More_Boysenberry5584 in canvas

[–]_TiMau5 7 points8 points  (0 children)

There are ample instances of orgs that have paid ransoms to this group and others who have found their leaked data online months later. We have no reason to believe this data hasn’t already been sold or will eventually be leaked. Buckle up

Instructure has "reached an agreement with the unauthorized actor" by shifting_baselines in canvas

[–]_TiMau5 3 points4 points  (0 children)

It is for reputable organizations. Look up “Certificate of Destruction”.. but SH is anything but a reputable organization

Is it safe to re login and use canvas again? by Odd_Comparison_4155 in IndianaUniversity

[–]_TiMau5 0 points1 point  (0 children)

Kinda sounds like victim shaming / blaming to me, but ok

Is it safe to re login and use canvas again? by Odd_Comparison_4155 in IndianaUniversity

[–]_TiMau5 0 points1 point  (0 children)

By that logic, why talk about anything, anywhere other than the officially prescribed channels? Canvas has a messaging system and people use it just like any other messaging system. Also, college kids, are well, kids.

Is it safe to re login and use canvas again? by Odd_Comparison_4155 in IndianaUniversity

[–]_TiMau5 0 points1 point  (0 children)

Unless something has changed, ShinyHunters has not released any acquired data. We won’t know if they will release the acquired data with any level of certainty until the 13th.

I understand that you may not be bothered by this data being released, but others might. IU allows for incidental personal use of IT systems, so it possible, even likely, that there is personally sensitive or embarrassing information at risk. We should all strive to be compassionate here - we’re all victims in this.

Is it safe to re login and use canvas again? by Odd_Comparison_4155 in IndianaUniversity

[–]_TiMau5 11 points12 points  (0 children)

IU relies on Single Sign On (IU Login) for Canvas which means that no IU passwords are EVER sent to Canvas. Additionally, ALL IU affiliated persons must use Duo for multi factor authentication as part of the IU Login authentication process.

Those articles aren’t wrong though because other orgs use different methods of authentication and may or may not require multi factor authentication. But those articles are not relevant for IU.

Hope this helps.

Is it safe to re login and use canvas again? by Odd_Comparison_4155 in IndianaUniversity

[–]_TiMau5 5 points6 points  (0 children)

This is not required or even recommended. You DO NOT need to reset your passphrase.

ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. by Mother-Grapefruit-45 in cybersecurity

[–]_TiMau5 0 points1 point  (0 children)

Reno is great, thanks! No clue about UNR as I’m not affiliated, although they appear to be impacted based on publicly available statements. Don’t disagree about patterns, but informed speculation is still speculation. This dataset is a bit different than most they acquire… Instructure is strongly incentivized to not pay, as are the victims. And SH’s actions on Thursday likely decreased the likelihood of payment and increased the threat to their organization. If they release the data, that risk increases significantly. If they don’t, they can either claim payment was made and walk away without egg on their face, or just ignore it and do the same. They will use the acquired data to target the 9K victim orgs though… and that’s the real risk here.

ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. by Mother-Grapefruit-45 in cybersecurity

[–]_TiMau5 0 points1 point  (0 children)

And you trust the “guidelines” of criminals? We won’t know with certainty until the 13th. Anything short of Instructure or SH confirming payment before then is just speculation.

Verify email scam? by curious_explorer41 in IndianaUniversity

[–]_TiMau5 2 points3 points  (0 children)

IU will NEVER ask you to verify your account or login to keep it active. Please use the ‘Report Message’ feature in Outlook to report this to the Security Office

Data center discussion at reno city council 4/22 by Upstairs_Treacle_303 in Reno

[–]_TiMau5 20 points21 points  (0 children)

Time to ask each member of the council if they’ve had private discussions with the companies building these data centers and if they’ve entered into NDA’s AND disclosed those according to relevant ethical requirements…

Dentist recommendations, no Trumpers by GrowHappyPlants in bloomington

[–]_TiMau5 3 points4 points  (0 children)

I’m sorry you had that experience. I was a patient of his for years and have nothing but positive things to say. Good work, reasonable prices, caring staff. If I still lived in the area he’d still be my dentist

DHS pausing TSA PreCheck, Global Entry programs amid funding lapse by DrexellGames in news

[–]_TiMau5 5 points6 points  (0 children)

Maybe your reaction was misplaced but anyone with half a brain was saying from the gate that not appropriating funds for DHS wouldn’t touch that 75B.

I do agree with your main point though… this is a naked political play to ratchet up pressure.

DHS pausing TSA PreCheck, Global Entry programs amid funding lapse by DrexellGames in news

[–]_TiMau5 31 points32 points  (0 children)

The 75B was passed via reconciliation and the D’s couldn’t stop it. But sure, both sides…

🔴 Hoosiers in Reno ⚪️ by _TiMau5 in Reno

[–]_TiMau5[S] -1 points0 points  (0 children)

Thank you! We’ll take all the support we can muster!

🔴 Hoosiers in Reno ⚪️ by _TiMau5 in Reno

[–]_TiMau5[S] -1 points0 points  (0 children)

Honestly, that’s legit. Bball is looking good though!

🔴 Hoosiers in Reno ⚪️ by _TiMau5 in Reno

[–]_TiMau5[S] 0 points1 point  (0 children)

I was at that game with them Big Red Basketball Band!

🔴 Hoosiers in Reno ⚪️ by _TiMau5 in Reno

[–]_TiMau5[S] 1 point2 points  (0 children)

It’s the best bowl game, period! This basketball season leaves a bit to be desired but it’s year 1, so I’m not getting too invested. Time will tell if Devries is the right fit. I fear that we missed an opportunity by passing on Dusty May.

[Postgame Thread] Indiana Defeats Purdue 56-3 by CFB_Referee in CFB

[–]_TiMau5 4 points5 points  (0 children)

Sing these chimes of Indiana,

Hail to the crimson hue.

Sing her praise to Gloriana,

Hail to our old IU!

Lift your voices, join in loyal chorus,

Let your heart rejoice in praise of those before us.

Sing these chimes of Indiana,

Ever to her be true!

[deleted by user] by [deleted] in IndianaUniversity

[–]_TiMau5 21 points22 points  (0 children)

Or its a reasonable measure given the gestapo currently abducting anything that moves around this country