Illinois college, hit by ransomware attack, to shut down
nbcnews.com
nbcnews.com
The ransomware attack certainly didn't help, but it is wildly misleading to say, or even imply that caused them to shut down.
The actual reasons:
(a) They filled a niche that didn't need to be filled anymore. They used to absorb students from other local universities (ISU, UIS, UIUC). Those schools have realized the value of helping their own students be successful, leading to declining enrollment.
(b) They were previously a community college, and began awarding bachelor's degrees. They were then fighting in a weight class way above what they were used to, and never really got their feet under them (to use some mixed metaphors).
(c) They were expensive for the quality. They gave a good education, but had zero connections to business and industry to justify the cost.
(d) They had a pipeline from Chicago's south and south-east side that has recently been sniped by large state schools, leading to a decline in enrollment.
For context, I worked with them on enrollment management and declining enrollment a decade ago.
What would be a comparable industry perspective to the way colleges fight over tuition generators (students)? Oil companies fighting over oil fields?
Residential solar or real estate agents?
The crazy thing to me about higher ed is that there's large loans and everybody qualifies. We'd probably get a better skills/job match by including the major in interest rate calculations.
This brings up the hairy issue that all education should not be focused on eventual income generation. We still need our English, History, and other majors out there in the real world even if we don't expect them to make a great ROI on their degrees. Their contributions to society are still worthwhile.
I think a policy that incorporates the major into the interest rate would drive universities to cut less profitable programs, and MAYBE lower tuition for those majors.
I think my approach to change the system would be to put a cap on the maximum loan that the government will back, and have that cap be influenced by major. This would be similar to the conventional loan situation for mortgages.
I agree, but getting them from an expensive private school is a luxury.
> I think my approach to change the system would be to put a cap on the maximum loan that the government will back, and have that cap be influenced by major. This would be similar to the conventional loan situation for mortgages.
Some kind of cap is a really good idea. Especially if that means state schools are covered, but not the entire 80k/year of a private one.
The way student loans are difficult to discharge in bankruptcy means a lot of kids make a mistake they'll spend the rest of their life trying to get away from.
Why would anyone in the middle or lower income class spend money on a college degree that was not geared toward increasing their income?
There is a reason that journalism graduates predominantly come from wealthy families.
Actually, in my opinion, one of the main problems in higher education today is that the value proposition of the actual education and student experience is secondary to the ability to market. In other words, new programs are presented by faculty (or rarely staff because of politics) and administration will immediately ask how this can be sold to increase enrollment (read: revenue). In other words, what is best for students, in terms of experience and employment outcomes, will always take a backseat to what is flashy and looks good in a brochure.
When Profit is the system's main incentive, it can be easy for decision makers to start viewing "profit" as an input rather than an output.
You have government funding, both for research and education.
You have tuition and fees, which students pay but there are student loans and grants etc.
You have endowments.
You have alumni and donor funding.
You have schools that develop technology and own profitable patents.
Sports is its own topic that I don't know enough about to comment on.
In the first paragraph it's saying in part.
The article also details other challenges they face. We'll never know if they would have found a way to address these challenges and survive long-term had this not happened.
Some constructs are on the edge and kicking them may cause them to collapse. It probably will only change the timing but it is still the kick that is the first order cause of the collapse.
Plenty of institutions are being hit with a perfect storm, two years of COVID and associated rules probably didn't help either.
A college or three have failed every year for the past 5 years or so. There will be more until populations of college age students starts to grow again. Most small colleges are extremely vulnerable.
Size and endowments offers some protection to large and wealthy schools.
Are they helping them in any way other than marking what would previously have been a failing grade as a passing grade instead?
I wouldn't be surprised if there were multiple other things they should have been doing to lower operational risk but couldn't realistically do given their situation.
That took a wild turn. Does allowing ice fishing on Lake Michigan also lead to prostitution?
Sadly, I think we're more likely to see pressing F12 become illegal, meanwhile society will lament that half the country's personal data is leaked on a weekly basis and ransomware runs rampant.
Digital Good Samaritan laws.
