upvote
> the students themselves don't have the artifacts to resubmit via email because they were done in Canvas

It’s so simple to send an e-mail to the student with relevant records on completion of a quiz or whatnot. They don’t do it, because they want to control the data. (And universities don’t insist on it for who knows what reason.)

reply
I've never used Canvas before, but all the LMSes that I've used allow students to enable emails whenever anything is updated, including when grades are posted. This is off by default because it's often 10+ emails a day, because many teachers post notes once a day, and with 5 classes, that adds up pretty quick. I personally have it enabled because it's pretty manageable with some custom Outlook rules, but setting this up is well beyond the capabilities of most students.
reply
Canvas will send emails when grades are posted, but not what the grade is. Or at least that’s the way in the configurations I’ve seen. So, that wouldn’t help in a case where no one can access the canvas gradebook.
reply

  > setting this up is well beyond the capabilities of most students.
Setting up custom email filters is beyond the capabilities of most students? What are they learning? Where will they be qualified to work?
reply
Most of my students, across all disciplines, don't have basic competence in Word or GDocs, software they've been using for years. It's weeks to teach them how to appy headings
reply
Most graduates aren't really qualified to work anywhere that they couldn't have worked before going to college in the first place.
reply
You mean graduates of US colleges? Not colleges in general. Or non-technical graduates of US colleges?
reply
I think they point weird-eye-issue wants to make is: Students attend college to become qualified to work.
reply
I think you completely misread my comment.
reply
I understood your comment perfectly fine. I'm asking which graduates of which colleges you were referring to. It looked like you were generalizing about US HS and colleges. If so, plenty of other countries' HS and college education systems work better, so your comment doesn't extend.
reply
> Where will they be qualified to work?

Going by a certain story 2 years ago, their concern should be that they're overqualified for Meta.

It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers. So you can't really just put a filter that drags all the 100 low-priority alerts in what would count as a first degree abstraction of "place where things are sorted into". No, there are two layers of abstraction between point A and B of things, sorter and sorted things. The result? Muggles can't recognize the heck you're describing and refuse to even acknowledge the possibility.

reply
> It doesn't help that gmail, which is the only serious direct competition to outlook, straight up doesn't do "folders" and instead goes with markers.

While true, unless I'm mistaken, markers (I assume you're referring to tags) can be nested to provide a pseudo-folder hierarchy, and with proper filters you can remove the "inbox" tag and have the mail only show up under the specific tag.

TBH I don't fully mind it, it lets you classify an email in multiple ways (eg "See Later" as well as "Work related").

reply
People in my work and personal life experience do not understand the concept of labels in a Google inbox and misname them folders 100% of the time. Google allows you to drag-n-drop emails "into" labels like you would files in folders conflating the issue even more as the logic to automate this behaviour with a filter isn't leveraged. Even the layout of a default inbox is setup in a way that the average user has difficulty understanding what happens when an email drops off the "front page" of their inbox.
reply
Tags are great but I still want my folders. Also doesn't help that the way google describes some things is unnecessarily complex or confusing. For example, removing an email from the inbox requires archiving it. In most other applications (WhatsApp, Signal, Outlook, etc) archiving usually results in the email being placed in a specific archive folder that isn't readily accessible through the UI. At least not to the same level that normal emails are.
reply
Gmail still has perfectly functional filters that can be set to auto-apply a label and skip the inbox. They may be called "labels" now, but they still function just as they did when the UI called them "folders"
reply
I partially solve this by using Thunderbird on my laptop. When I get emails on my smartphone (on the Gmail app), they unfortunately all go to the inbox. But the moment I open Thunderbird, it nicely organizes them for me.
reply
I use Thunderbird on both the desktop and Android. Love it.

Perhaps Outlook is difficult to configure. Thunderbird is intuitive.

reply
If a CS graduate can't figure out some simple gmail labels and filters then they should not be awarded that degree. Plain and simple. It's not rocket science.
reply
And there are no other students at any college other than CS students? I'm not sure why a biologist or a literature student would need to be au fait with Google's admittedly fairly unfriendly email management setup.
reply
Digital literacy is important to every field. Email filters are not some arcane computer science concept, they are the modern equivalent of filing physical mail into the right folder/pidgeon hole/inbox/whatever.

Biology is a great example because of just how important digital record management is to experimentation in the field.

reply
I have been using email for as long as email was a thing and I still managed to blackhole important emails with filters not too long ago.
reply
Most people who have office jobs don't know how to do this either
reply
I'd hope/assume that any Computer Science students would be able to do this, but most Biology/Education/English/Art students probably couldn't.

I mean, anyone smart enough to attend university could probably figure it out if they really wanted to, but there are hundreds of other useful things that they could learn too. There are only so many hours in the day, and given that most students don't get that many emails, I can hardly blame them for not wanting to prioritize learning how to filter emails.

