Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

61–70 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#61
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…

As a business owner, I can tell you that having a “cyber” rider on a business E&O policy can be eye-wateringly expensive.

Re: US travel firm $4.5M ransom negotiation open chat

#62
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

> let any company that doesn't have the budget to have a proper cybersecurity team just die?

Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations, I really don't have a problem with them going under. It's less burdensome than being compliant with the local tax code, which all businesses have to do already.

Re: US travel firm $4.5M ransom negotiation open chat

#65

Earlier quoted context omitted.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

I think this is where insurance can come into play. Like get a smoke alarm and sprinklers, but also get fire insurance.

An insurance would be a much better idea than what OP suggested.

Re: US travel firm $4.5M ransom negotiation open chat

#66
post #53

Earlier quoted context omitted.

Does that revenue include pass-through?

Good question, I was wondering the same thing. It seems it doesn't. The main article body puts total transaction volume at $23B.

That makes sense. $1.5 billion didn’t sound like it would buy a lot of travel/conferences/whatever once you paid 18k employees.

Re: US travel firm $4.5M ransom negotiation open chat

#68
post #23

Earlier quoted context omitted.

Aren’t there mixer services for that or just convert to monero? This is off an exchange so lots of shenanigans to make things less traceable. I am guessing these people know what they are doing.

I’d imagine the feds are involved at this point. They paid to get their data, but the feds have to be tracking the addresses from this juncture and examining the breach. I hope.

I hope the hackers are caught too. But from bitcoin perspective, I am not sure how traceable things are if the hackers use mixing services or convert to actually anonymous currency such as monero. The main problem is converting untraceable bitcoin back to fiat, since most exchanges now follow KYC and will track bitcoin both before and after it touches the exchange.

Re: US travel firm $4.5M ransom negotiation open chat

#69
post #47

Earlier quoted context omitted.

Continuous append-only backups, where one can't rewrite them without physical access to the system, would - most likely - help with a data loss, malicious or accidental.

Maybe a dumb question but -- I'm not a sysadmin, why isn't this the case already? At least for a company doing $1.5 billion in revenue.

Same as with purchasing [non-mandatory] insurance, I guess.

One may not recognize the real value of something (or costs of losing something) until it happens.

Re: US travel firm $4.5M ransom negotiation open chat

#70
post #45

Earlier quoted context omitted.

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

Reading "Never Split The Difference" - sounds like the police will work with families pay off kidnappers is some countries, but get it down from millions to a token amount. I think he aims for zero though most of the time.

It seems to be a necessary part of the strategy though as the negotiation also helps to delay and buy time for escape/rescue.
Post reply on HN