I confess that while I used to spend quite a deal of time thinking about this class of problem, I haven't done much of it recently, so the following is a mix of potentially outdated thoughts and speculative nonfiction.
If you have the privilege to be outside of any or all of those groups, I feel like it falls on us to speak up to ensure that other people are okay, and Good Samaritan laws can be problematic in this respect, because it's too easy to convince a jury to deny 'those people' standing.
I wondered in another response if some sort of self-reporting system would better serve this space. Possibly 'feature-parity' with other citizen-action laws where community policing and reporting are carried out. The latter closes out a learning opportunity however because you're identifying and reporting a suspicion of an issue and allowing The Authorities to look into it. "We will take it from here." doesn't afford you the opportunity to become part of 'we'.
Perhaps there's precedent with confidential informant laws, and we need to reframe white hat hackers under that umbrella.
you mean increase the rewards?
Way back in college, I talked myself into doing a white-hat hack of a service another student was running that I valued highly. He had used software with a rather nasty CERT advisory outstanding. My attempts failed, which meant he had patched his system, probably at the firewall. I shrugged and went on with life.
Or at least I tried to, because the next day I got an email from him telling me that he saw what I did and if I ever pulled shit like that again he'd report me to the Dean's Office. For the time, the university had some pretty sophisticated auditing tools to backtrack problems including shenanigans of this sort and because I was doing something 'good' I had just accessed his system straight from my dorm room (I found out shortly after that even if I had attempted to remote in he still would have been able to send that email).
I offered an "apology" that was about what you'd expect from a 20 year old white male: all excuses and rationalization. It hadn't quite sunk in yet that this distinction between black and white hat existed solely in my brain. I don't even think I bothered to tell my roommate what I was planning to do. I had zero alibi because I was impulsive. I never did anything like that again. If memory serves, I told him I'd never do something like that again (which means it was sinking in a little bit), and that has been largely true.
In hindsight, I was such an earnest kid that any decent lawyer could have would have been able to get me off with a warning, that would have saddled me with debts that would have fucked up my 20's, even if we had gotten a good rate through a family friend. I'd probably have still failed a background check on the piece of software that I worked on in my 30's that is and probably will remain one of the mantelpieces of my career.
The Venn diagram of people with a suspicious enough mind to think of trying what I did and the personality that would keep them out of big trouble is very narrow. But to your point, the circles for aptitude, desire, and history are pretty small. As it turns out, I didn't enjoy being a low-bus-number person responsible for the security of the system, so I now fall outside of the 'desire' circle. These days I'm content to help people sort out/select auth libraries, configure CA certs, and occasionally talk trash about cryptocurrency. I have enough other interests that I'm probably booked out until after retirement.
"White hat" describes someone acting on behalf of the owner of the system being tested. It sounds like you acted on your own and thus were grey hat hacking. I only bring this up because it has different ramifications, legal, social, and otherwise.
This is somewhat confusing because there is a college called Illinois College. Because of this news, they are accepting transfers from Lincoln for all students in good academic standing: https://www.ic.edu/news/04-4-2022/illinois-college-extends-b...
But getting to the point of needing to shut down entirely because of a ransomware attack seems like negligence. If your data is that vital to you, you really ought to have some backup of it.
I wonder what the ransom was and if they paid it.
Side note: Planet Money had an interesting segment on insurance claims for things like cyber attacks last week, it's worth giving a listen.
Like driving without insurance, it works until it doesn’t.
A year ago they would just send a laptop with Nessus on it and then sign off on a risk sheet full of the usual llmnr/nebios/kerberoast/smb1 vulns because they didn't know what it meant. Now they will pop your domain administrator and refuse your renewal or jack your rates until you get a followup pentest demonstrating that those vulns have been resolved.
I get the feeling this is one of those rules setup to make sure they don't deal with small institutions with small IT departments or they really don't know how much the cost of insurance to them will be.
How enforceable is this? Why could you not just leave that machine out of your inventory?
I don't like it, but it's been the nature of the headline game since long before clicks.
How is this possible? There's literally not a second copy of the data anywhere? The people working in the admissions office didn't have a printout and they had absolutely no idea what the numbers looked like? It's one thing to have all the videos for online classes get locked up in a ransomware attack, but this simply cannot be true.
