Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

141–150 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#141

Earlier quoted context omitted.

1) You need to be able to tie a BTC address to a human 2) Mixers

Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?

500 unrelated accounts all deposit money into a single shared account. From that shared account, payments are made to 1,000 other accounts. None of the amounts match the original deposits, even when summed. Whose money is whose?

This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.

Re: US travel firm $4.5M ransom negotiation open chat

#142

Another windows local admin/group/domain thing. When are IT departments going to take it off their networks? Why have LANs at all, for most back office work? Immutable, versioned files in managed cloud storage eliminates the locker threat (not the disclosure one though).

When work for a big IT team at a company that's already invested a fortune in on-prem storage and your job depends on pre-cloud procedures, you keep your mouth closed and do what's asked of you. After all, if the company gets hacked, it's usually just the CISO that gets fired. Not you.

You made a very good point about Windows GPOs. The delivery mechanism for them vs. how macOS does it shows how dated of a paradigm they are. It's bringing back memories to me of importing ADMX templates, gpupdate.....

Re: US travel firm $4.5M ransom negotiation open chat

#143
post #120

Earlier quoted context omitted.

>Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. >This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime. Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current impleme…

Banning... how?

The entire thing relies on several things: nearly always-on connectivity, ability to convert to USD, crummy UX, and legit cover.

A ban would do serious harm to 2, 3 and 4. If no one could pay legitimately and it would become (ever more) difficult to launder, the ransomware demands would die. The first (connectivity) could be impacted as well. What would happen when traffic shaping makes sync take longer and when every LN transaction risks losing money due to disconnections?

Re: US travel firm $4.5M ransom negotiation open chat

#144

Earlier quoted context omitted.

> n a difficult to trace manner is a new thing I still don’t understand - how is Bitcoin difficult to trace when there is a global immutable public record of all transactions?

https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

What happens when crypto tumblers run away with the money

Re: US travel firm $4.5M ransom negotiation open chat

#145

Earlier quoted context omitted.

1) You need to be able to tie a BTC address to a human 2) Mixers

Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?

When you use a mixer, there’s a delay between when you put your money in and when it comes back out. The mixing service randomly splits up the transaction into batches and sends them out at different times. So even if you know that somebody sent to a mixer (perhaps as an investigator you could find out mixer addresses by sending lots of transactions to the mixer service yourself), you wouldn’t be able to associate those inputs with any particular output.

If the mixer has a lot of users, at best you could determine that the your target is among the entire set of people who used the mixer this hour/day. Although if the mixer was compromised, you’d have everything. That does seem like a substantial risk. It’s kind of like deciding to trust your vpn. You could mitigate that risk by using multiple mixers.

Re: US travel firm $4.5M ransom negotiation open chat

#146

I found it interesting none of these sites actually provided the alleged bitcoin wallet address. I found it @ https://www.blockchain.com/btc/address/13nmJ3SsNB5pSyQrmX3e6...

Kinda funny to see 1BTC sent to check it worked before they sent the rest. Cant undo it like a wire transfer...

Re: US travel firm $4.5M ransom negotiation open chat

#147
post #112
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

It doesn't matter how big your company is, every penny still gets counted. This will come out of some department's budget and have an adverse impact on operations or even cost them some employees. Hopefully whoever was auditing their security.

For all we know their security folks have been warning about something like this and have been pooh-poohed by senior management for years. Sometimes the auditors can only lead the horse to water.

Re: US travel firm $4.5M ransom negotiation open chat

#149
post #126
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

It wouldn't work in this case. It will be similar to drug trade, where everything is hush hush and the price probably will go up. It will just push more innocent people into white colar crime. You are running the company. You spend all your life getting to CEO position. And then boom breach and your company has massive loss, lawsuits and you are out of the job. Probably 9/10 CEO types will just engage in a crime to a…

> It will be similar to drug trade, where everything is hush hush and the price probably will go up.

It's somewhat more difficult for actual businesses to buy drugs, though, isn't it? The money would show up in audits and all that.

Re: US travel firm $4.5M ransom negotiation open chat

#150
post #135

Earlier quoted context omitted.

Not sure how you arrived at a negative value. Or are you suggesting there is no positive use-case that could offset it?

I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.

That's because you live in a country with a functioning currency.
Post reply on HN