(I personally have over a hundred lines of Sieve filters, but I'm definitely not a typical student)

reply
In my experience, it’s hard enough to make students check their school email in the first place. Let alone filter it.
reply
>Setting up custom email filters is beyond the capabilities of most students?

Yes. And most of the general population. They can do it once they know it exists, most people just are not aware it is a thing at all.

>What are they learning?

Here, their "major" as you say in the US. Someone in econ, biology or even CS is not going to learn Outlook rules. Maybe IT or business will have a sentence on it.

>Where will they be qualified to work?

Any office job. Any job really.

reply
Most managers I've met, struggle with setting up email filters, and have to ask tech support to do it for them. These students will be qualified just fine.
reply
it's MS software, i think it's inanely difficult
reply
> What are they learning?

Exactly what is in their field of study, nothing more. That's a huge part of the problems created by treating academia as a degree mill mandatory to get a job able to feed yourself instead of a place only for those truly interested in actually studying a subject.

reply
Students having records of what their score was doesn't prove to the professor / university what score they received. "FWD: Exam 1 Results" is not especially auditable.
reply
If only we had some way of signing messages
reply
> Students having records of what their score was doesn't prove to the professor / university what score they received

It's better than nothing. (And good training for the real world.)

Also, most universities (and many schools now) issue academic e-mail addresses to students. In those cases, the email is definitive proof.

reply
DKIM signature could be used to verify that Canvas' server sent the email with the given content
reply
Good luck having people forward an email a) with headers and b) in a way that doesn't break the signature...
reply
And who exactly do you think is going to verify 100s of thousands of emails this way dude?
reply
A computer?
reply
As opposed to a screenshot of a website? Presumably the professor has a spreadsheet of all assignment grades that is submitted to the school?
reply
> Presumably the professor has a spreadsheet of all assignment grades that is submitted to the school?

This would undermine Canvas's lock-in.

reply
Canvas is built to automatically export its gradebook to an external system. It will do that automatically every day if you want it to. Teachers or others can manually export to the configured foreign system on demand. So if you grade something and want it to show up in the foreign gradebook without waiting for the daily export, you can just press the button to make it happen right away.
reply
i cannot believe how much benefit of the doubt people are giving canvas

ed tech is the WORST performing VC sector

the ONLY game in that town is vendor lock-in! are people joking?

c'mon, canvas is a huge piece of shit. the SaaSpocalypse is coming for them - it seems it is simply that LLMs will be used to exploit it first, rather than universities writing an open alternative they share with each other for free.

reply
Canvas is AGPL licensed. Moodle is GPL. Universities or anyone else can already contribute to big name LMS.

Canvas is used by Harvard, MIT, Stanford, Carnegie Mellon, CalTech, etc. If they each paid 10 FTE, they could set up a foundation that could govern the development of a top-tier LMS. Every tier-1 state institution could contribute 5 FTE. Even little JuCos could chip in an employee here and there. You'd pick up hundreds of capable employees at a fraction of what those schools currently pay to Instructure.

reply
How well has this worked for Open edX?
reply
Why do they all pay for it then? Seems pretty universal in the UK too. Is it having the benefit of someone to blame when things go wrong?
reply
On paper your idea seems obvious. You take a bunch of institutions that actually teach students how to program and have them cooperate to build an open LMS that benefits them all.

In reality, universities always spin off anything that looks like it could generate revenue. It is very telling that you can't even get your college transcript from your college. You have to go to (and pay) some third party to get it. Some universities even outsource their "classes" like elderhostel to cruise lines and travel companies.

reply
> rather than universities writing an open alternative they share with each other for free

That already exists [0], and is actually reasonably popular.

> the SaaSpocalypse is coming for them - it seems it is simply that LLMs will be used to exploit it first

I doubt it, because enterprise sales has nothing to do with how good your product is, how expensive it is, how easy it is to administer, how secure it is, etc.; it only depends on how good you are at enterprise sales. I mean, my university is Oracle-based, and I'm pretty sure that you could get 3 random undergraduates to write something better, so I don't think that LLMs writing better/cheaper software will make any difference here.

[0]: https://moodle.org/

reply
Nope! We're encouraged to keep all that exclusively in canvas. (As noted, I have my own spreadsheet. But I'm an outlier.)
reply
Presumably the system will be back up eventually, so there's not much benefit to lying here, since at best you'll raise your grade in a few classes for a couple months, while taking on a pretty big risk of getting caught.
reply
You forget things can be signed, with the key owned by the school. It can be done.
reply
Does signing really make this easily auditable from the professor’s perspective?
reply
Exactly this, when was the last time a HN user had to interact with the prototypical 60-year-old set-in-their-ways professor?

