A computer science lecturer warns that universities are much more vulnerable to having their systems hacked, after the learning portal many use had its security breached last week. Last Friday, the Canvas system was hacked by a "malicious actor", and names, email addresses, phone numbers and messages between students and staff were put at risk. The system, used by about 9000 institutions worldwide, was out of action for about two days, before it was brought back online. University of Auckland computer science lecturer and technology consultant Ulrich Speidel said the system was now far more vulnerable to future hacks, because the hackers had got inside the programme. "The moment you're on the inside and you can actually see the code that's there, it makes it much, much easier to look for security holes." Because of that, he worried the hackers could strike again soon. "We might be seeing those hackers come back in days or weeks to come, once they've looked through the code that they may have been able to look at." Speidel said his department was planning for how it would teach students without Canvas, if there was another hack. He had raised concerns about Canvas in the past, after noticing that students could log into one account from different locations during an exam, allowing them to bring in outside helpers. He said the response from Instructure, which runs Canvas, was to ask him to put it on to the community mailing list and, if enough people supported it, they'd fix it. "That's not really the attitude that I'd expect from a supplier who prides themselves on providing a secure system." Earlier this week, Instructure said it had "reached an agreement" with the hackers. As part of the agreement, the stolen data had been returned, along with digital
Global student network more vulnerable after successful system hack
Read the original article
rnz.co.nz →