Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

51–60 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#51

That's really not smart. By paying it up you just incentive them to do it more often. Not only to yourself but to other websites.

This is the first case I've seen where a digital blackmailer didn't follow through with their promise. It's bad for business for them to renege as it increases the chance that their next victim wont pay.

I have no idea how to verify the statements, but I found some comments on the blockchain.info page for the bitcoin address regarding the DoS. It is supposedly from the blackmailers: https://blockchain.info/address/1FxHcZzW3z9NRSUnQ9Pcp58ddYaS...

"Somebody with great power, who wants ProtonMail dead, jumped in after our initial attack!" "We have no such power to crash data center and no reason to attack ProtonMail any more!" "WE DO NOT HAVE THAT POWER! NOT EVEN CLOSE!" "We are not attacking ProtonMail! Our attack was small, directed at their IP only and lasted 15 minutes only!"

I don't believe Protonmail have said they have received any more requests for money, so that would go along with the above. I agree that it was silly to pay the blackmailers, but there is some reason to believe that these are two separate attacks.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#53

Earlier quoted context omitted.

never deal with terrorists

Bomb their families instead?

If victims need to be consistent. When terrorists are shown that they'll either get a bomb through the roof or nothing, but never payment, then they'll change their business plan.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#54

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

From their blog: https://protonmaildotcom.wordpress.com/

At around 2PM, the attackers began directly attacking the infrastructure of our upstream providers and the datacenter itself. The coordinated assault on our ISP exceeded 100Gbps and attacked not only the datacenter, but also routers in Zurich, Frankfurt, and other locations where our ISP has nodes. This coordinated assault on key infrastructure eventually managed to bring down both the datacenter and the ISP, which impacted hundreds of other companies, not just ProtonMail.

At this point, we were placed under a lot of pressure by third parties to just pay the ransom, which we grudgingly agreed to do at 3:30PM Geneva time to the bitcoin address 1FxHcZzW3z9NRSUnQ9Pcp58ddYaSuN1T2y. This was a collective decision taken by all impacted companies, and while we disagree with it, we nevertheless respected it taking into the consideration the hundreds of thousands of Swiss Francs in damages suffered by other companies caught up in the attack against us. We hoped that by paying, we could spare the other companies impacted by the attack against us, but the attacks continued nevertheless. This was clearly a wrong decision so let us be clear to all future attackers – ProtonMail will NEVER pay another ransom.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#55

Earlier quoted context omitted.

If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack. This goes for any 'in the cloud' data that you might have. In the end it's your data and your company that is at stake. Not all data wipe-outs are malicious, sometimes accidents do happen.

Except that it seems when it comes to Azure everyone feels safe then also backing up to Azure (specifically talking about SQL database here). Sigh...

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#56

Earlier quoted context omitted.

If your a security service, definitely pay no ransom money. Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack.

> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack you would be shocked at the number of people who get upset when you advise them to make their own backups, and interpret this as an indictment of the reliability of your own backup procedures. e.g. "isn't that what we pay you for???" nevertheless, do it anyway and let them fume. there are no prerequi…

Agreed. Whenever I hear a self important IT person saying "this place WILL go under without me" I know I'm dealing with someone delusional or inexperienced.

A company of any size can continue on even if severely crippled with nobody left who understands how anything works. I've seen it time and again - also even where I've felt I was important.

Minimal viable product and vendor lock ins are powerful real world things.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#57

Earlier quoted context omitted.

Ransomware is a different scenario. With ransomware, if you have no backups and absolutely need your files back, paying the ransom is the only sane option. Of course, this can easily be prevented by taking frequent backups. With a DDoS, there are almost no advantages to paying the ransom. Much better to spend the money on DDoS mitigation instead, to help now and in the future. Also, the FBI wasn't making an official…

Agreed. The difference is that with ransomware the act has already been done. You can think of it as negotiating with kidnappers vs. paying off the mob to not rough up your shop.

Exactly, that's a perfect analogy. If someone kidnapped your child, paying the ransom isn't such a bad idea.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#58

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

If you are the victim of a crypto locker, you don't really have a choice. In fact it is true of any hostage situation. Parents of a kidnapped kid only have one solution. It is the authorities role to ensure that the hostage takers end up in a jail or a coffin, otherwise impunity will fuel criminal behavior.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#59
post #24

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

I think cryptolocker actually decrypted the FS after the ransom was paid. So sometimes it works. Actually, it makes no sense to not follow through because that is their business model.

If at any point a CryptoLocker locked a person files up, and they didn't give up the key and it got out, no-one will ever pay them again. It's in their best interest to actually unlock the files.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#60
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

No, profiting in any way off blackmailers looks really bad...

Reminds me of when Uber had that surge pricing scandal during the Sydney hostage crisis.

Post reply on HN