Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

391–400 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#391
post #170

Earlier quoted context omitted.

> Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better. Is this based in reality? What countries have banned ransom payments for human kidnapping and what people did it “suck” for? My hunch is that if your spouse gets kidnapped and you have the means to get them back, you’ll risk it.

https://www.nytimes.com/1998/02/01/world/italian-ban-on-payi... They are not the only ones, just the first I found on Google.

So when you said “countries” and “historically” you meant “Italy” and “since 1991”?

Good to know you weren’t just talking shit there.

Re: US travel firm $4.5M ransom negotiation open chat

#392
post #304

Earlier quoted context omitted.

Don’t be surprised if companies would rather roll the dice than pay whatever it costs to prevent the problem. $4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy. Tough call.

How many times would you need to do a security audit before this paid for itself?

Not just the audits, but the work to follow through on the audits, too. And follow through correctly.

Re: US travel firm $4.5M ransom negotiation open chat

#393

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

My thoughts, also. It's obvious why they don't, but ideally, every business would take a "we don't negotiate with terrorists" stance on this.

Could governments outlaw these ransom payments?

Re: US travel firm $4.5M ransom negotiation open chat

#394
post #17

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

> To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices.

I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?

Re: US travel firm $4.5M ransom negotiation open chat

#395

Whilst paying the ransom is often advisable in specific cases like these, it’s absolutely a bad thing for society as a whole. Seeing successes like this will encourage organised crime to keep doing this, as they know there’s gonna be a big reward. It’s like the prisoners dilemma. If people didn’t pay the ransom, there wouldn’t be ransomware. But people don’t take precautions, so they have to pay the ransom, leading t…

Not to mention the fact that the money could be going to terrorists or rogue states. This is clearly unethical, and IMHO should absolutely be against the law.

Re: US travel firm $4.5M ransom negotiation open chat

#396

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. It may also lead to companies paying for a more aggressive response. Uber has been known to deal with fraud by eventually finding the fraudster, even in Nigeria, and having them "visited".[1] [1]…

Would you mind elaborating a little bit? To me what you're saying implies extralegal activities, just want to make sure I'm not misunderstanding.

Re: US travel firm $4.5M ransom negotiation open chat

#397
post #90
post #36

This is a very recent event (ransom was only paid on 07/28). They're not out of the woods yet. Whats the bet they get crypto locked again next week?

Why would the hackers do that? It wouldn't help them in any way.

Not necessarily the same attacker but unless the flaws that led to the attack are patched then copycats will target them now they know they will pay up

Re: US travel firm $4.5M ransom negotiation open chat

#398
post #17

Earlier quoted context omitted.

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

> To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?

What makes crime "organised"? There's no indication that this involved more than one thief.

Re: US travel firm $4.5M ransom negotiation open chat

#399

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. It may also lead to companies paying for a more aggressive response. Uber has been known to deal with fraud by eventually finding the fraudster, even in Nigeria, and having them "visited".[1] [1]…

2019, not 2009.

Re: US travel firm $4.5M ransom negotiation open chat

#400

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

> It’s sad that it’s come to this point but the end result may be better for everyone. Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware". Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe developmen…

How do top tier tech companies, who are very likely continuous targets for this kind of thing, avoid ransomware attacks? I know there's nothing like that at my employer.
Post reply on HN