Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

1–10 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#2
Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

Re: American spy hacked Booking.com, company stayed silent

#4

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

> Why wouldn't they stay silent?

Booking.com is required to follow Dutch law and originates from the Netherlands, which at that time required informing customers if the hack could have negative consequences for them. They ignored it and did nothing.

Re: American spy hacked Booking.com, company stayed silent

#5

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

They operate in he EU, doesn’t the GDPR mandate rapid disclosure of security breaches?

Re: American spy hacked Booking.com, company stayed silent

#6

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

Because Booking.com is a Dutch company, and the EU has GDPR, the incident cannot legally repeat itself. This was 2016 incident and GDPR become effective 2018.

Re: American spy hacked Booking.com, company stayed silent

#7

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

This took place just before the EU-wide GDPR was introduced, but under the Dutch national laws applicable at the time Booking.com was obliged to notify its affected users. Because the impact of a foreign state actor spying on your hotel bookings can be quite high (something Booking.com cannot reasonably determine for their users themselves) disclosure should have happened then in 2016, and the Dutch Data Protection Authority should have been informed as well.

Re: American spy hacked Booking.com, company stayed silent

#8
post #5

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

They operate in he EU, doesn’t the GDPR mandate rapid disclosure of security breaches?

This is before the GDPR, but precursor Dutch national laws already mandated disclosure.

Re: American spy hacked Booking.com, company stayed silent

#9
Interesting part from the Dutch version of the article:

Booking is nooit eerder op spionage gestuit. Het bedrijf is er ook niet echt naar op zoek. Zolang die geen hinder oplevert, kost het geen geld. De onuitgesproken consensus onder specialisten binnen het bedrijf is: we vermoeden dat inlichtingendiensten meekijken, maar zolang we ze niet zien, maken we ons niet druk.

Which roughly translates to We are not looking for espionage and if it doesn't hinder us we don't care.

Re: American spy hacked Booking.com, company stayed silent

#10
post #4

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

> Why wouldn't they stay silent? Booking.com is required to follow Dutch law and originates from the Netherlands, which at that time required informing customers if the hack could have negative consequences for them. They ignored it and did nothing.

They did something; they found someone else to blame:

"The management claims it was not legally required to do so at the time, based on advice it received from the law firm Hogan Lovells."

Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable...

Post reply on HN