Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

181–190 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#181
post #159

Earlier quoted context omitted.

500 unrelated accounts all deposit money into a single shared account. From that shared account, payments are made to 1,000 other accounts. None of the amounts match the original deposits, even when summed. Whose money is whose? This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.

Authorities might already know mixers service providers and a subpoena will give them all info they need. Not sure tho, I haven't used bitcoin but there always be weak link somewhere

I would be very surprised if any mixer operators are located in places that care in the slightest about a US subpoena (russia, etc).

Re: US travel firm $4.5M ransom negotiation open chat

#183
post #71
post #45

Earlier quoted context omitted.

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

What's the difference? Cut deeply enough - take out entire companies - and people lose their jobs. People can't eat. People lose their health insurance that allows them to afford their life-saving medication. At some point, it's not just "big corporations"; it's the people that work for them, too.

"People lose their health insurance that allows them to afford their life-saving medication."

Only in one country on the planet.

Re: US travel firm $4.5M ransom negotiation open chat

#184
post #45

Earlier quoted context omitted.

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

Ok, and now a hospital with critical medical information gets hit by the ransom. What then?

Well in the case of UCSF, they paid $1.14M[1].

But really, I expect such a law would provide for exceptions, with a maximum payout capability. And for such a law to come after an offsite airgap backup requirement for such entities.

But really, the answer is that the equivalent physical criminal action: walking into a hospital and absconding with all of their medical records, would result in criminal action against the thief. Their actions may be akin to manslaughter if deaths result.

[1]: https://www.ucsf.edu/news/2020/06/417911/update-it-security-...

Re: US travel firm $4.5M ransom negotiation open chat

#185
post #171

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

Isn't 'tumbling' literally a money laundering operation?

yes, and it proves GP's point about crypto enabling crime. It's trivial to implement.

It's just a ledger kept outside so there is no link between the money going in and the money coming out.

Re: US travel firm $4.5M ransom negotiation open chat

#186
post #17

Earlier quoted context omitted.

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

> It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. That argument could be used to justify any theft or even kidnapping. I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives. There are real harms to ra…

> The government should similarly hold firms accountable when they are hacked

What should the govt so when govt agencies get hacked?

Re: US travel firm $4.5M ransom negotiation open chat

#187
post #82
post #36

This is a very recent event (ransom was only paid on 07/28). They're not out of the woods yet. Whats the bet they get crypto locked again next week?

From what I read, the hackers always keep their words. Otherwise nobody will pay them next time.

This particular hacker. What's preventing another hacker group doing the same? The company is not able to fix all of the security issues immediately.

Re: US travel firm $4.5M ransom negotiation open chat

#188

Another windows local admin/group/domain thing. When are IT departments going to take it off their networks? Why have LANs at all, for most back office work? Immutable, versioned files in managed cloud storage eliminates the locker threat (not the disclosure one though).

When work for a big IT team at a company that's already invested a fortune in on-prem storage and your job depends on pre-cloud procedures, you keep your mouth closed and do what's asked of you. After all, if the company gets hacked, it's usually just the CISO that gets fired. Not you. You made a very good point about Windows GPOs. The delivery mechanism for them vs. how macOS does it shows how dated of a paradigm th…

Scenario 1: Keep head down, company gets attacked, shrug shoulders.

Scenario 2: Sell solid security and backup principles to management, fighting annoying budget and corporate culture battles along the way. Company does not get attacked. Nobody notices.

Scenario 3: Quietly set up an immutable backup service with hourly backups for your enterprise without anyone really noticing. Company gets attacked. "Actually, we do have backups. We can just reformat all those Windows machines." Hero!

Re: US travel firm $4.5M ransom negotiation open chat

#189

Earlier quoted context omitted.

1) You need to be able to tie a BTC address to a human 2) Mixers

Do you not tie yourself to your Bitcoin when you try to use it for something physical like turning it into cash or buying a physical asset? Can you not track all Bitcoins going in and out of a mixer?

If you understand enough about Bitcoin to know how the immutable ledger works, your questions feel bad faith. One of the biggest “selling points” early on was obviously anonymity.

Re: US travel firm $4.5M ransom negotiation open chat

#190

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

Do you want a solution that makes such an attack unprofitable to execute (i.e. it raises the cost of doing a similar attack above $4.5M)?

Buy insurance and pray. There is not a single readily available enterprise solution that would even dare to put that in writing, let alone deliver. If there is one that does dare, ask to test their claim by having the deal conditional on them putting out an open $4.5M bug bounty and nobody collecting on it (you should also be the one to determine if they have to pay). Every company will either back out or get collected on, no question. This is a good test because if it costs more than $4.5M to do such an attack, then it would be unprofitable to collect on the bug bounty. It is also unlikely to give a false positive (their system is good when it is not) since $4.5M is more than than almost every other bug bounty and it is totally above board, so you will get the best of the best trying to break into the system.

Post reply on HN