Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

71–80 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#71
post #45

Earlier quoted context omitted.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

What's the difference?

Cut deeply enough - take out entire companies - and people lose their jobs.

People can't eat. People lose their health insurance that allows them to afford their life-saving medication.

At some point, it's not just "big corporations"; it's the people that work for them, too.

Re: US travel firm $4.5M ransom negotiation open chat

#72
post #58

Earlier quoted context omitted.

Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws? Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.

If you were a corporate executive would you risk hard prison time just to save your employer from taking a loss? The whole point of imposing draconian penalties is to make such attacks unprofitable. If the attackers know they won't be able to extract any money from victims then they'll move on to some other scheme.

Executives don't go to jail when their companies kill people. There's no way we manage to restructure our justice system so that they go to jail for paying ransoms.

Re: US travel firm $4.5M ransom negotiation open chat

#73

Earlier quoted context omitted.

Maybe require cyber insurance instead, pricing premiums based on audits performed by infosec practitioners. Similar to auto insurance, and what happens when you’re a high risk driver; you still have insurance, but you’re paying out the nose for it. Our current legal framework doesn’t support such a draconian suggestion as presented imho. You want poor security practices to be painful, not fatal, to the corporate enti…

As a business owner, I can tell you that having a “cyber” rider on a business E&O policy can be eye-wateringly expensive.

As an infosec practitioner, I can’t tell you how many times I’ve seen someone have insurance and their security posture be effectively nothing, or the insurance not pay out even with reasonable measures in place. Market failure in my opinion, needs more regulation.

Re: US travel firm $4.5M ransom negotiation open chat

#74

Earlier quoted context omitted.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

> let any company that doesn't have the budget to have a proper cybersecurity team just die? Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations…

>"the most basic offline redundancy"

How many people you meet everyday that are not in IT even knows what offline redundancy means?

I think what your suggestion amounts to, is effectively a mandate on SMBs having either an in house security team, or a contract with a consultancy on cyber security. That's a huge burden. It's not really easier than local tax code. These things change much more frequently and it's not like you can just walk into a local H&R Block to take care of your cybersecurity needs. Ransomeware, as it is now, didn't even exist (or is that popular) 10 years ago.

Re: US travel firm $4.5M ransom negotiation open chat

#75
post #58

Earlier quoted context omitted.

Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws? Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.

If you were a corporate executive would you risk hard prison time just to save your employer from taking a loss? The whole point of imposing draconian penalties is to make such attacks unprofitable. If the attackers know they won't be able to extract any money from victims then they'll move on to some other scheme.

There are reasons why companies manage to do tons of illegal things. A lot of executives would have a good amount of their wealth in company stocks, for example. This has no reason to be an exception.

Re: US travel firm $4.5M ransom negotiation open chat

#77

Earlier quoted context omitted.

Reading "Never Split The Difference" - sounds like the police will work with families pay off kidnappers is some countries, but get it down from millions to a token amount. I think he aims for zero though most of the time.

It seems to be a necessary part of the strategy though as the negotiation also helps to delay and buy time for escape/rescue.

They sometimes paid the amount. In some countries that was probably seen as a better plan. It probably depends how loose the cannons are.

Re: US travel firm $4.5M ransom negotiation open chat

#78

Earlier quoted context omitted.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

The main idea here is that prohibiting payouts might make the crime less frequent. That’s somehow reasonable given the relative low stakes involved—from a moral perspective, data is usually of a lesser value than human lives. Therefore, yes, those cases are very different indeed. For once, kidnapping a human being is already punishable enough by itself so it makes no sense to punish a payout that could actually save…

The only reason the kidnappings happen is because the payouts happen. If effective measures stopped any real possibility of payouts, the kidnappings would stop, too, saving a lot more lives.

Re: US travel firm $4.5M ransom negotiation open chat

#79

Earlier quoted context omitted.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

> let any company that doesn't have the budget to have a proper cybersecurity team just die? Are you implying that without a cybersecurity team, you'll fall victim to ransomware and be forced to pay up to stay in business? Because that's a false dichotomy - the simplest of backup solutions would have prevented this. And if a company can't manage the most basic offline redundancy for their critical business operations…

> the simplest of backup solutions would have prevented this.

Incorrect. The black hats almost always encrypt backups, too. You could say "what about offline, glacial backups?" But then you're no longer talking about "the simplest of backup solutions"

Re: US travel firm $4.5M ransom negotiation open chat

#80
post #68

Earlier quoted context omitted.

I’d imagine the feds are involved at this point. They paid to get their data, but the feds have to be tracking the addresses from this juncture and examining the breach. I hope.

I hope the hackers are caught too. But from bitcoin perspective, I am not sure how traceable things are if the hackers use mixing services or convert to actually anonymous currency such as monero. The main problem is converting untraceable bitcoin back to fiat, since most exchanges now follow KYC and will track bitcoin both before and after it touches the exchange.

> The main problem is converting untraceable bitcoin back to fiat

Got to imagine there’s a well-established laundering system for just that

Post reply on HN