Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

461–470 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#461

Earlier quoted context omitted.

Tax fraud is usually much more painful to suffer from instead of a simple drug charge or illegal gambling charge. If you get nicked on drug charges there will be parallel reconstruction to get you on tax fraud despite this "not happening" between US government branches.

I think you have it backwards. If you commit tax fraud, you will be prosecuted. And the FBI will work with the IRS to do this. But, supposedly, putting a non-zero value in the "illegal income" field of the 1040 (which ISN'T fraud) both (1) can't be used as evidence against you in court, and (2) isn't reported by default to the IRS to the FBI or other law enforcement agencies, so you don't end up on any watch lists. O…

No sorry, I agree with you. I mean if you don't declare your income THEN you get busted on the illegal activity, you are guaranteed to get busted twice.

Re: US travel firm $4.5M ransom negotiation open chat

#462

Earlier quoted context omitted.

What makes crime "organised"? There's no indication that this involved more than one thief.

Organized crime has a specific meaning. Whether this particular outfit is one or more people has no bearing on the use of the term organized crime in this instance.

I asked:

> What makes crime "organised"?

Your answer is:

> Organized crime has a specific meaning

Well... what is it?

Re: US travel firm $4.5M ransom negotiation open chat

#463
post #309

Earlier quoted context omitted.

As far as I know, nearly everyone uses Western Union (Transferwise etc. etc.) for that. Bitcoin is too costly* and complicated for most people. * Two set of fees to exchange crypto to fiat + transfer fee compared to one set of fiat currency exchange + transfer fee.

But you're making an assumption here that both the sender and recipient will be using fiat currency in the end, and that crypto is only being used as means to make the transfer. This is not necessarily true.

IMHO, it's a pretty reasonable assumption, as very few businesses agree to be paid in crypto directly.

Re: US travel firm $4.5M ransom negotiation open chat

#464
post #381
post #262

Earlier quoted context omitted.

Well, that was a simple scenario with a simple answer. But there are many other things powerful adversaries could do. For example, what happens when miner traffic itself is disrupted and the network is forcibly split between China and the rest of the world? Leaving everyone at risk of having their transactions overwritten when the network is allowed to reintegrate? Anyway, we don't need a 100% effective ban to get an…

> what happens when miner traffic itself is disrupted and the network is forcibly split between China and the rest of the world? How would this be done? It only takes a single node capable of connecting to both networks to keep the whole thing working. There are already many nodes working with satellite connections so I'm pretty sure this can't be done even by state actors.

A satellite connection is still dependent on BGP routing to get to China/RoW and still goes via the Great Firewall to connect to China (if outside of China, not sure on how the miners in China do it - possibly they don't have satellite equipment at all). Poisoning BGP routes is well within the capability of state actors, and China could of course decide to block its firewall.

Re: US travel firm $4.5M ransom negotiation open chat

#465
post #221

Earlier quoted context omitted.

What harm reduction happens when the 'large entities' are the courts[0], municipalities[1] or even hospitals[2]? Alleged better safeguarding of our data* isn't worth it. * I suspect that right now companies find it cheaper to pay than to improve their security. [0] https://wtop.com/national/2020/05/texas-high-courts-hit-by-r... [1] https://www.msspalert.com/cybersecurity-research/municipalit... [2] https://www.wwnytv…

> What harm reduction happens when the 'large entities' are the courts[0], municipalities[1] or even hospitals[2]? Aren't these the entities that you would most want to keep your data secure? > Alleged better safeguarding of our data* isn't worth it. > * I suspect that right now companies find it cheaper to pay than to improve their security. That makes no sense, because if you don't improve your security, you'll be…

>Aren't these the entities that you would most want to keep your data secure?

I don't think the local municipality or the courts have anything I'd consider sensitive on me. Regardless, my bigger desire is for them to stay running, especially the hospitals. I'm not willing to temporarily shut some down 'for better security'.

>That makes no sense, because if you don't improve your security, you'll be hacked in the same way again. There isn't an upper bound on how much it can cost to not improve your security.

What actually happens is that the targets pay, and issue tougher mandates which may or may not be respected in their organization. These hacks are rare enough for now - I suspect hackers don't like to hit the same target again soon after (bigger risk of the target not paying you) - so eventually the organization slips back into same security morass they were in the first place, if they ever left it. There isn't a true desire to change.

Also, there is an upper bound if you're paying insurance, like that hospital did[0]. Over the long term insurers will raise their price, but at least it's a predictable bound.

[0] https://www.wwnytv.com/2020/07/28/western-ny-hospital-recoun...

Re: US travel firm $4.5M ransom negotiation open chat

#466

Earlier quoted context omitted.

Banning... how?

Bitcoin is only useful currently when it can be turned into cash. There are no real businesses that don't turn their payments into a taxable national currency at the end. If you just ban exchanges in a few dominant countries btc is effectively useless as a hold of value and you're back to convincing the pizza guy to accept 30 coins for one pizza and other one off transactions

If you give me 30 bitcoins I will even give you a free pizza and deliver them almost anywhere. Joke appart, it is effectively useless for now but some places are now accepting it which means that the usefulness might change sooner than we expect. It doesn't mean the seller won't be able to locate you with the address for the delivery though. Real problem will be if they use Monero or some real anonymous cryptocurrency where fungability is respected.

Re: US travel firm $4.5M ransom negotiation open chat

#467

Earlier quoted context omitted.

Organized crime has a specific meaning. Whether this particular outfit is one or more people has no bearing on the use of the term organized crime in this instance.

I asked: > What makes crime "organised"? Your answer is: > Organized crime has a specific meaning Well... what is it?

Sorry, I didn't think you might not be able to search for it. Here's a link.

https://en.m.wikipedia.org/wiki/Organized_crime

Re: US travel firm $4.5M ransom negotiation open chat

#468
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

Well I hope they get fined by the US Government for negotiating with terrorists

Re: US travel firm $4.5M ransom negotiation open chat

#469
post #202
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

It might over time. If I was deploying ransomware, the first thing I would do after receiving a ransom payment from a company would be to try them again in a month or two.

Well if they care about money at all they'll have at least one good backup by then.

Re: US travel firm $4.5M ransom negotiation open chat

#470

Earlier quoted context omitted.

There was a post on here a few days back about why it's not that simple. Basically, by the time your stuff is ransomed, they've potentially been in your network for a long time. There's no telling how far you have to go in your backups to make sure they are gone. Who knows, maybe they wait on your computers for several months just so restoring from backups isn't a realistic option, and punish you for trying.

What? I mean back up your data. Not your whole... computer, or whatever. Install latest software, import data from back up, back in business. It's trivial to tell intact data from ransomed data - the latter looks like random noise, as it's encrypted. If your backup process "isn't that simple", then you should make it that simple . Otherwise failure looms.

You misunderstand. I'm saying the network has potentially been infiltrated for months, and there's no telling what configuration and files have been altered to facilitate future infiltration. See further discussion here: https://news.ycombinator.com/item?id=23929344

Particularly this conversation: https://news.ycombinator.com/item?id=23951941

Post reply on HN