By MARTY LEVINE
Pitt Digital has already taken a new step to prevent future Canvas hacks, such as the spring incident that targeted more than 100 organizations — most of them universities — and caused Instructure, the parent company of the Canvas learning management system, to pay the hacking group “ShinyHunters” a ransom to keep the stolen data out of even worse hands.
But fully preventing such future hacks of the software companies so many universities use (such the more recent PeopleSoft breach, also by ShinyHunters, that did not compromise any data or continue further, according to Pitt’s PeopleSoft provider) is a complex issue, said John Duska, Pitt Digital’s chief information security officer.
Since those two incidents, Duska said, “Pitt Digital turned off students’ ability to create access keys (called API tokens) that let outside apps or scripts connect directly to a Canvas account. These keys are a common target for bad actors because they can be used to pull data without needing a password, so removing this access for students reduces one more way a Canvas account could be exploited.
“This kind of incident tends to push institutions to focus on three things,” Duska added: “Making sure only the right people and systems have access to sensitive data (the access-key change is one example); more closely scrutinizing the outside companies whose software they rely on; and improving their ability to detect problems quickly when something does go wrong.”
Asked for further plans to increase local security, Duska could only reply: “We generally avoid detailing specific security strategies publicly, since doing so could give adversaries useful information about how to work around them. But these are the general areas institutions like ours continue to invest in.”
Asked whether Pitt would benefit from devising its own uniquely designed learning management system, or some sort of Pitt-only version of Oracle’s PeopleSoft, to better fend off hackers who accessed many universities at once through the same software, Duska said: “Building and running our own version of these systems, at the level of security that companies like Instructure and Oracle provide, would mean recreating years of specialized software development and dedicated security teams that these companies build up by serving thousands of institutions at once. That kind of scale isn’t realistic for a single university to reproduce — and a homegrown system would carry its own risk of being hacked, without the added benefit of a vendor’s dedicated security resources.”
However, he allowed, “no institution can fully protect itself if the outside company providing its software is the one that gets breached. That’s why resilience and fast response matters as much as prevention.”
There’s no specific reason to suggest that the particular student data accessed in the Canvas hack would be used to create stolen identities for anyone in the future, Duska said. “Instructure has confirmed the information taken included names, email addresses, student ID numbers and messages exchanged between Canvas users. There’s no evidence that passwords, dates of birth, Social Security numbers or financial information were involved.”
But, of course, the hacker group that accessed Canvas and PeopleSoft, calling itself ShinyHunters, cannot be taken entirely on its word, he said, despite promises to destroy and not sell data: “There’s never real certainty when dealing with criminal actors. Because of that, we treat any data that was taken as still being at risk — regardless of what the attackers claim.”
Asked what Pitt had learned from the Canvas and PeopleSoft incidents, Duska said: “In the Canvas incident, data was taken from Instructure’s systems, not Pitt’s own. In the PeopleSoft incident, Pitt’s environment was scanned by our service provider and no evidence of compromise was found. Either way, a vendor’s incident becomes an incident the University has to respond to — which is why institutions like Pitt continue to invest in vendor risk assessment, faster detection and monitoring, and clear, fast communication to the community.”
Marty Levine is a staff writer for the University Times. Reach him at martyl@pitt.edu or 412-758-4859.
Have a story idea or news to share? Share it with the University Times.
Follow the University Times on Facebook.