Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

151–160 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#151

Earlier quoted context omitted.

This is nonsense. Source: I have been working in the cyber security department of a major Dutch bank.

Doesn't an admission that you work for the cybersecurity of a Dutch bank immediately discount any claims you make? If you're responsible for their cyber security, I guess you have a stake in projecting the idea that everything is fine. Either way you can't prove anything with a one line comment like this. The only winning move is not to play... (Or ask for sources. Of course the assertion by smooc is equally devoid o…

This is one of those interesting lines of argument where you position yourself so that you can't possibly be proven wrong. No one can prove you wrong when you claim that anyone with knowledge from the other side should be immediately discredited.

You mention sources, but if you discredit the first-party source out of the gate, what sources are even left? Documents from the bank created by the people you discredit?

(I take no position either way, I'm just commenting because your comment amuses me.)

Re: American spy hacked Booking.com, company stayed silent

#152
post #27

This isn’t surprising to me. I know lots of people who work for this company in the Netherlands, and I’ve heard a lot of inside stories about the questionable business practices that go on there. Starting at the very top, with the fraudulent marketing lies to sell you rooms because there’s only X number of rooms left, which is entirely bogus, and for which the courts have punished them, if I recall. They’re not inter…

For some reason, the hotel business seems pretty shady. My sense from crawling the web is that it's one of the areas that have the most blackhat SEO as well. Straight up linkfarms. This is sheer speculation, but I do think the hotel business is really convenient to get into if you have a questionable side-business and need to launder money. Who is to say if a room was occupied or not that night, if that foreigner who…

> Who is to say if a room was occupied or not that night, if that foreigner who paid in cash really existed.

That's why in some countries ID is required when checking-in. Makes it a bit harder to use for money laundering.

Re: American spy hacked Booking.com, company stayed silent

#153
post #9

Interesting part from the Dutch version of the article: Booking is nooit eerder op spionage gestuit. Het bedrijf is er ook niet echt naar op zoek. Zolang die geen hinder oplevert, kost het geen geld. De onuitgesproken consensus onder specialisten binnen het bedrijf is: we vermoeden dat inlichtingendiensten meekijken, maar zolang we ze niet zien, maken we ons niet druk. Which roughly translates to We are not looking f…

According to Google Translate: > Booking has never encountered espionage before. The company isn't really looking for it either. As long as it doesn't cause any hindrance, it won't cost you any money. The unspoken consensus among specialists within the company is: we suspect that intelligence services are watching, but as long as we don't see them, we don't worry. What should make me believe that they don't have the…

>> black hat hackers

How are foreign intelligence services not black hats? They are stealing data in order to use it for any number of non-nice things. Not selling the data on the dark web doesn't bleach their hats.

Re: American spy hacked Booking.com, company stayed silent

#154
post #70
post #59

Earlier quoted context omitted.

> I'll always book direct once I find one. Sometimes booking direct is expensive and the hotels most of them have a shitty website.

Booking takes a 20% cut of the reservation, so I expect every hotel to gladly you offer a 10% off the booking.com price.

You are correct. Marriott, Hilton, and IHG (and probably others) have price match guarantees, offering 20-25% discount (or a load of reward points) on top off of the cheaper rate that you found. Submitting claims can be a little inconvenient, but it’s worth attempting before booking an expensive trip.

Booking through a third party also usually prevents you from receiving loyalty rewards, if that's something you're concerned about.

https://www.marriott.com/look/claimForm.mi

https://hiltonworldwide3.hilton.com/en/price-match-guarantee...

https://www.ihg.com/content/us/en/customer-care/best-price-g...

Re: American spy hacked Booking.com, company stayed silent

#155

If you're a name with brand recognition, and active in a space that allows effective monitoring and/or eavesdropping on the communications of a large number of people then you can consider yourselves either already hacked or a target of various intelligence services. Also beware of employees that are overly eager to have more access than they should have the 'plant' is a very effective way to gain access to data (sup…

> Companies routinely wipe hacks and data leaks under the carpet in the hope that nobody will notice, with the GDPR active they really should stop doing this but it still happens with great regularity.

That's why the DPO is mandatory to have and is personally responsible. From my experience ( MSP/MHP/consultancy with lots of clients), post-GDPR data leaks are taken much more seriously.

Re: American spy hacked Booking.com, company stayed silent

#156

Earlier quoted context omitted.

According to Google Translate: > Booking has never encountered espionage before. The company isn't really looking for it either. As long as it doesn't cause any hindrance, it won't cost you any money. The unspoken consensus among specialists within the company is: we suspect that intelligence services are watching, but as long as we don't see them, we don't worry. What should make me believe that they don't have the…

>> black hat hackers How are foreign intelligence services not black hats? They are stealing data in order to use it for any number of non-nice things. Not selling the data on the dark web doesn't bleach their hats.

[deleted]

Re: American spy hacked Booking.com, company stayed silent

#157
post #37

Earlier quoted context omitted.

I bet the attitude would have been very different had spying been done by China, Russia, Israel, or even the Netherlands itself.

It would have turned into one of the hundreds of articles about Russian, Chinese, Iranian, Ukrainian, North Korean, etc. hackers meant to solidify people's world view that we have a "good side" and a "bad side" of the world. The reality is that we have a "bad side" and a "worse side" but that's a hard pill to swallow for the regular person. Hence the deluge of articles meant to "straighten up" the view.

You’re mistakenly assuming that everyone sees intelligence services as bad, because as much as many people are concerned, “an enemy of an enemy is a friend.”

Re: American spy hacked Booking.com, company stayed silent

#158

> The specific intelligence organization—of which the United States has 18—is unknown. I certainly couldn't have named them all, so I dug up a list: • Air Force Intelligence • Army Intelligence • Central Intelligence Agency • Coast Guard Intelligence • Defense Intelligence Agency • Department of Energy • Department of Homeland Security • Department of State • Department of the Treasury • Drug Enforcement Administrati…

This reminds me of the book Military Intelligence Blunders and Cover-Ups by John Hughes-Wilson.

It has a good overview on a few different failures, including multiple ones by the US, not least because of the huge number of different agencies, each wanting to protect its territory and reputation more than to actually do their job. The incompetence is frankly pretty staggering. And those are the people who can just drone strike, extradite or kidnap you and torture you, anywhere in the world. Fun !

Re: American spy hacked Booking.com, company stayed silent

#159
post #9

Interesting part from the Dutch version of the article: Booking is nooit eerder op spionage gestuit. Het bedrijf is er ook niet echt naar op zoek. Zolang die geen hinder oplevert, kost het geen geld. De onuitgesproken consensus onder specialisten binnen het bedrijf is: we vermoeden dat inlichtingendiensten meekijken, maar zolang we ze niet zien, maken we ons niet druk. Which roughly translates to We are not looking f…

How could allowing random countries to spy on your customers not be considered a hindrance?

Don't you think this would cost you future customers?

Post reply on HN