Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

21–30 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#21
post #10

We are truly in the age of rich data pirates. I dont see them becoming extinct any time soon with decent ROI like this. I would be curious to learn the % of origins for most attacks. [1] Incompetence by dumb employees [2] Insider attacks [3] Paid cybersecurity protection racket that take down strong systems with stolen tech [4] Unskilled or understaffed security employees

The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.

But wouldn't the payments just end up being passed through?

For example, one way to get around that is you could sign a contract with a foreign consultant firm for "security services", say for 1 year, and they would take your money, and pay a portion of it to the ransomware authors and profit on the rest.

Re: US travel firm $4.5M ransom negotiation open chat

#22
post #5

Gotta love that they pitch this as a "service" they provide. The person talking to them must have been seething at having to treat them like "professionals" too.

I don't see backups in that list. Backups would have avoided the need for decryption, yes?

Re: US travel firm $4.5M ransom negotiation open chat

#23
post #16
post #2

Wow. $4mil just like that.

But now you have $4 million in a bitcoin address linked to criminal activity. Then what? How much do you lose along the way to having laundered cash in hand?

Aren’t there mixer services for that or just convert to monero? This is off an exchange so lots of shenanigans to make things less traceable. I am guessing these people know what they are doing.

Re: US travel firm $4.5M ransom negotiation open chat

#25

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

Continuous append-only backups, where one can't rewrite them without physical access to the system, would - most likely - help with a data loss, malicious or accidental.

Re: US travel firm $4.5M ransom negotiation open chat

#26
post #10

We are truly in the age of rich data pirates. I dont see them becoming extinct any time soon with decent ROI like this. I would be curious to learn the % of origins for most attacks. [1] Incompetence by dumb employees [2] Insider attacks [3] Paid cybersecurity protection racket that take down strong systems with stolen tech [4] Unskilled or understaffed security employees

The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.

Countries where kidnapping was common, are also usually countries with weak government and very ineffective policing, so it's not that simple. Laws like that are in the end pushing responsibilities of law enforcement on the companies and citizens.

I'm against ransoms, but if I was CEO of company that's about to release COVID19 vaccine, or provides jobs to 100k of people, you bet I'd pay that ransom.

But even if that would happen, it's naive to think that corporations wouldn't work around it. They already do, by outsourcing payments to 3rd party companies - they can proxy it via other countries, fake identities, etc, etc.

Re: US travel firm $4.5M ransom negotiation open chat

#27
post #17

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

> It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices.

That argument could be used to justify any theft or even kidnapping.

I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives.

There are real harms to randomware. Companies go out of business, people lose their jobs, people lose their service providers, etc.

To say, "it serves them right for not following proper security" literally can be said for a mom/pop business in a poor neighborhood who didn't have bulletproof glass or bars on their windows. It is negating the fact that (a) the harms are very real and (b) security costs money and resources, which is effectively another tax on their business.

If instead the government made it illegal to pay such ransoms and actively audited large BTC transactions and charged people accordingly, then we could get rid of the incentives to do this in the first place.

The government should similarly hold firms accountable when they are hacked (due to the harms on consumers) and require prompt disclosure of any hacks.

There are ways to incentivize the preferred outcomes without supporting the active theft of property and destruction of someone's business.

Re: US travel firm $4.5M ransom negotiation open chat

#28
post #17

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

I agree. It's a trade-off, especially if you're a startup or a company with a hot product trying to beat competitors to market. Security practices would translate to loss of opportunity, so maybe it's a worthwhile trade-off to pay 1% of the gained revenue to these kinds of threats as a company. Unless there are harsher penalties and victims start caring more (and are given more tools and power to punish the companies that make that trade-off), this situation will remain.

But then again, this makes the barrier to entry even higher for newcomers and gives an unfair advantage to the entrenched players. Tragedy of the commons?

Re: US travel firm $4.5M ransom negotiation open chat

#29

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

It should encourage companies to lock down their infrastructure as well.

Re: US travel firm $4.5M ransom negotiation open chat

#30

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

Offsite offline backups. Redundant ones. This scenario is really no different than if your datacenter had a gas leak and blew up, particularly because you never will ever be able to prove the attacker didn't retain your data somewhere so all you can do is guarantee recovery. Of note in this case is that the thieves only stole 2TB of data - this is a trivial expense to orchestrate a manyfold backup regime for in near real time when the alternative is shelling out millions.

And its also about your threat model. If data leakage of any form threatens your business you need way more security than if you just want to be able to recover from exploits in your publicly facing infrastructure (or the ability for a rogue actor inside the company from sabotaging the business from the inside).

At the most extreme having physical separation of infrastructure with physical token based auth and multiple signature verification to interact with data is going to be a heavy price in diligence to maintain secrecy. At the lowest end having a redundant backup storage array with a cron job on all employee computers to versioned backup files every minute that doesn't have network signin access.

Post reply on HN