Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

41–50 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#42
post #24

Earlier quoted context omitted.

I think cryptolocker actually decrypted the FS after the ransom was paid. So sometimes it works. Actually, it makes no sense to not follow through because that is their business model.

Let me make a spam analogy: the reason we are drowning in spam is because it works. If even 0.00001% of the spam recipients enters into a financially beneficial relationship with the spammers then everybody will get spammed. The only way spam will go away is if everybody will finally stop responding to spam. So you just simply do not pay extortion fees unless you want to become part of the problem. In the case of an…

> The only way spam will go away is if everybody will finally stop responding to spam.

Right, which is why "never pay extortion fees" doesn't make much more sense for combatting this stuff than "never click on spam links" makes for combating spam. It's unrealistic to think we will convince enough businesses to altruistically not pay extortionists, just like it's unrealistic to think you'll get your grandmother to stop clicking on spam links. You need another solution.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#44
post #32

It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…

never deal with terrorists

Bomb their families instead?

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#45
post #38
post #4

Earlier quoted context omitted.

But if it buys you time to upgrade your infrastructure it could be worth it.

Paying ransom is never worth the long-term costs. Once you've proven to the criminal that you're someone who will pay, they usually try again in the future because you're an easy mark. Not only that, there is a power imbalance that shouldn't be ignored: the criminal has more experience in these kinds of confrontations than you do. Sam Harris has a very good article on this topic[1]; while he is discussing violent int…

> Paying ransom is never worth the long-term costs.

I am amazed about how many people are making this claim confidently in this thread. It's clearly wrong. Very, very often it's definitely worth the cost, because very often you will never see the same criminal again. Consider:

"Don't pay ransoms, because (1) you'll get extorted again once the criminal knows you're an easy mark and (2) if everyone always refuses to pay, criminals will have no incentives to try and extort."

versus

"Don't pay muggers, because (1) you'll get mugged again once the mugger knows you're an easy mark and (2) if everyone always refuses to pay muggers, muggers will have no incentive to mug."

Yes there are cases, like if you're the government, where you are very long-lived and your reputation is reliable such that having a stated, followed policy of not being extorted works. But for individuals, it's just not feasible most of the time. You probably won't see that mugger/extorter ever again, and it's very unlikely that most victims will refuse.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#46
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

Cloudflare's $200/month business plan includes DDoS mitigation. It's self-serve and there's an "I'm Under Attack!" button in every account. There's no extra cost for the bandwidth.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#47

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

>NEVER EVER PAY... you are making the problem larger for others

That's true but for the individual payee it can make sense. Trying to get the ransomers back can work. They'll keep at it till they figure they can get harmed.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#48

Earlier quoted context omitted.

never deal with terrorists

Bomb their families instead?

Questionable solution but I bet it would help for hackers! Impunity is what fuels this type of criminal behavior.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#49
post #24

Earlier quoted context omitted.

I think cryptolocker actually decrypted the FS after the ransom was paid. So sometimes it works. Actually, it makes no sense to not follow through because that is their business model.

Let me make a spam analogy: the reason we are drowning in spam is because it works. If even 0.00001% of the spam recipients enters into a financially beneficial relationship with the spammers then everybody will get spammed. The only way spam will go away is if everybody will finally stop responding to spam. So you just simply do not pay extortion fees unless you want to become part of the problem. In the case of an…

According to Spam Nation by Krebson Security, Spam works because people can get cheap prescription drugs.

http://www.amazon.com/gp/product/1492603236 http://krebsonsecurity.com

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#50
post #13

God, why? That's utter incompetence. Never pay ransoms. This has highly lowered my opinion of ProntoMail.

I know you mistyped it, but ProntoMail really sounds cool.

Might have been autocorrect on my phone but I'm leaving it now.
Post reply on HN