Earlier quoted context omitted.
> It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. That argument could be used to justify any theft or even kidnapping. I know many people who grew up in countries where kidnapping was a very real concern. Consequently, they had to adopt "greater security practices" and it had a very real, negative effect on their lives. There are real harms to ra…
In addition, the company isn't the only victim in a ransomware attack, its customers are too. And does anyone really believe the hackers deleted the data off their own servers? They can easily double-dip by selling that information. It's valuable, so why would they delete it?
US travel firm $4.5M ransom negotiation open chat
471–480 of 480 posts
Re: US travel firm $4.5M ransom negotiation open chat
#472Earlier quoted context omitted.
I think you have it backwards. If you commit tax fraud, you will be prosecuted. And the FBI will work with the IRS to do this. But, supposedly, putting a non-zero value in the "illegal income" field of the 1040 (which ISN'T fraud) both (1) can't be used as evidence against you in court, and (2) isn't reported by default to the IRS to the FBI or other law enforcement agencies, so you don't end up on any watch lists. O…
No sorry, I agree with you. I mean if you don't declare your income THEN you get busted on the illegal activity, you are guaranteed to get busted twice.
Re: US travel firm $4.5M ransom negotiation open chat
#473Earlier quoted context omitted.
> To be honest, just how bad of a thing is this? It’s a direct financial punishment for a company with lax security practices. It encourages greater security practices. I see your point but this is flat-out organized crime, extortion to be precise. How long will it be before we're all making protection payments to ransomware groups?
A difference to physical "protection" schemes is that the group you'd pay to might actually keep other groups out of what they consider their turf. Ransomware attacks are not geographically bound so I really doubt that similar structures would develop there. With growing numbers of ransomers demands just wouldn't stop until either the company runs out if money or security gets good enough to keep them out.
When I was (a lot) younger, I had a pet theory that the anti-virus companies were making the viruses and that it was a sort of protection racket.
Re: US travel firm $4.5M ransom negotiation open chat
#474Earlier quoted context omitted.
I asked: > What makes crime "organised"? Your answer is: > Organized crime has a specific meaning Well... what is it?
Sorry, I didn't think you might not be able to search for it. Here's a link. https://en.m.wikipedia.org/wiki/Organized_crime
Re: US travel firm $4.5M ransom negotiation open chat
#475Earlier quoted context omitted.
What? I mean back up your data. Not your whole... computer, or whatever. Install latest software, import data from back up, back in business. It's trivial to tell intact data from ransomed data - the latter looks like random noise, as it's encrypted. If your backup process "isn't that simple", then you should make it that simple . Otherwise failure looms.
You misunderstand. I'm saying the network has potentially been infiltrated for months, and there's no telling what configuration and files have been altered to facilitate future infiltration. See further discussion here: https://news.ycombinator.com/item?id=23929344 Particularly this conversation: https://news.ycombinator.com/item?id=23951941
Re: US travel firm $4.5M ransom negotiation open chat
#476Earlier quoted context omitted.
> It’s sad that it’s come to this point but the end result may be better for everyone. Meanwhile in the real world, a company I develop for implemented the most draconian security measures to "prevent ransomware". Development environment is a virtual machine at the other end of the world, with disabled copy-pasting from and to the local system. A complete separation between safe internal network and unsafe developmen…
Had one of these. All development through Citrix. The security policy was draconian to the extent I’m sure it was well intentioned but led you to do things in the least secure way possible as it was the only way to complete a contract. I.e the servers on the other end running Windows 7 (in late 2019) where so old they didn’t have the required cpu instruction set to run some required software. Likewise input lag was e…
The bank was using remote desktops over Citrix from HP workstations (thin clients). It worked really really well, including copy/paste.
If not for the initial login and citrix log, I don't think it would be possible for a developer to figure out he is working on a remote desktop.
Re: US travel firm $4.5M ransom negotiation open chat
#477Earlier quoted context omitted.
Back in 2018 I spent six months trying to get a small software shop to implement automated backups as their answer to ransomware fears.(on top of the usual anti-malware and restrictions on lateral movement where we could put those in) They didn't object to the idea insomuch as they had somehow convinced themselves that they needed some kind of security specific product. We were never able to tease the shape or color…
Marketing opportunity for a backup product named Ransomware Protect?
Re: US travel firm $4.5M ransom negotiation open chat
#478While these stories are becoming all too common I’d like to think that while we’re in a golden age of being a ransomware payouts, it will lead to actually caring about security by many of the high-profile affected companies. While the overall cost may be low for them, if they don’t make meaningful changes to prevent these issues in the future, it’s not hard to imagine it might add up quickly. I don’t support these at…
Nothing will change until they make it a felony to pay a ransom.
It already is a felony to pay ransomware attackers in the US, depending on who attacked you.
Many of the principal ransomware gangs are listed as OFAC [1] restricted entities. If you pay them, even indirectly, you are as criminally culpable as if you sent sponsor dollars to ISIS or another terrorist or organized crime entity.
Garmin’s execs are in for a big surprise when the Treasury agents come to visit.
[1]: https://en.wikipedia.org/wiki/Office_of_Foreign_Assets_Contr...
Re: US travel firm $4.5M ransom negotiation open chat
#479Earlier quoted context omitted.
You misunderstand. I'm saying the network has potentially been infiltrated for months, and there's no telling what configuration and files have been altered to facilitate future infiltration. See further discussion here: https://news.ycombinator.com/item?id=23929344 Particularly this conversation: https://news.ycombinator.com/item?id=23951941
Disconnect entire network. Factory reset all devices. Reinstall latest everything.
Re: US travel firm $4.5M ransom negotiation open chat
#480Earlier quoted context omitted.
What exchanges allow you to move that kind of money?
every trade desk anywhere its been like this for half of bitcoin's existence they consider themselves distinct from exchanges because they do not take custody of people's funds, in their opinion
Almost all illegal bitcoin stolen by hackers and ransomware is cashed out in countries with limited or no AML/KYC.