Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

341–350 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#341
post #120

Earlier quoted context omitted.

>Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. >This kind of attack would be almost impossible in the pre-bitcoin era.... Instead democratizing currency, we're democratizing large scale crime. Just wanted to make this same point - right now, cryptocurrency has negative value for society. Perhaps this is a justification for banning the current impleme…

We need to make laws in western countries that paying off these kinds of ransoms is illegal. It gives money to criminal elements and only encourages this. I also thought it would be possible for powerful law enforcement groups to follow the bitcoins even through exchanges. Why does this not run into the worldwide hunt for the perpetrators?

> We need to make laws in western countries that paying off these kinds of ransoms is illegal.

That'd be the sort of counter-productive legislation we see too often. The only result would be to push this underground and to keep authorities in the dark. It might end up helping criminals.

A similar case has been made about corruption: If you're asked for a bribe by, say, a corrupt official you usually have no choice but to pay and once you have paid you are in it with them, both criminals, so no-one talks.

Re: US travel firm $4.5M ransom negotiation open chat

#343

Earlier quoted context omitted.

In the US for example, there's an actual field in your 1040 tax return for entering income from otherwise undeclared illegal businesses. Putting your drug or extortion money there and paying taxes is not admitting guilt and can't be used against you IIRC.

What does one gain by doing this? Is there a particular incentive apart from one's own principles?

Tax fraud is usually much more painful to suffer from instead of a simple drug charge or illegal gambling charge. If you get nicked on drug charges there will be parallel reconstruction to get you on tax fraud despite this "not happening" between US government branches.

Re: US travel firm $4.5M ransom negotiation open chat

#344

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

Isn’t it already a felony to attack computer systems and hold data for ransom? That doesn’t seem to be working flawlessly.

Re: US travel firm $4.5M ransom negotiation open chat

#345
post #213

Earlier quoted context omitted.

That's because you live in a country with a functioning currency.

I keep hearing that, but I am not familiar with any data that shows actual widespread use by common people* in those countries without a functional currency. Most of these countries barely have a stable internet connection or even stable electrical power, so I wouldn't surprised if these 'currencies' aren't so helpful in practice. * Note that use by corrupt politicians to launder their ill-gotten gains is not a posit…

I pay for translation services in cryptocurrency (XMR lately) to Venezuelan citizens who can't readily use USD. Easily thousands of dollars per year.

Re: US travel firm $4.5M ransom negotiation open chat

#346

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

I'm sure criminals would like that. Victims would still have an incentive to pay, but also an incentive not to say anything.

Re: US travel firm $4.5M ransom negotiation open chat

#347
post #309
post #299

Earlier quoted context omitted.

The main one I know of is international money transfers (remittances). Usually these have to go through an oligopoly that sets the fees and exchange rates to be favorable to itself. This is the kind of market that's pretty big on the international scale, but it's completely boring and non-sensational to read about a bunch of people who are sending $400 to their moms on a regular basis.

As far as I know, nearly everyone uses Western Union (Transferwise etc. etc.) for that. Bitcoin is too costly* and complicated for most people. * Two set of fees to exchange crypto to fiat + transfer fee compared to one set of fiat currency exchange + transfer fee.

BTC is not the only cryptocurrency used there. I've sent LTC and XRP most often, but XMR lately. tx fees need not be large (also Lightning Network exists).

Re: US travel firm $4.5M ransom negotiation open chat

#348

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

Given that the alternative is usually the business folding, I don't think this is likely to happen.

Edit: also, I don't think that making getting hacked more onerous while keeping software developers completely legally immune from liability for the software getting hacked would be politically sustainable either...

Re: US travel firm $4.5M ransom negotiation open chat

#349
post #182
post #134

Earlier quoted context omitted.

Isn’t stuff stolen in a theft/robbery deductible generally?

The ransom payment isn't really a theft or robbery, they didn't have to give it.

At the bottom of the thread the ransomers gave them security advice. Therefore this is an "unplanned penetration test" and gets filed as "consulting" on the expenses side of the accounts.

Almost all money going out of a business can be deducted from money coming for purposes of counting taxable profit. I'm having a hard time thinking of one that isn't.

Re: US travel firm $4.5M ransom negotiation open chat

#350
post #202
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

It might over time. If I was deploying ransomware, the first thing I would do after receiving a ransom payment from a company would be to try them again in a month or two.

And if you don't 'visit' them in a month or two, someone else like you will visit them. Now they know their security is crippled, there is no way the patched all holes (system, process, operations) in such a short notice, and we know they can be blackmailed and pay big money.

The only way to mitigate this risk is actually walk the walk (implement appropriate security controls).

Post reply on HN