Earlier quoted context omitted.
But if it buys you time to upgrade your infrastructure it could be worth it.
It's never worth it. For $6k you can get actual protection for some time before you upgrade your infrastructure.
ProtonMail pays $6k ransom, gets taken out by DDoS anyway
31–40 of 233 posts
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#32And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane!
It is always a temptation for a rich and lazy nation, To puff and look important and to say: -- "Though we know we should defeat you, we have not the time to meet you. We will therefore pay you cash to go away."
And that is called paying the Dane-geld; But we've proved it again and again, That if once you have paid him the Dane-geld You never get rid of the Dane.
It is wrong to put temptation in the path of any nation, For fear they should succumb and go astray; So when you are requested to pay up or be molested, You will find it better policy to say: --
"We never pay any-one Dane-geld, No matter how trifling the cost; For the end of that game is oppression and shame, And the nation that pays it is lost!"
- Rudyard Kipling
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#33The only thing worse than paying a ransom is publicly announcing you've paid a ransom.
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#34It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#35God, why? That's utter incompetence. Never pay ransoms. This has highly lowered my opinion of ProntoMail.
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#36Earlier quoted context omitted.
If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.
> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack. This goes for any 'in the cloud' data that you might have. In the end it's your data and your company that is at stake. Not all data wipe-outs are malicious, sometimes accidents do happen.
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#37NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.
If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.
you would be shocked at the number of people who get upset when you advise them to make their own backups, and interpret this as an indictment of the reliability of your own backup procedures.
e.g. "isn't that what we pay you for???"
nevertheless, do it anyway and let them fume. there are no prerequisites for running a business and you'll find that many absolute morons are at the helm of some nominally successful businesses.
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#38That's really not smart. By paying it up you just incentive them to do it more often. Not only to yourself but to other websites.
But if it buys you time to upgrade your infrastructure it could be worth it.
Not only that, there is a power imbalance that shouldn't be ignored: the criminal has more experience in these kinds of confrontations than you do. Sam Harris has a very good article on this topic[1]; while he is discussing violent interactions on a personal level (e.g. mugging), the principles apply to many situations. The short version is that the criminal is trying to draw you onto their turf and to play by their rules. Almost always you will only make your situation worse when you let the criminal set the rules.
[1] http://www.samharris.org/blog/item/the-truth-about-violence
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#39That's really not smart. By paying it up you just incentive them to do it more often. Not only to yourself but to other websites.
This is the first case I've seen where a digital blackmailer didn't follow through with their promise. It's bad for business for them to renege as it increases the chance that their next victim wont pay.
Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway
#40I'm reminded of a similar article on ransoms and FBI's strange advice to pay up. https://news.ycombinator.com/item?id=10482242 I think this is a good example of why this is bad advice.
Ransomware is a different scenario. With ransomware, if you have no backups and absolutely need your files back, paying the ransom is the only sane option. Of course, this can easily be prevented by taking frequent backups. With a DDoS, there are almost no advantages to paying the ransom. Much better to spend the money on DDoS mitigation instead, to help now and in the future. Also, the FBI wasn't making an official…