Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

21–30 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#21

I don't understand why the attackers wouldn't stop? Why would they want to build up a reputation of not being worth paying? If they were always true to the word, then people would mostly always pay.

Different shark. Once there is blood in the water there'll be more.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#24

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

I think cryptolocker actually decrypted the FS after the ransom was paid. So sometimes it works.

Actually, it makes no sense to not follow through because that is their business model.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#27
There's regular security solutions then there's those meant to stop High Strength Attackers. I warned ProtonMail's team and infrastructure wouldn't handle the latter. I was expecting stealth 0-days, though, given there's DDOS mitigations available. That they went down due to DDOS was a bit of a surprise.

"Cost estimates for these solutions are around $100,000 per year since there are few service providers able to fight off an attack of this size and sophistication. These solutions are expensive and take time to implement, but they will be necessary because it is clear that online privacy has powerful opponents."

No shit lol... Not a good sign that they're already in reactive mode. On other end, that MyKolab hasn't gone down might mean they're already compromised or just not targeted by this attack. I wonder what it is. They're just a GPG carrier in a semi-neutral jurisdiction in my usage, though. ProtonMail would've been, too, but I figured they'd be more likely to have service issues.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#28

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#29
post #24

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

I think cryptolocker actually decrypted the FS after the ransom was paid. So sometimes it works. Actually, it makes no sense to not follow through because that is their business model.

Let me make a spam analogy: the reason we are drowning in spam is because it works. If even 0.00001% of the spam recipients enters into a financially beneficial relationship with the spammers then everybody will get spammed. The only way spam will go away is if everybody will finally stop responding to spam.

So you just simply do not pay extortion fees unless you want to become part of the problem.

In the case of an encrypted filesystem that means you will have to restore from a back-up (which I assume (naively maybe) that you have). And you chalk the whole thing up to your education fund. Paying up is simply wrong.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#30

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

This goes for any 'in the cloud' data that you might have. In the end it's your data and your company that is at stake. Not all data wipe-outs are malicious, sometimes accidents do happen.

Post reply on HN