Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

11–20 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#11
Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading to more ransomware... it’s a vicious cycle

Re: US travel firm $4.5M ransom negotiation open chat

#12
post #6

Maybe I just don't understand either the ThreadReader or Reuters article, but I couldn't find a transcript of the chat linked anywhere? Does anyone else know where it is?

Click the images in the article (showed up as white boxes for me but clicking through worked)

Re: US travel firm $4.5M ransom negotiation open chat

#17

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices.

The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claiming billions for nonexistent PPE.

As a member of society, I don’t care if I’m paying a professional ransomware group, or a professional corruption gang.

Re: US travel firm $4.5M ransom negotiation open chat

#18

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

Take backups, practice restoring them, invest in a security program.

Re: US travel firm $4.5M ransom negotiation open chat

#19
For some context about CWT (I was curious about these figures) -- via Wikipedia[1]:

* US$1.5 billion in revenue * 18k employees

For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure).

It's insane that this is the case and that companies are willing & able to pay ransoms like this, but the hackers were right - the payment is much less than lost business, bad PR, etc. if the actual information had leaked. Such is where we are.

[1] https://en.wikipedia.org/wiki/CWT_(company)

Re: US travel firm $4.5M ransom negotiation open chat

#20

This story is going to be used by every security consultant selling their services for a long, long time.

I'll actually be ok with that.

The security recommendations they put forward at the end are significantly better than anything I can ever get backing to implement.

Post reply on HN