Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

451–460 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#451

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

> It’s sad that it’s come to this point but the end result may be better for everyone. Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware". Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe developmen…

Can't you just still do a screenshot/screen recording and use OTR on it? Or just use a keylogger for logging what you typed (and just use keylogger to retype it)?

Re: US travel firm $4.5M ransom negotiation open chat

#453

Let this be a lesson to those that say bitcoin and other cryptocurrency has no real value outside of speculation. This kind of attack would be almost impossible in the pre-bitcoin era. The difficulty of receiving that volume of money in that short of a period of time in a difficult to trace manner is a new thing. We are entering a new era where crime can pay in very large sums with orders of magnitude less complexity…

Would you blame for things such as the innocent lives lost to the drug trade and or human trafficking? Banks have been caught stealing more money than there hackers could ever do in their lifetime, with fiat currency. This is what economic freedom looks like, theft is made possible again, but then again, it was always possible to some.

Re: US travel firm $4.5M ransom negotiation open chat

#454

Earlier quoted context omitted.

That's because you live in a country with a functioning currency.

There are simpler solutions, such as dollar bills, or a centralised digital banking system in a trusted currency.

These depend on a functioning legal system in a country that recognizes human rights. Dollar bills may work in incompetent states, but they don't in oppressive ones.

Re: US travel firm $4.5M ransom negotiation open chat

#455

Earlier quoted context omitted.

What does one gain by doing this? Is there a particular incentive apart from one's own principles?

Tax fraud is usually much more painful to suffer from instead of a simple drug charge or illegal gambling charge. If you get nicked on drug charges there will be parallel reconstruction to get you on tax fraud despite this "not happening" between US government branches.

I think you have it backwards. If you commit tax fraud, you will be prosecuted. And the FBI will work with the IRS to do this.

But, supposedly, putting a non-zero value in the "illegal income" field of the 1040 (which ISN'T fraud) both (1) can't be used as evidence against you in court, and (2) isn't reported by default to the IRS to the FBI or other law enforcement agencies, so you don't end up on any watch lists.

Of course you gotta take their word for part (2), but it is their incentive to get every tax dollar regardless of source.

Re: US travel firm $4.5M ransom negotiation open chat

#456
post #444

Earlier quoted context omitted.

Isn't that almost a cliche of organized crime? It's not enough to be rich, powerful, feared, people also have to pretend to like and respect you?

Haha possible. Haven’t had much encounters with organized crime thus far thankfully

I mean, neither have I, but it definitely shows up in pop culture depictions of the mafia and drug lords and oligarchs and warlords.

Re: US travel firm $4.5M ransom negotiation open chat

#457

Earlier quoted context omitted.

Had one of these. All development through Citrix. The security policy was draconian to the extent I’m sure it was well intentioned but led you to do things in the least secure way possible as it was the only way to complete a contract. I.e the servers on the other end running Windows 7 (in late 2019) where so old they didn’t have the required cpu instruction set to run some required software. Likewise input lag was e…

The organization has externalized all the responsibility for the next breach to you, the individual contributor who is breaking security protocol to get work done. When we little employees roll our eyes and say "this doesn't make sense," we're telling ourselves a comforting lie because the situation you describe DOES make sense- from the organizational perspective. Management did everything their rules allow to make…

Get email approval, aka written documentation, of all process steps from people one step up on the food chain. Explain why it’s needed so they are squarely the section maker.

Re: US travel firm $4.5M ransom negotiation open chat

#458
post #430

Earlier quoted context omitted.

No worse than us being unable to take an extremely obvious joke as a joke, and feeling the need to respond to it as if it wasn't meant completely in jest.

Joking is against the HN guidelines. I was completely serious.

You're good, we get it!

Re: US travel firm $4.5M ransom negotiation open chat

#459
post #431

Earlier quoted context omitted.

Nothing will change until they make it a felony to pay a ransom.

On what grounds would you make a monetary transfer like this illegal? Why a felony? What's the punishment? Who gets punished when a public company does it? You can't charge a company with a felony (usually). What about a private company? LLC? Sole proprietorship? What about my laptop, can I pay a $1000 ransom for that?

I guess same as violating economic sanctions since it is similarly funding a group that is by definition hostile to the US’s economic interests.

Re: US travel firm $4.5M ransom negotiation open chat

#460

Earlier quoted context omitted.

When you use a mixer, there’s a delay between when you put your money in and when it comes back out. The mixing service randomly splits up the transaction into batches and sends them out at different times. So even if you know that somebody sent to a mixer (perhaps as an investigator you could find out mixer addresses by sending lots of transactions to the mixer service yourself), you wouldn’t be able to associate th…

>you could find out mixer addresses Why would the mixer need to reuse addresses when you could create a brand new one each time.

Investigators could be sending many small transactions into the mixer all the time. Depending on the transaction volume and how the mixer works, they could identify most of the mixer’s transactions this way. This would allow them to show that somebody sent money to or received money from the mixer.
Post reply on HN