Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

381–390 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#381
post #262

Earlier quoted context omitted.

That implementation of offline transactions is a poor one, so the rebuttal would be too, but the reality is that bitcoin can work with offline transactions. You can create the transaction object and hand that over. Transferrable literally as a file. Instead of having over notes with the private key on them. Eventually that transaction will need to be settled onchain. This can work in a world without a familiar lookin…

Well, that was a simple scenario with a simple answer. But there are many other things powerful adversaries could do. For example, what happens when miner traffic itself is disrupted and the network is forcibly split between China and the rest of the world? Leaving everyone at risk of having their transactions overwritten when the network is allowed to reintegrate? Anyway, we don't need a 100% effective ban to get an…

> what happens when miner traffic itself is disrupted and the network is forcibly split between China and the rest of the world?

How would this be done? It only takes a single node capable of connecting to both networks to keep the whole thing working. There are already many nodes working with satellite connections so I'm pretty sure this can't be done even by state actors.

Re: US travel firm $4.5M ransom negotiation open chat

#382

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

Easy to go around that, companies will just pay an offshore company that can recover the decryption key (and they do so by using part of what you pay them to pay the ransom)

Re: US travel firm $4.5M ransom negotiation open chat

#383

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

>Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole.

If your family member was ever kidnapped by a group of terrorists, please keep this in mind before paying those terrorists to not cut their head off.

Re: US travel firm $4.5M ransom negotiation open chat

#384
post #171

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

Isn't 'tumbling' literally a money laundering operation?

Not necessarily, if the source of the money is legal and you're tumbling it just for privacy reasons, it's not money laundering.

Re: US travel firm $4.5M ransom negotiation open chat

#385
post #144

Earlier quoted context omitted.

https://en.wikipedia.org/wiki/Cryptocurrency_tumbler

What happens when crypto tumblers run away with the money

You'll have potentially thousands of criminals trying to get their money back? I don't like those odds but if someone wants to try that go ahead.

Re: US travel firm $4.5M ransom negotiation open chat

#386

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

> It’s sad that it’s come to this point but the end result may be better for everyone. Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware". Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe developmen…

Had one of these. All development through Citrix.

The security policy was draconian to the extent I’m sure it was well intentioned but led you to do things in the least secure way possible as it was the only way to complete a contract.

I.e the servers on the other end running Windows 7 (in late 2019) where so old they didn’t have the required cpu instruction set to run some required software. Likewise input lag was extremely noticeable to the point you hit a key, wait one second then press again thinking something went wrong only to have to press delete some seconds later.

How did I deliver that project? Developed on my own local machine, emailed the artifact to the cooperate email address obfuscated, log in to the corporate laptop, then Citrix, ssh the artifact up to the cloud ec2 servers.

That’s another one. The cloud ec2 servers. No public outbound internet, no internal trusted repositories. What was the accepted way of setting up the servers? Going to random internet sites, downloading random binaries to your Citrix account, scp’ing then to the servers. Trying to explain how stupid this is gets no where in organisations with thousands of people. When you mention trusted artifact repositories, immutable / reproducible builds, deployment pipelines the answer was we don’t have this as they didn’t meet security guidelines.

This was a tier 1 bank. Experience is the bigger the company the worse things are due to the size and different teams/departments being so disconnected.

Re: US travel firm $4.5M ransom negotiation open chat

#387
post #128

Earlier quoted context omitted.

Yeah, same issue with Nobel inventing the dynamite. Just because some people are going to use it for unethical purposes, it doesn't mean that we have to stop the advance of science and technology. Besides, it seems that Bitcoin was inevitable, the internet needs its own decentralized currency.

> The internet needs its own decentralized currency Why?

Because why shouldn't I be able to make an online service and easily allow people to pay for it?

Currently you have to setup accounts with multiple companies in many different countries and pay fees to all of them, it's an absolute mess.

Re: US travel firm $4.5M ransom negotiation open chat

#388
post #276
post #273

Earlier quoted context omitted.

How do you know that? Are you judging based on a representative sample of all uses of cryptocurrency, or the uses you hear about?

If there are any large scale positive uses of cryptocurrency, I'm sure that we would have heard of them by now; The proponents would have shouted them from the rooftops. That said, proponents do have a shot at enlightening us (me and other viewers of the thread). What large scale positive application are you aware of?

It's great for bypassing mass censorship. Wikileaks, Hatreon, 4chan are all prominent examples.

https://wikileaks.org/Banking-Blockade.html

Post reply on HN