Extremely non-tech savvy, hates computers, and is gonna grumble "What the hell is a PGP? Better not be another one of those phone code things." as you try to pitch this highly-technological solution to a largely niche problem domain.

reply
I mean a cloud based learning management system also seems to be a very technological solution to the very old problem of checks notes grading quizzes?
reply
They don’t even need to not be tech savvy. This stuff just registers as “hassle” to most people so they do the bare minimum or search for ways to not deal with it at all. It’s easy to “tut tut” at them but ultimately we need to accept reality: privacy, security, these things take extra effort that isn’t strictly necessary for people to go about their daily lives even though the stakes can be super high. It’s not a problem until it is, so they aren’t really barriers that require people to do the work. It’s like convincing someone who just simply doesn’t want to go out and buy/install a lock on their door to go do it, except it’s not even a one-time thing. Their door works fine. They can come and go as they please. It’s not until something happens that they maybe change their tune (and even then!)

Hell just getting people to do secure passwords is a whole thing.

reply
Makes me glad I've always avoided doing my work on web platforms. When we used to have to make presentations in Google Slides I used to do them in Org-mode, then export to Sheets. I still have all those assignments sitting on my disk. Sure, there's versions of them on Google Drive, but I always make sure that the canonical version is the one on my disk.
reply
>It’s so simple to send an e-mail to the student ...

What seems easy on hobby projects gets way more difficult at scale. Source: experience.

reply
For what they charge for these LMSs, they should definitely be able to sent some emails.
reply
I work in the Education sector as IT. We don't know much else either.

Everything we know has come from reddit threads / hackernews threads. There has been 0 official communication today indicating this was an attack, yet the login page was defaced by ShinyHunters.

reply
Just to add one more data point, we also use Canvas at my university. The deadline for submitting who are eligible (i.e. passed compulsory assignments and labs) to take the exam was yesterday, and I couldn’t meet that deadline because Canvas went down. I usually do corrections offline so I have backups of my own evaluations, but these are courses with many teachers and many TAs, so Canvas is the way we sync our assessments.
reply
I guess what surprises me the most is that it’s even legal for schools to outsource the core of what they do to some random tech company.

Either way, they were under no obligation to adopt this garbage technology regardless of whether it’s available, so this is 110% on them.

reply
The alternative would be that each school develop their own platform for this, which also isn't very good use of their time and money?

Edit: No idea why this was down voted so much. I'm not defending Canvas, just wondering what the alternative would be.

reply
They do not need to develop it, but host an existing software on their infrastructure maybe...
reply
The alternative is FOSS.
reply
If your line is GPL rather than AGPL there's Moodle.

But you do then have to have a sysadmin capable of managing an enterprise grade LAMP stack.

reply
Canvas already is AGPL, though?
reply
I don't understand what's the panic and doomerism about. Any competent IT team has backups and will be up and running as they go back to a state before the breach. This is HN. I'm disappointed that everyone is talking about losing grades and going back to pen and paper. I don't see how that could happen in 2026.

And from the hacker's message itself, it's clear they want money in exchange for not releasing private info, not for the data itself.

Do we live in a fear based culture? Why the panic? Even if everything was hosted on Instructure's infrastructure, it's all AWS. I'd be VERY surprised if there aren't multiple way to go back to a previous state.

Most of the work and delay is to make sure they figure out where the breach occurred.

reply
I'm sure you're right. Across tens (hundreds?) of thousands of institutions worldwide, each one is exercising its well-written incident runbook that not only gets updated regularly but also is rehearsed constantly, just in case something like this happens. After all, what university IT department DOESN'T prepare obsessively for the moment when they need to restore all grades on all assignments for all courses from backup and fall over to the backup system for final exam administration in any required format specified by any professor, in the second week of May, on a non-negotiable schedule? There's absolutely nothing to worry about here.
reply
Schools don't have competent IT teams.

Here in the Netherlands a data center's power source (not even the machines) burnt down, data center is offline and University of Utrecht, one of the biggest universities here, is closed. Access passes don't work, work from home environment doesn't work, student information system is down, system for grading doesn't work. No failover for any of them (or maybe it was in the same DC?)

https://nos.nl/artikel/2613485-storingen-in-hele-land-door-b...

reply
Sometimes it is very hard to recover from the offlining of essential systems: https://www.bbc.co.uk/news/articles/cy9pdld4y81o (Jaguar Land Rover, estimated cost in the billions)
reply
I fully agree. What really pisses me off is that these "hacker" groups always spout off how they are doing it to screw the man but then threaten the average person. Millions of them. It just goes to show how uneducated, low-class, and simple these people really are.
reply
> Any competent IT team has backups

Backups can be sabotaged (turned off or schedules manipulated) or compromised (say, by lateral movement).

> Even if everything was hosted on Instructure's infrastructure, it's all AWS.

