Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

131–140 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#131

Earlier quoted context omitted.

> Wrong They said they saw a difference. They didn’t say other people didn’t see a difference.

>"They said they saw a difference." Which would be the point, that there are no fundamental differences between corporate assets and human lives.

If I say I like cats, and you find an article saying someone else doesn’t like cats, that does not mean I’m mistaken on the fact that I like cats.

You seem to think they said that ‘everyone sees a difference’. They didn’t. They said ‘I see a difference’. They’re only ‘wrong’ about that if you think they’re lying to us about their own personal position.

Re: US travel firm $4.5M ransom negotiation open chat

#132
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Why not make it a criminal offense for companies who don't take reasonable approaches to preventing such attacks in the first place? We place a lot of trust in companies that hold our personal data (e.g. Equifax), and I'd argue there need to be harsh penalties. The tools exist and guidelines are clear.

It shouldn't be the criminals penalizing them, but here they are filling the gap that the regulators ignored.

Re: US travel firm $4.5M ransom negotiation open chat

#133
post #54
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

While I understand the sentiment, there needs to be a reasonable alternative here. You can’t ask people or organizations not to protect or recover their property if they have no other recourse. I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know…

How about a tax on paying bounties that is used solely to fund agencies that track down and put those engaging in criminal activity online in jail. In order to be allowed to deduct the expense require paying the tax.

Re: US travel firm $4.5M ransom negotiation open chat

#135
post #120

Earlier quoted context omitted.

>Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. >This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime. Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current impleme…

Not sure how you arrived at a negative value. Or are you suggesting there is no positive use-case that could offset it?

I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.

Re: US travel firm $4.5M ransom negotiation open chat

#136

Earlier quoted context omitted.

1) You need to be able to tie a BTC address to a human 2) Mixers

Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?

I think one of the ideas of mixers is to achieve such a large volume of transactions that dedicating man-hours and personnel resources to tracking down every transaction path becomes cost prohibitive on the part of a law enforcement organization.

Re: US travel firm $4.5M ransom negotiation open chat

#137
post #32

Earlier quoted context omitted.

I don't know about that. For one, travel margins are not exactly the same as SaaS margins. Secondly, there's the global pandemic and all, kinda hurts the free cash of most travel companies. I wouldn't be surprised if they genuinely would have trouble coughing up 10 million two days after the attack hit.

CWT is used by corporate travel systems. I'd expect their margins to be similar to enterprise software vendors, rather than other travel agencies.

It depends if they report revenue gross or net. If it is gross that means they recognize all booked travel as revenue (and earn a margin on top of that) instead of just recognizing their fee as revenue. In that case it would be much worse margins than a mature SaaS company.

If I had to guess based on the figure, I would guess gross but I'm not sure.

Re: US travel firm $4.5M ransom negotiation open chat

#138
post #54

Earlier quoted context omitted.

While I understand the sentiment, there needs to be a reasonable alternative here. You can’t ask people or organizations not to protect or recover their property if they have no other recourse. I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know…

How about a tax on paying bounties that is used solely to fund agencies that track down and put those engaging in criminal activity online in jail. In order to be allowed to deduct the expense require paying the tax.

I think this is a step in the right direction, but I'd expand this to be a tax on all organizations that maintain large enough systems to become targets because:

1. Taxing only the victims is adding salt to a wound: these companies are already hurting from being attacked, lost money to the ransomer, and are likely to lose more shortly thereafter due to bad PR. They'll need this money to fix things and hire/consult appropriate experts.

2. Taxing all parties likely to be hit by stuff like this spread the financial burden amount companies of all sizes. Larger companies/targets can thus help protect smaller outfits that aren't well enough funded to field a robust security team or program.

3. Some kind of revenue stream is required here to beef up federal/regional programs relating to cybersecurity. There's no real source of funding for this that doesn't come out of a larger budget. The scope of the problem is large enough that I feel it justifies a specialized agency with it's own budget. Having a dedicated tax applied to parties with need for the service/support seems fair and progressive to me.

Re: US travel firm $4.5M ransom negotiation open chat

#139

Earlier quoted context omitted.

>"They said they saw a difference." Which would be the point, that there are no fundamental differences between corporate assets and human lives.

If I say I like cats, and you find an article saying someone else doesn’t like cats, that does not mean I’m mistaken on the fact that I like cats. You seem to think they said that ‘everyone sees a difference’. They didn’t. They said ‘I see a difference’. They’re only ‘wrong’ about that if you think they’re lying to us about their own personal position.

I edited my original comment to now say "The idea that there are fundamental differences between human lives and corporate assets is flawed."

Thank you for your logic lesson but I fail to see how this changes the discussion.

Re: US travel firm $4.5M ransom negotiation open chat

#140

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

An interesting technical and financial challenge is how they intend to launder and tumble the Bitcoin and eventually turn it into fiat currency. The open nature of the block chain means that third parties can and will track all transactions related to the wallet(s) that received the 4.5m.

I guess figure out the average amount tumbled typically (maybe half a bitcoin - 4kish), divide that by total amount (4.5m), something like 1100 tumbles/mixes? Then spend 1100 days mixing the total sum to keep things as banal as possible (3 years). Possibly randomize the amount tumbled per transaction up to $1000 dollars.

The 4.5m would have to be mixed immediately so the original wallet can no longer be an event source.

Is that the right idea?

Post reply on HN