I wrote a Blackmirror fanart script based on Hackers using Ransomware to threaten Universities to write down student debt, I got to Act II before I left it. I want to spend more time writing this year, but so far I have spent way too much time on HN than creative writing and that is unfortunate.
> For context, I worked with them on enrollment management and declining enrollment a decade ago.
What measures did they take? And what expertise cold you lend them to counter this?
How can they know this?
No insights on that, but this is more the way I read such statements:
This is their report of what they know.
Common sense dictates that this does not mean much as we normally only know a fraction of what is.
However it might also be a sign that they are not yet aware of much at all as it is that overly unspecific.
It is just not known which individuals in specific.
Should be common to send a notice to all individuals then and explain the details so those who are affected do know and can act.
(In other words, there's a yin and yang situation in which the ransomware threat actor happens to have a philanthropic arm.)
I think most people would say that the answer is no. This topic has been widely discussed on HN with regards to the MIT Media lab accepting money from Epstein.
(A) The government tracks down the ransomware guy, seizes his assets, and decides that $50 million is Lincoln's fair share to reimburse Lincoln's losses (8 of 8 would take the money).
(B) Lincoln tracks down the ransomware guy, takes him to court, and wins a civil judgment of $50 million (8 of 8 would take the money).
(C) Lincoln tracks down the ransomware guy, their lawyers show proof of Lincoln's losses and how much they could potentially win in a civil trial, and the parties agree to a $50 million out-of-court settlement (7 of 8 would take the money).
(D) A ransomware criminal proactively contacts Lincoln, the criminal won't comment on whether he had any role in harming Lincoln (and Lincoln doesn't know either), but the criminal offers to donate $50 million to Lincoln anyway (2 of 8 would take the money).
That needs to happen
The humanizing done about how its was something like an HBCU and weathered other calamities is sad, should also be a wakeup call to other organizations
The "we need more victims to change everyone's minds" is a strawman.
https://lincolncollege.edu/file/471/21-22%20Undergraduate%20...
Math runs out at calculus. No computer science. Very few programs which would translate to real careers.
Reforming a school like this is much more than cutting a check. It's a worthwhile project, but it's a major undertaking.
Any truly critical system should not be connected to the public internet. Computers with internet connections are for sending email and reading Wikipedia. Any data critical to your organization should be accessed from separate terminals connected via LAN. No VPN, that's still the internet.
Do that, and unless you're the CIA you will never be hacked. You can even run Windows XP if you feel like it.
The internet is the root of the problem, and it's time we start realizing that some things shouldn't be online.
Email (or other messages systems like slack) are one of primary tools of business, facilitating communication within an organization. You can't do that well with an air-gapped network, except to make that network really leaky.
I imagine students applied via snail mail, and then someone manually entered the information into a database. There's no reason to go back to paper applications, and that database should absolutely be digital—but I think we could do a lot more manual entry.
Start receiving long-awaited envelopes around Spring Break, and speculate on whether said envelopes were thin because they contained simple rejection letters, or because the desired financial aid details would follow the next week.
The LAN is a much more used attack vector than the internet. It has nothing to do with some hacker sitting there banging at your door users just share files and reuse devices as part of their day to day effort. The instant someone in the college brings in a compromised USB, intentionally or unintentionally, all of the isolation in the world from the internet doesn't save you from ransomware.
The medical device? They didn't, WannaCry would spread over the LAN to the systems silently then when the vendor came to do maintenance on a system or an upgrade they would become a transport vector between sites.
Generic? Because limiting college computers to only be able to work on what you can type into each one you visit makes them relatively useless and creates a much larger burden than managing security.
Another helper technology that's underused is data diodes, which prevent two-way connections but allow one-directional data flows, such as security updates for a lab full of workstations, or in the other direction, allowing internet monitoring of a source-of-truth or sensor while preventing internet tampering.
Unfortunately, distributed orgs can't as easily benefit from air gaps and data diodes, but they're effective tools when your physical boundaries align with your security boundaries such as in a lab or around a campus.