AWS Backup isn't foolproof. Get your hands on administrator credentials as an attacker and suddenly the only thing between everything being gone for good and unrecoverable even for AWS is remembering to have put a permanent deletion protection on all resources in AWS Backup.

reply
All these articles listing the American schools affected, "nationwide" outage reported, meanwhile hundreds of millions in the rest of the world affected.

Does anyone have a list of affected schools?

reply
I don't have a list, but I can tell you the University of Iceland is affected.
reply
Maybe a hybrid approach. Scramble to create a final exam/project and give them the option to do pass/fail or a real grade, their choice.

And then wish for the death of saas and a day where you can deploy your own software you can control and modify as you need.

reply
Universities are not going to write their own software, and no they can’t use ‘agents’ to write and maintain it for them either.
reply
What is the strategic response then? Assuming I'm a student and my grades are gone, and I want to graduate, shouldn't I pick pass/fail?

Does a future employer look at pass/fail vs the grade? do they care? Are there even jobs that matter enough to care out there for them?

This seems like, solving the problem but without actually seeing the broader goal or trajectory education is supposed to follow.

reply
Most jobs I've had didn't care about a transcript in the slightest. It matters for future education and a small selection of jobs, and even them a few pass/fail courses won't cause any issues. It's not great if important, major-specific coursework is pass/fail, but usually you're not allowed to do that, so when it does come up you'll just have somebody ask what absurd situation (like this canvas thing) caused it.
reply
> day where you can deploy your own software you can control and modify as you need.

Canvas is mostly FOSS

https://github.com/instructure/canvas-lms

reply
To my European ears this just sounds like a disaster like this waiting to happen. God bless the annoying privacy OSS advocates and bureaucrats, I guess.
reply
> they have airgapped backups and can be working as soon as they can spin up new servers

... and assuming they have a documented, tested, and trusted restore process.

reply
Reminds me of the incident last year when a South Korean government's server room caught fire, which contained the government equivalent of Google Drive, and the only backup was in the same room, and they all burnt down together.

Some data was permanently lost, and then officers told reporters that multi-regional backup was not yet built because it was too hard at such a massive scale... of 858 TB.

reply
> it was too hard at such a massive scale... of 858 TB

There are probably many S3 buckets in existence that are bigger than that.

Not saying that they should've used S3, but it's definitely possible configure multi-regional backup (and a government can afford it).

reply
My home theater setup has more storage than that.
reply
Ah yes the “recovery” part of the continuity plan. We tested that right? Right?
reply
deleted
reply
Backups are definitely helpful in ransomwares, but before systems can be restored and brought back online, victim organizations still need to assess the scope of the breach, find the initial access vector, identify compromised accounts, and evict the threat actor. That can take time.
reply
I’m not certain, but it appears you’re giving Instructure a pass here, as if this is the first time they were hacked. But, it’s the second, by the same group.

As a parent of kids who are impacted by this, I’m not super concerned about the data being held for ransom, but I sure as fuck am concerned about how much it’s going to cost the district to move to another provider.

reply
> I sure as fuck am concerned about how much it’s going to cost the district to move to another provider

Does Canvas have cybersecurity insurance?

reply
Not at all; standard IR procedure is scope -> containment -> eradication -> recovery. There is a fog right now; we don't know all the details. It seems to me that it's just as likely they weren't fully kicked out before or that the initial vulnerability wasn't remediated. You can't recover until the threat actor has been removed.
reply
> let classes that normally count for a grade just submit grades as pass-fail. Because what else can you do?

Schedule a single exam and that's your grade for that subject? That's how it should work anyway, credits for work during semester (or worse attendance) are not needed to evaluate if someone learned the material, give them an exam and done.

reply
That's just bad outdated practice. It leads to cramming and less remembering than of the demand is for students to do work and show learning and effort throughout the year.
reply
Most courses I've taken have obligatory assignments that are pass/fail, and you have to pass a certain amount during the semester to take the final exam. But the grade is determined entirely of the final exam.

Which to me seems the best way, you still have to learn throughout the year. Especially to avoid cheating this works nice. And as an aside, most people I know that did a year abroad in the US got 1-2 grades higher, as it was quite easy to just farm extra credits.

reply
It has been my observation that most of the better students were the ones who would not put in work during the semester/year and cram at the end.
reply
That's maybe something a school can do if exams are next week, or after.

At my school, tomorrow is the last day of exams. Most of the students have left campus. There's no time or mechanism to schedule an(other) exam.

reply
Then you're testing how good someone is at exams as much as anything
reply
Exams have performance variance. Otherwise you're only getting a pass/fall signal in any case.
reply
Exams are the only fair way to evaluate if someone knows something (written or oral, in person). Take homes and attendance are just window dressing.
reply
[flagged]
reply
[dead]
reply
[dead]
reply