Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

221–230 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#221
post #120

Earlier quoted context omitted.

>Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. >This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime. Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current impleme…

> Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current implementations. Ehhhh, I think the overall impact of Bitcoin is negative, but the "democratizing large-scale crime" argument is a pretty poor argument for why that is. First, Bitcoin isn't "democratizing" anything good or bad--people need to stop using this word wi…

What harm reduction happens when the 'large entities' are the courts[0], municipalities[1] or even hospitals[2]? Alleged better safeguarding of our data* isn't worth it.

* I suspect that right now companies find it cheaper to pay than to improve their security.

[0] https://wtop.com/national/2020/05/texas-high-courts-hit-by-r...

[1] https://www.msspalert.com/cybersecurity-research/municipalit...

[2] https://www.wwnytv.com/2020/07/28/western-ny-hospital-recoun... https://edition.cnn.com/2019/10/11/us/alabama-hospital-ranso...

Re: US travel firm $4.5M ransom negotiation open chat

#222

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

At the very least they should require full disclosure, including an analysis of how the hackers were able to breach their systems.

I believe that some laws requiring notification to customers in case of a data breach would already cover this. However, from another article I found this statement from CWT:

"While the investigation is at an early stage, we have no indication that personally identifiable information/customer and traveller information has been compromised."

That appears to be a complete lie based on the chat transcripts, and if so I hope CWT is punished legally for it.

Re: US travel firm $4.5M ransom negotiation open chat

#223

Earlier quoted context omitted.

Something like 95%+ of bitcoin is related to financial speculation, investing, DeFi etc etc. An order of magnitude of more drugs are sold on Cash App and Venmo -- which is why they're in rap songs. As for large scale hacking, extortion and ransom, yes bitcoin is used but it is increasing difficult to cash out in a large way.

>it is increasing difficult to cash out in a large way It is actually difficult to cash out?

I imagine you'd get caught on the off-ramps, since you'd most certainly be reported (by the exchange and/or your bank) to FinCEN. At that point you'd have to contend with the "the money came from bags of cash that just landed in my back yard" problem if federal agents come knocking. As for whether the federal agents will show up at all, I'm not sure. There probably aren't too many criminals who would openly admit that they successfully were able to withdraw their ill gotten gains.

Re: US travel firm $4.5M ransom negotiation open chat

#224

Earlier quoted context omitted.

Can you really not follow the trail from the mixers?

CipherTrace says they lost the trail on the twitter hackers when they threw the btc they scammed into mixers. On the other hand, the Feds arrested a kid in Florida, so my question is... how did they find him?

> It's not so much loose ends as loose everything.

https://news.ycombinator.com/item?id=24013070

Re: US travel firm $4.5M ransom negotiation open chat

#225
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Or start small: tax these payments at a rate of 400%

Re: US travel firm $4.5M ransom negotiation open chat

#226

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

It definitely makes the costs of bad security immediately obvious to the company, rather than just taking the data and selling it, which externalizes the cost to the user.

To me this seems kind of like a company that has a big warehouse full of product that intentionally (or carelessly) neglects its fire alarm and fire suppression system. Or a warehouse of valuable product (say, many pallets of $5000 DSLR cameras) that has very lax security. It's the network security and endpoint security version of that.

It's not absolutely guaranteed that your warehouse is going to catch on fire, or that some guys are going to back up a box truck and clean out your valuable inventory at 3am, but there is a high likelihood of it occurring.

Re: US travel firm $4.5M ransom negotiation open chat

#227
post #126

Earlier quoted context omitted.

It wouldn't work in this case. It will be similar to drug trade, where everything is hush hush and the price probably will go up. It will just push more innocent people into white colar crime. You are running the company. You spend all your life getting to CEO position. And then boom breach and your company has massive loss, lawsuits and you are out of the job. Probably 9/10 CEO types will just engage in a crime to a…

> It will be similar to drug trade, where everything is hush hush and the price probably will go up. It's somewhat more difficult for actual businesses to buy drugs, though, isn't it? The money would show up in audits and all that.

