Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

361–370 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#361

Garmin, now this, in one week. I beleive it is much easier to pull a trick like this with the help from the inside. If so, with malicious insider's incentives in a ballpark of hundreds of thousands we are doomed :(

And yet, these hacks tend to be done with some social engineering and no insider knowledge. Many companies aren't well protected, you don't need an insider to hack them.

Re: US travel firm $4.5M ransom negotiation open chat

#362

Earlier quoted context omitted.

Probably a condition of the ransom. If the wallet address is known, then it can be blacklisted by exchanges.

Lol as if they'd just send straight to an exchange.

Maybe not, but it still makes them easier to trace.

Re: US travel firm $4.5M ransom negotiation open chat

#363
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Not that but you could punish companies severely for the security practices that led to the hack. If those are high enough, it could make better security cheaper than paying randsom.

Re: US travel firm $4.5M ransom negotiation open chat

#364
post #190

Earlier quoted context omitted.

Do you want a solution that makes such an attack unprofitable to execute (i.e. it raises the cost of doing a similar attack above $4.5M)? Buy insurance and pray. There is not a single readily available enterprise solution that would even dare to put that in writing, let alone deliver. If there is one that does dare, ask to test their claim by having the deal conditional on them putting out an open $4.5M bug bounty an…

Not a good test. If they expect a decent ROI, the attack can't cost any amount up to $4.5M to execute. The $4.5M isn't a guaranteed outcome from such an attack. Some targets may not be willing to pay, or may only be willing to pay a substantially smaller amount. Also, part of the execution cost is the non-monetary "breaking the law" factor. For instance, would you rather make a legal $1M or an illegal $2M?

Are you saying it is a bad test because it overestimates the difficulty? If so, I agree that it overestimates the difficulty. My argument is that nobody would dare to accept such a test, which is clearly an overestimate of difficulty, therefore nobody is even close to achieving the actual number. If you wanted a more accurate estimate of security you would probably need to bump it up by a factor of 3-5x to account for execution risk.

If you are not, I am not sure what you are arguing since all of your statements show how the test overestimates the difficulty. The test is designed to identify, with reasonably high confidence, whether any attack is profitable given a specific upside. Therefore it should be as easy as possible for a legitimate bug that could result in at least a $4.5M upside to be paid.

A 100% guaranteed legal payout clearly minimizes the risk and thus allows more attacks below a $4.5M cost to execute to be profitable. Any other form of payout means the cost to execute must be lower to be profitable. Put another way, if it is unprofitable to do it totally legally for some amount of money, it is probably even more unprofitable to do it illegally for the same amount of money (obviously this excludes cases where you might be able to gain a higher upside, but then we are not talking about mitigating attacks with a certain upside), therefore this estimate should be no lower than the true cost to execute (on average).

To use your examples:

If they want a decent ROI, the cost of attack must be significantly less than $4.5M to execute to be a good investment. ROI of illegal actions usually needs to be higher to make up for the risk since you would almost always choose a legal action with the same ROI.

If the probability of payout is less than 100%, then the cost of attack must be less than $4.5M to make up for the reduced probability of success. The probability of payout for a bug bounty is usually higher than the highly variable payout of an attack. Also since the buyer is using this to make a quality decision and has authority to force the vendor to pay out with the stated scheme, it is in the buyers best interest to pay out credible attacks.

If the non-legal nature is a serious cost, then the cost of attack must be less than $4.5M for the illegal case to make up for the extra risk and cost. Non-legal actions usually come with extra costs compared to legal actions and thus have to be even more profitable to be worth doing.

Therefore, if a $4.5M bug bounty (where payout is decided by the product buyer) is not claimed after some reasonable amount of time we can conclude, with some reasonable amount of confidence, that the lowest risk option is likely unprofitable. Therefore, higher risk illegal options with the same upside are even less likely to be profitable. Thus, the test is a relatively good lower-bound for identifying if attacks with a $4.5M upside are actually being mitigated. If you can not even institute this lower bound, then you are nowhere near the necessary level.

Re: US travel firm $4.5M ransom negotiation open chat

#365
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

I don't think that budget is the problem. You can be very safe without a big budget. It's a lack of priority and management valuing quick development over security.

Re: US travel firm $4.5M ransom negotiation open chat

#366
post #304

Earlier quoted context omitted.

Don’t be surprised if companies would rather roll the dice than pay whatever it costs to prevent the problem. $4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy. Tough call.

How many times would you need to do a security audit before this paid for itself?

A company of this size? Just 10 or 20 times I'm guessing, which really doesn't seem like a high multiple. This is why laws are required to correct the incentives here.

Re: US travel firm $4.5M ransom negotiation open chat

#367

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

> It’s sad that it’s come to this point but the end result may be better for everyone.

Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware".

Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe development environment. No copy pasting from and to email, etc. Horrible environment to work in.

Re: US travel firm $4.5M ransom negotiation open chat

#368
post #349
post #182

Earlier quoted context omitted.

The ransom payment isn't really a theft or robbery, they didn't have to give it.

At the bottom of the thread the ransomers gave them security advice. Therefore this is an "unplanned penetration test" and gets filed as "consulting" on the expenses side of the accounts. Almost all money going out of a business can be deducted from money coming for purposes of counting taxable profit. I'm having a hard time thinking of one that isn't.

In Portugal you can actually make a payment as "Confidential or Undocumented Expense" (with no invoice supporting it), making it taxable instead of tax deductible.

Re: US travel firm $4.5M ransom negotiation open chat

#369
post #182
post #134

Earlier quoted context omitted.

Isn’t stuff stolen in a theft/robbery deductible generally?

The ransom payment isn't really a theft or robbery, they didn't have to give it.

You don't have to pay Bill $40/hour in wages, you could have probably hired someone who could do the job for $30/hour.

Yet, regardless of how much you pay Bill, his wages are tax-deductible.

Re: US travel firm $4.5M ransom negotiation open chat

#370

Earlier quoted context omitted.

When I started my career I'd always hear old greybeards talk about "oh this one time.. some certain thing happened, and everyone learnt a lesson" and I feel like I just witnessed one of those come into existence

Don’t be surprised if companies would rather roll the dice than pay whatever it costs to prevent the problem. $4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy. Tough call.

But it's not like the problem is solved now. They still need to secure their systems, especially now that criminals know that this company is willing to pay out.
Post reply on HN