Live data from Hacker News

American spy hacked Booking.com, company stayed silent

nrc.nl

211–220 of 301 posts

Re: American spy hacked Booking.com, company stayed silent

#211
post #190
post #186

The company's response is very much in line with standard Dutch policy. Unless someone forces you to do something, only do the absolute bare minimum necessary to not go to jail. The common term for this is "zesje" (little six in English), which comes from school and university where it's the bare minimum grade to pass. Anything more than the bare minimum is considered a waste of work. Before any Dutch members get wor…

Basically the current Dutch policy on covid measures as well i guess.

Only the Dutch Covid response has set a new low bar for complete incompetence and responsibility avoidance.

Re: American spy hacked Booking.com, company stayed silent

#212

Earlier quoted context omitted.

It’s because booking purchases the rooms wholesale, and typically well in advance of the stay dates. They can offer you a lower price because hotels use them to make their business more predictable.

I work at Booking. We do not do this and never have. Other OTAs do, like Expedia. It’s the merchant vs. agent model.

Oops, sorry!

Re: American spy hacked Booking.com, company stayed silent

#213
post #169

Earlier quoted context omitted.

>> black hat hackers How are foreign intelligence services not black hats? They are stealing data in order to use it for any number of non-nice things. Not selling the data on the dark web doesn't bleach their hats.

They are definitely black hats. Intelligence services operating in foreign countries (physically or digitally) are by definition criminals, in that they are breaking the local laws where they are operating / accessing. That they are doing it for a 'good cause' (often debatable) is somewhat irrelevant, that is a risk/reward calculation that the country/agency/spy needs to make themselves. If a a friendly country of th…

> they are definitely black hats

Both intelligence agencies and cyber-criminals can be considered threats, but they are quite different. Intel agencies would present a serious threat to confidentiality, but are very unlikely to threaten the integrity & availability of business systems.

Re: American spy hacked Booking.com, company stayed silent

#214
post #9

Interesting part from the Dutch version of the article: Booking is nooit eerder op spionage gestuit. Het bedrijf is er ook niet echt naar op zoek. Zolang die geen hinder oplevert, kost het geen geld. De onuitgesproken consensus onder specialisten binnen het bedrijf is: we vermoeden dat inlichtingendiensten meekijken, maar zolang we ze niet zien, maken we ons niet druk. Which roughly translates to We are not looking f…

How could allowing random countries to spy on your customers not be considered a hindrance? Don't you think this would cost you future customers?

Not really?

I mean, this is probably a subset of "I don't have anything to hide, so why do I care about privacy?" But I just went to California on vacation, and, sure, I'll tell the CIA all about it if they want to know.

And I'm one of the people who understands why privacy is important. (Or maybe, based on my previous paragraph, you'll conclude that I'm not, I just think I am.)

I don't know. It just... doesn't feel that intrusive, for some reason. Maybe because for international travel, I already have to use my passport, so they already know. (Yes, maybe it's a different "they"...) Maybe because there's already a "do not fly" list, so somebody's hitting that database every time I try to book a flight, and it wouldn't be that hard for them to log the queries against it. I don't know. But as I said, at least to me, this one doesn't feel that intrusive... and I can't really rationally explain why.

Maybe it's arrogance to assume that most people are no more paranoid than I am. But I think that means that most people probably aren't going to avoid booking.com because of this.

Re: American spy hacked Booking.com, company stayed silent

#216
post #141

Earlier quoted context omitted.

Why?

Would you rather live under the American, Russian, or Chinese government? Probably as simple as that- what's considered damaging in this case likely depends on your preferences.

Maybe I'm just a trivial person, but when I ask myself why I wouldn't live in those places, or any place, I find I'm simply psychologically incapable of being motivated by anything other than living standards, the attractiveness of members of my opposite sex, proximity to friends and family, and all that.

I would much rather not live in China, for the same reason I'd much rather not live in Montana, i.e. the living standards are a LOT lower in China than where I am, and it will be a lot harder to meet someone on places like Tinder I can feel attracted to.

Re: American spy hacked Booking.com, company stayed silent

#217
post #171

Earlier quoted context omitted.

How could allowing random countries to spy on your customers not be considered a hindrance? Don't you think this would cost you future customers?

I don't think anyone assumes the booking for their next family vacation or business trip can't be tracked. They use their credit card and their telephone number at least As for losing the customer base of drug kingpins and wanted terrorists, they're probably OK with losing them

You are assuming that the only black hat hackers are "trustworthy" Americans. There are a list of countries where selling on any of the collected data on the black market would either be condoned or actively pursued to maximise disruption. Would you be happy for a database of holidays to be sold to a crime ring to select their next best target for a burglary ?

Or more realistically, would you be happy for such state actors to identify PEPs (politically exposed person) who are potentially cheating on their partners and use this as leverage to drive through certain political decisions?

There is no such thing as a vulnerability that can only be abused by the good "guys"

Re: American spy hacked Booking.com, company stayed silent

#218

Booking.com parent company also owns: Priceline, Agoda, Rentalcars.com, KAYAK and OpenTable. It also has "subsidiary brands": Rocketmiles, Fareharbor, HotelsCombined, Cheapflights and Momondo. https://www.bookingholdings.com/about/factsheet/

It's worth noting the while some of the other brands may be more well known in the Americas, Booking.com is actually the vast majority of the business. That's the reason why the parent renamed from "Priceline.com" to "Priceline Group" to "Booking Holdings". (Source: I'm a former employee)

Re: American spy hacked Booking.com, company stayed silent

#219

Earlier quoted context omitted.

How could allowing random countries to spy on your customers not be considered a hindrance? Don't you think this would cost you future customers?

Not really? I mean, this is probably a subset of "I don't have anything to hide, so why do I care about privacy?" But I just went to California on vacation, and, sure, I'll tell the CIA all about it if they want to know. And I'm one of the people who understands why privacy is important. (Or maybe, based on my previous paragraph, you'll conclude that I'm not, I just think I am.) I don't know. It just... doesn't feel…

There are many other state actors who can do this, and they wouldn't necessarily have good intentions. Wouldn't it be great if you could use it to identify which PEP (politically exposed person) is using booking.com to cheat on their partner, and use this as leverage to drive through certain political decisions ?

I agree most people aren't going to avoid booking.com, but that doesn't justify leaving your system vulnerable to advanced hackers

Re: American spy hacked Booking.com, company stayed silent

#220
post #70
post #59

Earlier quoted context omitted.

> I'll always book direct once I find one. Sometimes booking direct is expensive and the hotels most of them have a shitty website.

Booking takes a 20% cut of the reservation, so I expect every hotel to gladly you offer a 10% off the booking.com price.

No there is no fixed price, it depends on the hotel. Smaller hotels typically get a worse deal than large chains.

Note: a lot of other "Facts" supporting the idea that booking is all evil are at least partly wrong.

Source: used to work for booking some time ago.

Post reply on HN