Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

41–50 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#41
post #40

Earlier quoted context omitted.

BooKing.com is one of the biggest Perl shops in the world. They're desperate to hire lots of willing Perl programmers, so they have to set the bar low. And inexperienced programmers cause lots of security problems. Edit: My point is about the moral flexibility of BooKing.com, which is well established and widely known, not good Perl programmers, who are rare, hard to hire, and extremely expensive (especially by Nethe…

Are Perl programmers generally more morally flexible than others?

No, I mean that BooKing.com is morally flexible enough to hire anyone who claims they are willing to program in Perl, because it's so damned hard to find good Perl programmers who don't know any other languages they enjoy programming in more, and can't find better jobs than programming in Perl.

If BooKing.com were trying to hire JavaScript programmers, they'd have a vastly more enormous pool of young and old, well educated and self taught, local and remote, highly experienced and self motivated talent to hire from, and wouldn't have to be so flexible about who they hired to program in Perl.

And the moral flexibility of that company (not the programmers) also expresses itself through those "dark UX patterns" that BooKing.com is so famous for.

(Although they should probably talk to somebody about their domain name: I always assumed BooKing.com was an anti-royalist web site. ;) )

Re: American spy hacked Booking.com, company stayed silent

#42
post #27

This isn’t surprising to me. I know lots of people who work for this company in the Netherlands, and I’ve heard a lot of inside stories about the questionable business practices that go on there. Starting at the very top, with the fraudulent marketing lies to sell you rooms because there’s only X number of rooms left, which is entirely bogus, and for which the courts have punished them, if I recall. They’re not inter…

Booking.com is the poster child of 'dark UX patterns' like that.

at the same time the UI is awesome. using booking.com on a regular basis and I'm quite happy with it.

Re: American spy hacked Booking.com, company stayed silent

#44
> The specific intelligence organization—of which the United States has 18—is unknown.

I certainly couldn't have named them all, so I dug up a list:

• Air Force Intelligence

• Army Intelligence

• Central Intelligence Agency

• Coast Guard Intelligence

• Defense Intelligence Agency

• Department of Energy

• Department of Homeland Security

• Department of State

• Department of the Treasury

• Drug Enforcement Administration

• Federal Bureau of Investigation

• Marine Corps Intelligence

• National Geospatial-Intelligence Agency

• National Reconnaissance Office

• National Security Agency

• Navy Intelligence

• Space Force Intelligence

Re: American spy hacked Booking.com, company stayed silent

#45
post #27

This isn’t surprising to me. I know lots of people who work for this company in the Netherlands, and I’ve heard a lot of inside stories about the questionable business practices that go on there. Starting at the very top, with the fraudulent marketing lies to sell you rooms because there’s only X number of rooms left, which is entirely bogus, and for which the courts have punished them, if I recall. They’re not inter…

For some reason, the hotel business seems pretty shady. My sense from crawling the web is that it's one of the areas that have the most blackhat SEO as well. Straight up linkfarms.

This is sheer speculation, but I do think the hotel business is really convenient to get into if you have a questionable side-business and need to launder money. Who is to say if a room was occupied or not that night, if that foreigner who paid in cash really existed. Can pretty much just trickle money into the books. I imagine you could also run contraband out of them fairly easily. Lots of people coming and going with all sorts of luggage. Who is to say if they are as full when they leave as they were when they arrived? Great for prostitution too, trafficking. The girls can tidy up the rooms during the day.

Re: American spy hacked Booking.com, company stayed silent

#46

Earlier quoted context omitted.

Sounds pragmatic, I wonder when this approach will backfire though.

I bet the attitude would have been very different had spying been done by China, Russia, Israel, or even the Netherlands itself.

Lol you'd be suprised. Recently one large dutch newspaper published a scathing report published by CapGemini (large consultancy in NL) that researched the security setup at the largest telco in NL (KPN). They found that Huawei was able to listen, read and do pretty much anything they'd like with the data. But this was quickly swept beneath the rug. So no, I am pretty confident that the attitude wouldn't be different if either of those state actors seem to be responsible.

Here's a link: https://www.volkskrant.nl/nieuws-achtergrond/huawei-kon-alle...

You can circumvent the paywall by disabling javascript.

Re: American spy hacked Booking.com, company stayed silent

#48
post #17

Earlier quoted context omitted.

> Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable... How does retaining outside counsel as opposed to employing internal counsel have any bearing on liability? Asking genuinely. I'm not an attorney.

More to the point, I don't understand how is this even an excuse? This sounds like invoking ignorance of the law as defense. "But your honor, Joe McLawyer told me it's perfectly legal for me to shoot my neighbor. I can't be held responsible!"

In narrow circumstances, I can see how receiving legal advice may be a factor. For instance, theft in England and Wales must be dishonestly done, and s.2(1)(a) of the Theft Act[1] states that:

> A person's appropriation of property belonging to another is not to be regarded as dishonest if he appropriates the property in the belief that he has in law the right to deprive the other of it, on behalf of himself or of a third person

Pure ignorance of the law doesn't provide you such a belief (IIRC), but seeking legal advice may do so. I'm can't think of any other examples, but I wouldn't be surprised if they exist (for example, if your conduct must be reasonable, following legal advice may lend weight to the argument that it was).

It would also be relevant to explaining the conduct, even if it does not provide a legal defence.

[1] https://www.legislation.gov.uk/ukpga/1968/60

Re: American spy hacked Booking.com, company stayed silent

#49
If you're a name with brand recognition, and active in a space that allows effective monitoring and/or eavesdropping on the communications of a large number of people then you can consider yourselves either already hacked or a target of various intelligence services. Also beware of employees that are overly eager to have more access than they should have the 'plant' is a very effective way to gain access to data (support: en detail, ops: en gros).

Companies routinely wipe hacks and data leaks under the carpet in the hope that nobody will notice, with the GDPR active they really should stop doing this but it still happens with great regularity.

Re: American spy hacked Booking.com, company stayed silent

#50
post #18

I guess the Board knows well enough how many skeletons they're hiding (either personally, or the company itself) and what US laws might be pulled out of the hat to give them an Assange or Huawey treatment. You don't mess with the US, even when you're the victim.

There's a simpler answer here. There's no money to be made by accusing the US. They just don't care about security.
Post reply on HN