Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

31–40 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#31
post #4

Earlier quoted context omitted.

But if it buys you time to upgrade your infrastructure it could be worth it.

It's never worth it. For $6k you can get actual protection for some time before you upgrade your infrastructure.

Isn't Cloudfare around $2,000 a month with no data caps for high-end package with $50 a month for low end? I know reasons why some people avoid them but I figure there's a similar service in Switzerland that just costs a bit more. That might be what they're referring to for $100,000. I'm curious.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#32
It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away."

And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane!

It is always a temptation for a rich and lazy nation, To puff and look important and to say: -- "Though we know we should defeat you, we have not the time to meet you. We will therefore pay you cash to go away."

And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane.

It is wrong to put temptation in the path of any nation, For fear they should succumb and go astray; So when you are requested to pay up or be molested, You will find it better policy to say: --

"We never pay any-one Dane-geld, No matter how trifling the cost; For the end of that game is oppression and shame, And the nation that pays it is lost!"

- Rudyard Kipling

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#33
post #26

The only thing worse than paying a ransom is publicly announcing you've paid a ransom.

I guess by publicly announcing that they paid ransom that "didn't work" they have slightly undermined the trust for ransom as a solution in cases like this. So it might be correct from a game theory perspective, if you disregard any decrease in trust for themselves that is.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#34
post #32

It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…

never deal with terrorists

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#36

Earlier quoted context omitted.

If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack. This goes for any 'in the cloud' data that you might have. In the end it's your data and your company that is at stake. Not all data wipe-outs are malicious, sometimes accidents do happen.

Banks are tripping over themselves to get out of the datacenter business and put all their files on Azure/Rackspace/AWS/what have you. It's embarrassing.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#37

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack

you would be shocked at the number of people who get upset when you advise them to make their own backups, and interpret this as an indictment of the reliability of your own backup procedures.

e.g. "isn't that what we pay you for???"

nevertheless, do it anyway and let them fume. there are no prerequisites for running a business and you'll find that many absolute morons are at the helm of some nominally successful businesses.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#38
post #4

That's really not smart. By paying it up you just incentive them to do it more often. Not only to yourself but to other websites.

But if it buys you time to upgrade your infrastructure it could be worth it.

Paying ransom is never worth the long-term costs. Once you've proven to the criminal that you're someone who will pay, they usually try again in the future because you're an easy mark.

Not only that, there is a power imbalance that shouldn't be ignored: the criminal has more experience in these kinds of confrontations than you do. Sam Harris has a very good article on this topic[1]; while he is discussing violent interactions on a personal level (e.g. mugging), the principles apply to many situations. The short version is that the criminal is trying to draw you onto their turf and to play by their rules. Almost always you will only make your situation worse when you let the criminal set the rules.

[1] http://www.samharris.org/blog/item/the-truth-about-violence

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#39

That's really not smart. By paying it up you just incentive them to do it more often. Not only to yourself but to other websites.

This is the first case I've seen where a digital blackmailer didn't follow through with their promise. It's bad for business for them to renege as it increases the chance that their next victim wont pay.

I think the most likely scenerio is actually that the blackmailers are outsourcing the DDOSing so there was a communication delay and/or there is some latency/delay when issuing commands to the botnet.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#40

I'm reminded of a similar article on ransoms and FBI's strange advice to pay up. https://news.ycombinator.com/item?id=10482242 I think this is a good example of why this is bad advice.

Ransomware is a different scenario. With ransomware, if you have no backups and absolutely need your files back, paying the ransom is the only sane option. Of course, this can easily be prevented by taking frequent backups. With a DDoS, there are almost no advantages to paying the ransom. Much better to spend the money on DDoS mitigation instead, to help now and in the future. Also, the FBI wasn't making an official…

Agreed. The difference is that with ransomware the act has already been done. You can think of it as negotiating with kidnappers vs. paying off the mob to not rough up your shop.
Post reply on HN