Survey 7: Digital Security (in the wake of the Canvas chaos)
- Due May 11 at 11:59pm
- Questions 10
- Available May 10 at 11:59am - May 13 at 11:59pm
- Time Limit None
Instructions
(Ignore points associated with answers. Canvas is not letting me eliminate points.)
This week seems like a good time to check in on your views on digital security. Two reasons:
(1) Instructure, the company that owns Canvas, was aware of a threat by the hacker group, Shinyhunters, to the courseware environment as early as May 1. Instead of issuing appropriate precautions to the 9,000 schools, colleges and universities, and 275,000 students, teachers and staff affected by what became a nationwide outage, Instructure covered it up. In the meantime, if you read the terms of use for Canvas, Instructure is mining all of our work, communications and content to develop its AI business. And UW will not divulge how much it has paid for its Canvas license.
In other words, UW has paid Instructure to mine a mountain of valuable information, and yet let us all drop into darkness last week. To date, Instructure has not revealed what data has been compromised.
I spent all day Saturday resetting all class- and UW-related passwords, running my security software, and cleaning out new malware.
(2) Some students have been accessing copyrighted books assigned for this class illegally via torrent ("crowd sourcing") sites like Anna's Archive and LIBGEN. After grading assignments for this class in which students' citations did not align with any copyrighted edition of the books, I set up an old laptop on Linux operating system and downloaded the texts from the sites students shared with me.
What a mess. One textbook arrived with four days (24 hours a day) of malicious code downloading continuously onto the laptop. I let the downloads run their course so I could assess the extent of potential damage. It was overwhelming.
I also looked up a book I published 20 years ago on the two torrent sites. All four editions available across the two sites were missing significant content. One of them was a copy of what are called "page proofs," which were the first print setting sent to me and me only (I thought), to which I sent back thousands of corrections.
If you have ever used these sites, I encourage you to immediately seek assistance to clean out the malicious code, malware and dark web plants that have likely invaded your devices. And do not use these sites again.
No such thing as a free lunch...