Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

11–20 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#14
post #6

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

Because Booking.com is a Dutch company, and the EU has GDPR, the incident cannot legally repeat itself. This was 2016 incident and GDPR become effective 2018.

GDPR isn't a be-all and end-all, Dutch laws already incorporated a lot of aspects of it such as having to notify their customers prior to GDPR becoming effective.

Re: American spy hacked Booking.com, company stayed silent

#16
post #6

Why wouldn't they stay silent? That is the norm unfortunately and congress is more concerned about being able to enact more anti-privacy and anti-encryption laws than they are of actually holding companies liable for poor cybersecurity. I definitely encourage everyone to watch the hearing with Colonial Pipeline to see what I'm talking about.

Because Booking.com is a Dutch company, and the EU has GDPR, the incident cannot legally repeat itself. This was 2016 incident and GDPR become effective 2018.

Of course it can repeat itself. Dutch laws already mandated disclosure of a breach like this before the GDPR. The company simply didn’t give a fuck and found a legal firm that gave it license not to.

As the article noted the company operates on a “if we don’t see it and it doesn’t hurt us we don’t care” principle. Even with the GDPR, the company can still chose to not give a fuck. It just becomes a more risky gamble assuming anyone ever finds out.

Re: American spy hacked Booking.com, company stayed silent

#17
post #10
post #4

Earlier quoted context omitted.

> Why wouldn't they stay silent? Booking.com is required to follow Dutch law and originates from the Netherlands, which at that time required informing customers if the hack could have negative consequences for them. They ignored it and did nothing.

They did something; they found someone else to blame: "The management claims it was not legally required to do so at the time, based on advice it received from the law firm Hogan Lovells." Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable...

> Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable...

How does retaining outside counsel as opposed to employing internal counsel have any bearing on liability?

Asking genuinely. I'm not an attorney.

Re: American spy hacked Booking.com, company stayed silent

#20
post #9

Interesting part from the Dutch version of the article: Booking is nooit eerder op spionage gestuit. Het bedrijf is er ook niet echt naar op zoek. Zolang die geen hinder oplevert, kost het geen geld. De onuitgesproken consensus onder specialisten binnen het bedrijf is: we vermoeden dat inlichtingendiensten meekijken, maar zolang we ze niet zien, maken we ons niet druk. Which roughly translates to We are not looking f…

Sounds pragmatic, I wonder when this approach will backfire though.
Post reply on HN