Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

441–450 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#441
post #159

Earlier quoted context omitted.

500 unrelated accounts all deposit money into a single shared account. From that shared account, payments are made to 1,000 other accounts. None of the amounts match the original deposits, even when summed. Whose money is whose? This is an oversimplification, but it should give you a rough idea of how difficult it is to trace Bitcoin.

Authorities might already know mixers service providers and a subpoena will give them all info they need. Not sure tho, I haven't used bitcoin but there always be weak link somewhere

You clearly have no idea what you're talking about.

Re: US travel firm $4.5M ransom negotiation open chat

#442
post #349

Earlier quoted context omitted.

At the bottom of the thread the ransomers gave them security advice. Therefore this is an "unplanned penetration test" and gets filed as "consulting" on the expenses side of the accounts. Almost all money going out of a business can be deducted from money coming for purposes of counting taxable profit. I'm having a hard time thinking of one that isn't.

In Portugal you can actually make a payment as "Confidential or Undocumented Expense" (with no invoice supporting it), making it taxable instead of tax deductible.

That's ... not a massive loophole used to hide money from taxation?

Re: US travel firm $4.5M ransom negotiation open chat

#443

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

Cryptocurrency can’t really get a fair shake at being legitimate until it’s treated by governments as currency, which means not taxing its capital gains. Criminals don’t care about filing tax returns for digital assets, which is why we see them use it as currency. When you or I try to use it as a currency, we’d have to file a tax return if the value of it changes (at least in the US) If we saw governments ease up on…

Who said governments don't tax capital gains for fiat currencies? Honestly, it's pretty much the same thing. Example : https://www.canada.ca/en/revenue-agency/services/tax/individ...

Re: US travel firm $4.5M ransom negotiation open chat

#444
post #5

Gotta love that they pitch this as a "service" they provide. The person talking to them must have been seething at having to treat them like "professionals" too.

Isn't that almost a cliche of organized crime? It's not enough to be rich, powerful, feared, people also have to pretend to like and respect you?

Haha possible. Haven’t had much encounters with organized crime thus far thankfully

Re: US travel firm $4.5M ransom negotiation open chat

#445
post #17

Earlier quoted context omitted.

To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. The money is funnelled to a criminal group, but what difference does it make? Some people consider the USG to be a criminal group; many people are out on the streets for that. My tax dollars directly go to corrupt crooks and nonexistent companies claimi…

> It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. That argument could be used to justify any theft or even kidnapping. I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives. There are real harms to ra…

In addition, the company isn't the only victim in a ransomware attack, its customers are too.

And does anyone really believe the hackers deleted the data off their own servers? They can easily double-dip by selling that information. It's valuable, so why would they delete it?

Re: US travel firm $4.5M ransom negotiation open chat

#446
post #321
post #271

Earlier quoted context omitted.

It's true that Bitcoin is a poor medium of exchange: it's not stable, has slow transaction times, does not work well with mobile devices, and has intimidating identifiers, but it did open the door to new ideas that will likely soon have a huge impact on exactly the uses you're describing.

I feel like I've been hearing this for over 5 years. I hope it materializes, but to be honest it's hard to not be skeptical, not in the least because a lot of the original values of Bitcoin/cryptocurrencies seem to have been subverted by certain people to serve their own needs (which ... is what usually happens if there are no rules to set boundaries).

I'm a little biased, but check out celo.org and valoraapp.com. Celo is a Proof of Stake protocol built to work efficiently on mobile, with stable value, and with phone numbers as identifiers.

Re: US travel firm $4.5M ransom negotiation open chat

#447
post #442

Earlier quoted context omitted.

In Portugal you can actually make a payment as "Confidential or Undocumented Expense" (with no invoice supporting it), making it taxable instead of tax deductible.

That's ... not a massive loophole used to hide money from taxation?

No, because they are taxed at basically the maximum marginal rate. There are cheaper ways to avoid taxation.

It's seldom used and only when there's no alternative (e.g. a lost invoice that you don't want to charge your employee for).

Re: US travel firm $4.5M ransom negotiation open chat

#448

Earlier quoted context omitted.

> We need to make laws in western countries that paying off these kinds of ransoms is illegal. That'd be the sort of counter-productive legislation we see too often. The only result would be to push this underground and to keep authorities in the dark. It might end up helping criminals. A similar case has been made about corruption: If you're asked for a bribe by, say, a corrupt official you usually have no choice bu…

I disagree with “no choice but to pay”, so long as the bribery is illegal and the relevant legislation not entirely hollow. You may be able to clearly document the attempted bribery, and report it to the relevant authority—which may be a central agency of some form, or may be just going up the chain within the same organisation. Success will vary by country, authority and magnitude of offence. But even threatening to…

When you are a nobody facing a demand for a bribe by an official or police you have no choice but to pay.

> nd more institutional bribery can generally be waited out, at the least. Even if it’s occasionally a long wait (like, months instead of days, or years instead of weeks).

And in the real world that means you pay.

> wouldn’t dream of driving without wearing a seatbelt.

Because people understand that it is in their interest to wear a seatbelt. That's very different from paying a a bride that is often in the person's interest.

It was an Indian economist, and chief economist at the World Bank, that suggested making payment of bride legal to shift incentives [1]. You still have an incentive to pay but also an incentive to report it, while it increases the risk for the bribe-taker. Whether that would work or not, it recognises that the key to influencing behaviour is to create the right incentives.

[1] https://www.bbc.co.uk/news/business-20218833

Re: US travel firm $4.5M ransom negotiation open chat

#449
post #442

Earlier quoted context omitted.

That's ... not a massive loophole used to hide money from taxation?

No, because they are taxed at basically the maximum marginal rate. There are cheaper ways to avoid taxation. It's seldom used and only when there's no alternative (e.g. a lost invoice that you don't want to charge your employee for).

Ach, sorry, I misread your comment -- so, it doesn't change their tax situation, so there's no reason to falsely use this. Understood. Never mind.

Re: US travel firm $4.5M ransom negotiation open chat

#450
post #379
post #344

Earlier quoted context omitted.

Isn’t it already a felony to attack computer systems and hold data for ransom? That doesn’t seem to be working flawlessly.

Yes, but the affected company is the one paying the ransom. Make that a felony and suddenly their choice is to invest in security or risk having their business halted for potentially months.

Or, pay ransoms secretly, which is of course what companies would do.
Post reply on HN