Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

471–480 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#471

Earlier quoted context omitted.

> It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. That argument could be used to justify any theft or even kidnapping. I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives. There are real harms to ra…

In addition, the company isn't the only victim in a ransomware attack, its customers are too. And does anyone really believe the hackers deleted the data off their own servers? They can easily double-dip by selling that information. It's valuable, so why would they delete it?

Double dipping ruins the reputation of the hackers and future income potential.

Re: US travel firm $4.5M ransom negotiation open chat

#472

Earlier quoted context omitted.

I think you have it backwards. If you commit tax fraud, you will be prosecuted. And the FBI will work with the IRS to do this. But, supposedly, putting a non-zero value in the "illegal income" field of the 1040 (which ISN'T fraud) both (1) can't be used as evidence against you in court, and (2) isn't reported by default to the IRS to the FBI or other law enforcement agencies, so you don't end up on any watch lists. O…

No sorry, I agree with you. I mean if you don't declare your income THEN you get busted on the illegal activity, you are guaranteed to get busted twice.

Ah I misunderstood, sorry.

Re: US travel firm $4.5M ransom negotiation open chat

#473
post #417

Earlier quoted context omitted.

> To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?

A difference to physical "protection" schemes is that the group you'd pay to might actually keep other groups out of what they consider their turf. Ransomware attacks are not geographically bound so I really doubt that similar structures would develop there. With growing numbers of ransomers demands just wouldn't stop until either the company runs out if money or security gets good enough to keep them out.

Good point, not a great analogy. My sentiment was the risk of this becoming normalized and even formalized.

When I was (a lot) younger, I had a pet theory that the anti-virus companies were making the viruses and that it was a sort of protection racket.

Re: US travel firm $4.5M ransom negotiation open chat

#474

Earlier quoted context omitted.

I asked: > What makes crime "organised"? Your answer is: > Organized crime has a specific meaning Well... what is it?

Sorry, I didn't think you might not be able to search for it. Here's a link. https://en.m.wikipedia.org/wiki/Organized_crime

The link says you're wrong, and that in fact you can't have organised crime without at least two people.

Re: US travel firm $4.5M ransom negotiation open chat

#475

Earlier quoted context omitted.

What? I mean back up your data. Not your whole... computer, or whatever. Install latest software, import data from back up, back in business. It's trivial to tell intact data from ransomed data - the latter looks like random noise, as it's encrypted. If your backup process "isn't that simple", then you should make it that simple . Otherwise failure looms.

You misunderstand. I'm saying the network has potentially been infiltrated for months, and there's no telling what configuration and files have been altered to facilitate future infiltration. See further discussion here: https://news.ycombinator.com/item?id=23929344 Particularly this conversation: https://news.ycombinator.com/item?id=23951941

Disconnect entire network. Factory reset all devices. Reinstall latest everything.

Re: US travel firm $4.5M ransom negotiation open chat

#476

Earlier quoted context omitted.

> It’s sad that it’s come to this point but the end result may be better for everyone. Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware". Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe developmen…

Had one of these. All development through Citrix. The security policy was draconian to the extent I’m sure it was well intentioned but led you to do things in the least secure way possible as it was the only way to complete a contract. I.e the servers on the other end running Windows 7 (in late 2019) where so old they didn’t have the required cpu instruction set to run some required software. Likewise input lag was e…

Counterpoint at another Tier 1 bank.

The bank was using remote desktops over Citrix from HP workstations (thin clients). It worked really really well, including copy/paste.

If not for the initial login and citrix log, I don't think it would be possible for a developer to figure out he is working on a remote desktop.

Re: US travel firm $4.5M ransom negotiation open chat

#477

Earlier quoted context omitted.

Back in 2018 I spent six months trying to get a small software shop to implement automated backups as their answer to ransomware fears.(on top of the usual anti-malware and restrictions on lateral movement where we could put those in) They didn't object to the idea insomuch as they had somehow convinced themselves that they needed some kind of security specific product. We were never able to tease the shape or color…

Marketing opportunity for a backup product named Ransomware Protect?

"Ransomwair Protect for National Security is detected suspicious activity on your computer. Please be call Windows technology Support for assistence with the files at 1-800-xxx-xxxx as required by the FBI and IRS required laws." [sic]* /s

Re: US travel firm $4.5M ransom negotiation open chat

#478

While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…

Nothing will change until they make it a felony to pay a ransom.

> Nothing will change until they make it a felony to pay a ransom.

It already is a felony to pay ransomware attackers in the US, depending on who attacked you.

Many of the principal ransomware gangs are listed as OFAC [1] restricted entities. If you pay them, even indirectly, you are as criminally culpable as if you sent sponsor dollars to ISIS or another terrorist or organized crime entity.

Garmin’s execs are in for a big surprise when the Treasury agents come to visit.

[1]: https://en.wikipedia.org/wiki/Office_of_Foreign_Assets_Contr...

Re: US travel firm $4.5M ransom negotiation open chat

#479

Earlier quoted context omitted.

You misunderstand. I'm saying the network has potentially been infiltrated for months, and there's no telling what configuration and files have been altered to facilitate future infiltration. See further discussion here: https://news.ycombinator.com/item?id=23929344 Particularly this conversation: https://news.ycombinator.com/item?id=23951941

Disconnect entire network. Factory reset all devices. Reinstall latest everything.

Clearly you know best

Re: US travel firm $4.5M ransom negotiation open chat

#480
post #279

Earlier quoted context omitted.

What exchanges allow you to move that kind of money?

every trade desk anywhere its been like this for half of bitcoin's existence they consider themselves distinct from exchanges because they do not take custody of people's funds, in their opinion

As someone who sold Bitcoin on LocalBitcoins, and have 4 friends in federal prison (or detention), plus friends with millions in tainted BitCoin, this is not true.

Almost all illegal bitcoin stolen by hackers and ransomware is cashed out in countries with limited or no AML/KYC.

Post reply on HN