Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

201–210 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#201

Earlier quoted context omitted.

There's a lot of potential here. I'm thinking a slow burning Breaking Bad set up that sells itself as a light hearted Fawlty Towers-type show about a wide eyed Monopoly enthusiast fulfilling his dream, but with every season it gets darker and grittier and ends as a tangled web of international crime and corruption. Everything spirals out of control. The hotel is hosting a big conference and the minister of whatever i…

This is almost exactly Ozark, if anyone likes the idea and wants to watch now.

I've kind of assumed that the posters were being ironic and describing Ozark, but maybe not.

Re: American spy hacked Booking.com, company stayed silent

#202
post #19
post #12

I'd feel sorry for anyone who hacked booking.com, they'd end up trying to decipher several petabytes of email data saying basically, "stop sending me hotel offers in Outer Mongolia!"

Worse still, they would have to read Perl code :)

Why would anyone build something like that in Perl? I could only see it being done “just because”. Wasn’t Perl specifically designed for the quickly code it once and not change it again case?

Re: American spy hacked Booking.com, company stayed silent

#203
post #169

Earlier quoted context omitted.

>> black hat hackers How are foreign intelligence services not black hats? They are stealing data in order to use it for any number of non-nice things. Not selling the data on the dark web doesn't bleach their hats.

They are definitely black hats. Intelligence services operating in foreign countries (physically or digitally) are by definition criminals, in that they are breaking the local laws where they are operating / accessing. That they are doing it for a 'good cause' (often debatable) is somewhat irrelevant, that is a risk/reward calculation that the country/agency/spy needs to make themselves. If a a friendly country of th…

>the CIA hacks NL companies and the Dutch RIVM hacks American ones and they share information/metadata

The AIVD is the Dutch intelligence service, the RIVM is the public health institute. I don't think even the most out-there of Dutch conspiracy theorists have accused the RIVM of hacking American companies on behalf of the CIA...

Re: American spy hacked Booking.com, company stayed silent

#204
post #141

Earlier quoted context omitted.

Why?

Would you rather live under the American, Russian, or Chinese government? Probably as simple as that- what's considered damaging in this case likely depends on your preferences.

I would prefer it was China or Russia, if then had a grunge with me, the bar would be higher for them to do something that affected me. Americans can put you on some secret list and generally ruin your life on the basis of nothing

Re: American spy hacked Booking.com, company stayed silent

#205
post #17
post #10

Earlier quoted context omitted.

They did something; they found someone else to blame: "The management claims it was not legally required to do so at the time, based on advice it received from the law firm Hogan Lovells." Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable...

> Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable... How does retaining outside counsel as opposed to employing internal counsel have any bearing on liability? Asking genuinely. I'm not an attorney.

Communications with outside counsel is (more) protected by privilege than with internal.

Re: American spy hacked Booking.com, company stayed silent

#206
post #202
post #19

Earlier quoted context omitted.

Worse still, they would have to read Perl code :)

Why would anyone build something like that in Perl? I could only see it being done “just because”. Wasn’t Perl specifically designed for the quickly code it once and not change it again case?

Perl was python before python was python, and booking.com is old.

Re: American spy hacked Booking.com, company stayed silent

#207
post #69

Earlier quoted context omitted.

> Who is to say if a room was occupied or not that night, if that foreigner who paid in cash really existed. Here in th EU, they usually have a look at your passport. I think it's enforced by law in some places. Government overreach

I don't understand your point. In "Breaking Bad" if he had a hotel instead of a car wash, he could claim it was 95% occupied every night. Thereby washing large quantities of cash. In the EU do they have to keep IDs for a certain amount of time or something? If so then you just keep a few on file and hand those over when asked.

It depends on countries, in Italy the data on the ID of guests (of a hotel or similar) is transmitted electronically (within 24 hours) to the Police.

This since a few years, 2013 I believe, until then you had to send (via snail mail) the "records" or bring them daily to the nearest Police (or Carabinieri) station.

The provision is since 1978, it was a Law approved in a short time due to the "emergency of fighting terrorism".

Re: American spy hacked Booking.com, company stayed silent

#209
post #72

Earlier quoted context omitted.

All that intelligence and they still can't figure out how to stop a bunch of unemployed basementarians from organising on Facebook to storm one of their principal seats of government... (Sorry for the Twitter-grade comment - but I do sometimes wonder what these people really spend their time doing, that they couldn't catch that one.)

Oh they knew it was going to happen, it's just that they don't have the people to actually intervene, and the ones that did were either in on it, indecisive, or ordered to not intervene from higher up.

Yeah, I'm not normally a conspiracy theorist, but it's hard to resist that conclusion, given the facts (as is the gist of my other replies above). Well, it's either a conspiracy or a fuckup - or more likely a combination of the two, with different answers for different people in the chain, like you say.

Re: American spy hacked Booking.com, company stayed silent

#210
post #155

If you're a name with brand recognition, and active in a space that allows effective monitoring and/or eavesdropping on the communications of a large number of people then you can consider yourselves either already hacked or a target of various intelligence services. Also beware of employees that are overly eager to have more access than they should have the 'plant' is a very effective way to gain access to data (sup…

> Companies routinely wipe hacks and data leaks under the carpet in the hope that nobody will notice, with the GDPR active they really should stop doing this but it still happens with great regularity. That's why the DPO is mandatory to have and is personally responsible. From my experience ( MSP/MHP/consultancy with lots of clients), post-GDPR data leaks are taken much more seriously.

Yes, it's better now. But it is still bad. We just went from 'terrible' to 'bad'.
Post reply on HN