Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

31–40 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#32
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

I don't know about that. For one, travel margins are not exactly the same as SaaS margins. Secondly, there's the global pandemic and all, kinda hurts the free cash of most travel companies.

I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.

Re: US travel firm $4.5M ransom negotiation open chat

#33

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

Take backups, practice restoring them, invest in a security program.

Just having backups isn't enough. It's ransomware 101 to wait and try to encrypt all of their online backups and any recent offline backups.

You really need comprehensive, air-gapped backups that date to years back.

Re: US travel firm $4.5M ransom negotiation open chat

#34
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it.

Our current legal framework doesn’t support such a draconian suggestion as presented imho.

You want poor security practices to be painful, not fatal, to the corporate entity.

Re: US travel firm $4.5M ransom negotiation open chat

#37
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

Re: US travel firm $4.5M ransom negotiation open chat

#38
post #17

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

> As a member of society, I don’t care if I’m paying a professional ransomware group, or a professional corruption gang.

The kidnapping analogy makes for a better understanding of why paying ransoms is bad for everybody else. If kidnappers know, or really just think, that they’ll get paid, they’re more likely to kidnap and hold hostages.

It’s not that companies are not solely responsible for their own lax security policies. It’s that incentivizing the exploiting of them is bad for society.

Re: US travel firm $4.5M ransom negotiation open chat

#39
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…

Our legal framework already contains many prohibitions on financial transactions with criminals and terrorists. It wouldn't be difficult to add one more.

Re: US travel firm $4.5M ransom negotiation open chat

#40
While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies.

While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly.

I don’t support these attacks and some of the targets in particular are insidious, like hospitals where an attack could lead to an actual death toll, but it might actually be the kick in the ass many organizations need to actually care.

It’s sad that it’s come to this point but the end result may be better for everyone.

Post reply on HN