Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

261–270 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#261

Earlier quoted context omitted.

The previous owners of my house dropped several hundred dollars on a Medeco lock. Keys are a pain in the ass to replace, and there is literally a set of 3 windows within reach in the porch that could be opened trivially. The biggest feature of any lock is breaking into a locked house is a felony for the perp.

My boss once bought a really expensive lock with a magnetic key. He was going on about how it was unpickable. When the key was forgotten one time, we found it could be opened by sticking scissors in and turning. I'm not sure what the moral is. Your comment reminded me of this story.

My house has one sided locks all over it. Kids are constantly locking themselves out of rooms / bathrooms. We use dry spaghetti to unlock them. Keep a few above door frame.

Leaves guests bewildered when they come to stay.

Re: American spy hacked Booking.com, company stayed silent

#262

Earlier quoted context omitted.

Even if a smart lock used ROT13 encryption, the easiest way to defeat it is still probably a mechanical attack. The state of mechanical security is a whole new level of weak.

The previous owners of my house dropped several hundred dollars on a Medeco lock. Keys are a pain in the ass to replace, and there is literally a set of 3 windows within reach in the porch that could be opened trivially. The biggest feature of any lock is breaking into a locked house is a felony for the perp.

I hope at least the garage door, doors, and all your windows have 'circuit breaker'-style sensors (inside the window frame) that trigger the alarm when is activated.

Long time ago I had to upgrade my whole bloody alarm system of my old house because I wanted to insure a watch.

Re: American spy hacked Booking.com, company stayed silent

#263

Earlier quoted context omitted.

what are you, a bartender?

I can dislike dishonesty even when I'm not the victim.

I see your point but to be fair at least I threw some money in the tip jar and treated the service people nicely, and quit after a couple of weeks of hijinks.

Kind of sounds like you need to have some fun on a vacation.

Re: American spy hacked Booking.com, company stayed silent

#264
post #258

From https://en.wikipedia.org/wiki/Black_Chamber "Gentlemen do not read each other's mail."

Henry Stimson later clarified he only meant close allies.

It is also hard to take moral guidance from the guy who oversaw Japanese internment camps in the US and decided to change the city we dropped the atomic bomb on because the original target was where he went on his honeymoon.

Re: American spy hacked Booking.com, company stayed silent

#265
post #202
post #19

Earlier quoted context omitted.

Worse still, they would have to read Perl code :)

Why would anyone build something like that in Perl? I could only see it being done “just because”. Wasn’t Perl specifically designed for the quickly code it once and not change it again case?

Perl was the best/fastest way to write web applications (think FastCGI, mod_perl) before PHP stole that crown in late 90s.

Re: American spy hacked Booking.com, company stayed silent

#266
post #37

Earlier quoted context omitted.

It would have turned into one of the hundreds of articles about Russian, Chinese, Iranian, Ukrainian, North Korean, etc. hackers meant to solidify people's world view that we have a "good side" and a "bad side" of the world. The reality is that we have a "bad side" and a "worse side" but that's a hard pill to swallow for the regular person. Hence the deluge of articles meant to "straighten up" the view.

You’re mistakenly assuming that everyone sees intelligence services as bad, because as much as many people are concerned, “an enemy of an enemy is a friend.”

[deleted]

Re: American spy hacked Booking.com, company stayed silent

#267
post #17
post #10

Earlier quoted context omitted.

They did something; they found someone else to blame: "The management claims it was not legally required to do so at the time, based on advice it received from the law firm Hogan Lovells." Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable...

> Although a company the size of booking.com should have its own qualified legal department, so that may not shield them from being liable... How does retaining outside counsel as opposed to employing internal counsel have any bearing on liability? Asking genuinely. I'm not an attorney.

From a legal perspective, internal counsel may not be able to shield certain things as attorney work product. If an outside counsel is representing the firm the attorney work product privilege is almost impenetrable (in US law). And the privilege can be asserted across all dealings around the investigation and the results. Any firm relying solely on internal counsel needs new counsel. Retainers are a thing.

Re: American spy hacked Booking.com, company stayed silent

#268
post #27

This isn’t surprising to me. I know lots of people who work for this company in the Netherlands, and I’ve heard a lot of inside stories about the questionable business practices that go on there. Starting at the very top, with the fraudulent marketing lies to sell you rooms because there’s only X number of rooms left, which is entirely bogus, and for which the courts have punished them, if I recall. They’re not inter…

Yeah, there's little regard for legalities as long as it's not _obviously_ bothering clients. Lying to both customers and partners doesn't seem to raise any eyebrows.

Re: American spy hacked Booking.com, company stayed silent

#269

Earlier quoted context omitted.

>> black hat hackers How are foreign intelligence services not black hats? They are stealing data in order to use it for any number of non-nice things. Not selling the data on the dark web doesn't bleach their hats.

This line of thinking comes from buying into the narrative that America (and west) is by definition good and so their activities are fine no matter what. They hack and steal data, we are ok with it. It's extremely dangerous.

Could we call it digital colonialism ?

Re: American spy hacked Booking.com, company stayed silent

#270
post #171

Earlier quoted context omitted.

I don't think anyone assumes the booking for their next family vacation or business trip can't be tracked. They use their credit card and their telephone number at least As for losing the customer base of drug kingpins and wanted terrorists, they're probably OK with losing them

You are assuming that the only black hat hackers are "trustworthy" Americans. There are a list of countries where selling on any of the collected data on the black market would either be condoned or actively pursued to maximise disruption. Would you be happy for a database of holidays to be sold to a crime ring to select their next best target for a burglary ? Or more realistically, would you be happy for such state…

> abused by the good "guys"

quotation marks are on the wrong word.

Post reply on HN