I assume that the money is just laundered and appears as clean money on accounts.

If drugs distributor has money in cash, they will probably engage in loaning short-term to ligitimate businessses with very predictable massive cashflows that pay in cash: construction, cleaning, farming, gambling etc. They don't even have to pay in cash, as long as they have cash receivables that will work as well.

They probably called something like Farming Loans Inc and deliver cash in the beginning of the month for business to meet their cash requirements. They either use it to pay their workers or will just deposit into their account as revenue. Month later they just send me back the check,that is loan pay back that is 100% clean money.

Obviously they will need to manage Farming Loans Inc balance sheet to explain where the seed money for loans are coming from, but that's where white colar crime comes in, where not so good accountants and lawyers will cook books.

For ransom money, the system will be even more cleaner. Somebody will create offshore consulting security firm, that will engage clients in return for consulting fees. So if somebody has breach, they will call them and like we need some consulting. Consulting firm will talk to ransom guys, get keys and then bill the client. So if you accountant and look at the balance sheet of multimillion dollar company, you will see consulting fee invoice and that is pretty much it. For IRS or FBI to dig any evidence, they will have to get a whistleblower plus somehow get the documents of offshore company, which makes it impossible.

In the end of the day white colar crime is 100x bigger then anything to do with drugs/ ransomware and it starts early, because the system pushes people to behave this way and 100% trust base and a lot of behaviours are 100% legal.

The good example is retail brokerage companies that encourage day trading, options trading, FX pares trading. This is just a scam, but hey why not.

Re: US travel firm $4.5M ransom negotiation open chat

#228

Earlier quoted context omitted.

Can you really not follow the trail from the mixers?

CipherTrace says they lost the trail on the twitter hackers when they threw the btc they scammed into mixers. On the other hand, the Feds arrested a kid in Florida, so my question is... how did they find him?

Only 20% of the funds went into mixers.

If I had to guess, the attack was done by a group of people and they split the funds up. Some of them were smarter than others.

It's also possible that the people who have been arrested are simply people who have received stolen goods (knowingly or unknownly). Perhaps they traded something else of value for the Bitcoin and didn't know how dirty it was.

Re: US travel firm $4.5M ransom negotiation open chat

#229
post #135

Earlier quoted context omitted.

I'm just looking at how it is currently used. If after all these years there isn't a positive use-case to offset it, there might not be one at all.

Although I refuted some of your arguments above ( https://news.ycombinator.com/item?id=24033759 ), I agree that cryptocurrency has fairly limited utility, especially given the costs. The biggest issue I have with cryptocurrency is that it’s an utter waste of resources. It incentivizes the consumption of electricity (and talent) purely to print money, rather than to produce value. Yes, currencies provide some value to…

The waste of electricity/mining gear is mostly due to Proof of Work consensus, but moving to Proof of Stake/other consensus algorithms will eliminate basically all waste (eg. Ethereum is moving to PoS).

Re: US travel firm $4.5M ransom negotiation open chat

#230
post #87

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

The folks like this should actually do a startup. Hardening security is often just keeping up with and following checklists, installing proper monitoring, backup and audit software however for large majority of company it is impossible to hire competitive security specialists. These guys can scale up by hiring 100s of employees who they train on different aspects and contract with small firms like these at annual sub…

> These guys can scale up by hiring 100s

If you live in the third world, that immediately puts you on the radar of corrupt government officials and organized criminal organizations that want to extort you.

The ransomware gig allows you to stay small and keep a low profile. Nobody has to know that you are raking in the cash until you pack up your family and book it to Tahiti.

> With their current approach they will almost certainly get traced eventually and end up in jail.

Prison in a first world country is a lot better than getting executed, watching your family get executed, or getting kidnapped and forced into slave labor for the local mafia boss.

Post reply on HN