Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

81–90 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#81
post #27

This isn’t surprising to me. I know lots of people who work for this company in the Netherlands, and I’ve heard a lot of inside stories about the questionable business practices that go on there. Starting at the very top, with the fraudulent marketing lies to sell you rooms because there’s only X number of rooms left, which is entirely bogus, and for which the courts have punished them, if I recall. They’re not inter…

> They’re not interested in anything but profit above all else

Not disagreeing with you, but why is it a surprise to anyone? Any company that seems to be “nice” is only doing that as a good PR increases their profits, which depending on domain may be very important.

Re: American spy hacked Booking.com, company stayed silent

#82
post #69

Earlier quoted context omitted.

For some reason, the hotel business seems pretty shady. My sense from crawling the web is that it's one of the areas that have the most blackhat SEO as well. Straight up linkfarms. This is sheer speculation, but I do think the hotel business is really convenient to get into if you have a questionable side-business and need to launder money. Who is to say if a room was occupied or not that night, if that foreigner who…

> Who is to say if a room was occupied or not that night, if that foreigner who paid in cash really existed. Here in th EU, they usually have a look at your passport. I think it's enforced by law in some places. Government overreach

Is it? Surely this simply and proportionately deals with exactly the risks above?

Re: American spy hacked Booking.com, company stayed silent

#83

Earlier quoted context omitted.

Booking.com is the poster child of 'dark UX patterns' like that.

at the same time the UI is awesome. using booking.com on a regular basis and I'm quite happy with it.

I agree. Their website and mobile app as well seem to be of very high quality (though unfortunately it is not that hard to be exceptionally good in that compared to all the buggy software around us)

I have seen their presentation on a ML-related conference and what goes into which pictures they show for you for a given room is quite advanced. E.g. whether you will prefer a photo of a pool vs a nice room, etc.

Re: American spy hacked Booking.com, company stayed silent

#84
post #47

Every time I read such articles, I replace the nationalities American with Russian or Chinese just to gauge how the reactions would be.

For edginess’ sake? While I don’t approve of hacking, I expect American spying to have less damaging results than Chinese or Russian spying.

Re: American spy hacked Booking.com, company stayed silent

#85
post #59

Earlier quoted context omitted.

> I'll always book direct once I find one. Sometimes booking direct is expensive and the hotels most of them have a shitty website.

That's not my experience, I think most hotels realise that their website needs to be useable but sure I guess there are probably still shitty hotel websites out there.

If you are looking at luxury hotels, of course they will have a fine website. But people often stay at smaller niche ones, that even if it has a website, it is probably several years out of date and was made with some drag and drop html editor, badly.

Re: American spy hacked Booking.com, company stayed silent

#86
post #9

Interesting part from the Dutch version of the article: Booking is nooit eerder op spionage gestuit. Het bedrijf is er ook niet echt naar op zoek. Zolang die geen hinder oplevert, kost het geen geld. De onuitgesproken consensus onder specialisten binnen het bedrijf is: we vermoeden dat inlichtingendiensten meekijken, maar zolang we ze niet zien, maken we ons niet druk. Which roughly translates to We are not looking f…

The same goes for Banks, a.o. Dutch banks. They are a bit more picky though. Domestic and US is fine, Russian and Chinese is not.

Re: American spy hacked Booking.com, company stayed silent

#87

> The specific intelligence organization—of which the United States has 18—is unknown. I certainly couldn't have named them all, so I dug up a list: • Air Force Intelligence • Army Intelligence • Central Intelligence Agency • Coast Guard Intelligence • Defense Intelligence Agency • Department of Energy • Department of Homeland Security • Department of State • Department of the Treasury • Drug Enforcement Administrati…

What does Space Force Intelligence do?

Re: American spy hacked Booking.com, company stayed silent

#88
post #72

Earlier quoted context omitted.

All that intelligence and they still can't figure out how to stop a bunch of unemployed basementarians from organising on Facebook to storm one of their principal seats of government... (Sorry for the Twitter-grade comment - but I do sometimes wonder what these people really spend their time doing, that they couldn't catch that one.)

I think the assumption that the gathering storm was not noticed by various intelligence agencies is a wrong one. You had to not want to notice some of chatter online and I am talking about publicly available stuff like FB, Imgur and so on; nothing fancy. I think what I am saying is that it was allowed to happen, for one reason or another.

It feels a bit tin-foil-hattish (I mean: why?), but, aside from my stupefaction at the possible motivation behind why they would do that, logically I find it pretty hard to deny that conclusion. They identify AQ/ISIS plots which are far more competently organised. I have absolutely 0% confidence that they weren't aware of something widely organised on literal Facebook.

--

Edit: The only other logical conclusion I can draw is that it was identified, passed up the chain, and then either covered up by someone (in the realm of politics) who did have that intention, or else bumbled (e.g. left on someone's desk and they were simply overloaded / missed it, a bit like the advance warnings relating to 9/11).

In that connexion it's interesting to read about the research done into pilot error (https://en.wikipedia.org/wiki/Pilot_error), and how surprisingly common it is for human beings to simply miss alerts like that. Multiply that by the probable number of people in the chain, and it's not wildly unlikely.

Re: American spy hacked Booking.com, company stayed silent

#89
post #40

Earlier quoted context omitted.

Are Perl programmers generally more morally flexible than others?

No, I mean that BooKing.com is morally flexible enough to hire anyone who claims they are willing to program in Perl, because it's so damned hard to find good Perl programmers who don't know any other languages they enjoy programming in more, and can't find better jobs than programming in Perl. If BooKing.com were trying to hire JavaScript programmers, they'd have a vastly more enormous pool of young and old, well ed…

> If BooKing.com were trying to hire JavaScript programmers, they'd have a vastly more enormous pool of young and old, well educated and self taught, local and remote, highly experienced and self motivated talent to hire from, and wouldn't have to be so flexible about who they hired to program in Perl.

Yes, but then they'd get results in Javascript, which has it's own security nightmares (like npm's recent third-party-code-injection incident.) Given their business most likely involves the need to quickly parse huge amount of text files (think: hotel booking information, SABRE info, ...), Perl might just be the right tool for the job.

I don't know about booking.com's hiring platform, but in my subjective experience, Perl people tend to be more professional and more careful than JS folks.

Re: American spy hacked Booking.com, company stayed silent

#90
post #27

This isn’t surprising to me. I know lots of people who work for this company in the Netherlands, and I’ve heard a lot of inside stories about the questionable business practices that go on there. Starting at the very top, with the fraudulent marketing lies to sell you rooms because there’s only X number of rooms left, which is entirely bogus, and for which the courts have punished them, if I recall. They’re not inter…

> It is unfortunate, that this is what the tech industry has evolved into.

My thoughts, exactly.

I started off in the 1980s, just as tech was starting to become mainstream.

In the early days, we were not the most "socially well-adjusted" crew, but were fairly enthusiastic about the tech, with most of us working for the love of the craft.

Then, the money started to pour in. It was inevitable.

That brought the sharks and the rapacious bastards.

They became heroes and role models.

And here we are...

Post reply on HN