Live data from Hacker News

US travel firm $4.5M ransom negotiation open chat

twitter.com

51–60 of 480 posts

Re: US travel firm $4.5M ransom negotiation open chat

#51
post #21
post #10

Earlier quoted context omitted.

The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.

But wouldn't the payments just end up being passed through? For example, one way to get around that is you could sign a contract with a foreign consultant firm for "security services", say for 1 year, and they would take your money, and pay a portion of it to the ransomware authors and profit on the rest.

Wouldn't that be extremely obvious though?

Re: US travel firm $4.5M ransom negotiation open chat

#52

This story is going to be used by every security consultant selling their services for a long, long time.

When I started my career I'd always hear old greybeards talk about "oh this one time.. some certain thing happened, and everyone learnt a lesson" and I feel like I just witnessed one of those come into existence

Don’t be surprised if companies would rather roll the dice than pay whatever it costs to prevent the problem.

$4 million once times the risk of getting hit vs. the up-front and ongoing costs of dealing with an overly paranoid IT guy.

Tough call.

Re: US travel firm $4.5M ransom negotiation open chat

#53
post #19

For some context about CWT (I was curious about these figures) -- via Wikipedia[1]: * US$1.5 billion in revenue * 18k employees For a firm like this, the payment probably amounts to a small uptick in a small portion of their IT budget and won't even come close to hurting them (and, frankly, neither would the $10m figure). It's insane that this is the case and that companies are willing & able to pay ransoms like this…

Does that revenue include pass-through?

Good question, I was wondering the same thing. It seems it doesn't. The main article body puts total transaction volume at $23B.

Re: US travel firm $4.5M ransom negotiation open chat

#54
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

While I understand the sentiment, there needs to be a reasonable alternative here. You can’t ask people or organizations not to protect or recover their property if they have no other recourse.

I don’t know much about this travel agency. They may or may not have had a security team. What they did have was mentioned in this article: liability. They took steps to reduce or eliminate this liability. I think we all know that there’s no proof these attackers acted in good faith past the actual decryption, but now CWT can at least say they attempted to recover lost data.

I think we can only realistically hold companies liable for transactions like this when we have better government resourcing and oversight. Getting the FBI involved in stuff like this is difficult, as they’re over loaded with such cases.

I also feel we should never hold individuals liable for stuff like this. It’s unreasonable to expect people who aren’t security professionals to know how to defend or respond to threats like this given how rapidly the landscape changes.

Figuring out a good way to holistically deal with cyber criminals will probably be a problem we struggle with for years, if not decades.

Re: US travel firm $4.5M ransom negotiation open chat

#55
post #10

We are truly in the age of rich data pirates. I dont see them becoming extinct any time soon with decent ROI like this. I would be curious to learn the % of origins for most attacks. [1] Incompetence by dumb employees [2] Insider attacks [3] Paid cybersecurity protection racket that take down strong systems with stolen tech [4] Unskilled or understaffed security employees

The US needs to pass a Federal law making it personally (not just "corporately") illegal to pay ransom. That would stop them because it would kill the market. Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.

> Historically it's how they stop kidnapping in countries where it's common. It REALLY sucks for the first few people after the law is passed, but after that things get better.

Is this based in reality? What countries have banned ransom payments for human kidnapping and what people did it “suck” for?

My hunch is that if your spouse gets kidnapped and you have the means to get them back, you’ll risk it.

Re: US travel firm $4.5M ransom negotiation open chat

#56
post #45

Earlier quoted context omitted.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

In general paying off kidnappers is also a bad policy. However I see a huge difference between protecting human lives versus protecting corporate assets.

Ok, and now a hospital with critical medical information gets hit by the ransom. What then?

Re: US travel firm $4.5M ransom negotiation open chat

#57
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

So you suggestion is to let any company that doesn't have the budget to have a proper cybersecurity team just die? I'll guarantee you that most of the small businesses that you encounter each day do not have such a thing setup.

I think this is where insurance can come into play. Like get a smoke alarm and sprinklers, but also get fire insurance.

Re: US travel firm $4.5M ransom negotiation open chat

#58
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

Isn't this likely short sighted in the same way that people talk about draconic enforcement of immigration laws? Criminalizing ransoms will result in victims doing it in secret, not in the elimination of ransoms. People won't be able to share information, and the financial incentive will continue to exist.

If you were a corporate executive would you risk hard prison time just to save your employer from taking a loss? The whole point of imposing draconian penalties is to make such attacks unprofitable. If the attackers know they won't be able to extract any money from victims then they'll move on to some other scheme.

Re: US travel firm $4.5M ransom negotiation open chat

#59
post #24

It should be a criminal offense punishable by prison time for companies to pay for ransomware keys. While that might cause some businesses to fail in the short term, it would benefit society as a whole by eliminating the financial incentive for such attacks.

I'm curious, how do you feel about people paying ransom for traditional kidnappings? Same logic, or is it different?

The main idea here is that prohibiting payouts might make the crime less frequent. That’s somehow reasonable given the relative low stakes involved—from a moral perspective, data is usually of a lesser value than human lives. Therefore, yes, those cases are very different indeed. For once, kidnapping a human being is already punishable enough by itself so it makes no sense to punish a payout that could actually save a live.

Re: US travel firm $4.5M ransom negotiation open chat

#60

So what's the current optimal solution, as far as precautionary measurements go - for these kinds of scenarios? The more companies that shell out, the more it's going to happen / motivate these pirates to continue with such rackets.

The responses suggesting backsups are ignoring the exfiltration part. The ransomware groups have updated their strategy to encrypt and carry away data that they would leak if not paid. Protecting against that is much harder. Compartmentalization and data minimization might help.
Post reply on HN