Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

61–70 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#61

I'm reminded of a similar article on ransoms and FBI's strange advice to pay up. https://news.ycombinator.com/item?id=10482242 I think this is a good example of why this is bad advice.

Ransomware is a different scenario. With ransomware, if you have no backups and absolutely need your files back, paying the ransom is the only sane option. Of course, this can easily be prevented by taking frequent backups. With a DDoS, there are almost no advantages to paying the ransom. Much better to spend the money on DDoS mitigation instead, to help now and in the future. Also, the FBI wasn't making an official…

In fact backups is not enough. It has to be offline backups, which raises the bar quite a bit. Backing up to a network drive doesn't even help, and I am not aware of any wildly used "write once-only" network drive capabilities.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#63
I suspect, sadly, this is why Gmail and sites like it will continue to win. Secure email always sounds like a good thing, but it's less important in practice than accessible email. If you have to make a choice between confidentiality, integrity, and availability, for day-to-day email, very few people will choose anything other than availability.

(The email deliverability problem doesn't help matters, of course.)

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#65

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

From their blog: https://protonmaildotcom.wordpress.com/ At around 2PM, the attackers began directly attacking the infrastructure of our upstream providers and the datacenter itself. The coordinated assault on our ISP exceeded 100Gbps and attacked not only the datacenter, but also routers in Zurich, Frankfurt, and other locations where our ISP has nodes. This coordinated assault on key infrastructure eventually manag…

They put their customers in charge of the company? This gets weirder all the time. The problem is that they asked their customers in the first place. They should have simply communicated the fact that they would be under attack shortly and indicate that they would never ever pay a red cent.

That would give their customers time to batten the hatches and/or migrate off the system for the time being while sending a clear signal that they would not pay anyway.

This is a tough situation to be in but putting your customers in control of the company (and in a democratic way no less) is not the solution. What about those customers that decided (rightly imo) against paying?

Companies such as these should have an up-front item in their terms of service indicating that they would never pay a ransom, that way they would be clear to both their customers and their potential attackers.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#66
post #47

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

>NEVER EVER PAY... you are making the problem larger for others That's true but for the individual payee it can make sense. Trying to get the ransomers back can work. They'll keep at it till they figure they can get harmed.

That's naive. If you pay a ransom they'll be back shortly for more. You've just turned yourself into an ATM for your attackers.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#67
post #58

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

If you are the victim of a crypto locker, you don't really have a choice. In fact it is true of any hostage situation. Parents of a kidnapped kid only have one solution. It is the authorities role to ensure that the hostage takers end up in a jail or a coffin, otherwise impunity will fuel criminal behavior.

Kidnapped kid versus restoring a back-up. That's not a fair comparison.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#68
post #32

It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…

Poems by the man who romanticized the colonization of my grandparents' country are always cool, but the logic doesn't hold up. If you're not as well-armed as the British Empire, and you very much do not have the resources to defeat the Dane, it's nice that the end of the game is oppression and shame, but you're going to lose well before you even get to endgame.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#70
post #58

Earlier quoted context omitted.

If you are the victim of a crypto locker, you don't really have a choice. In fact it is true of any hostage situation. Parents of a kidnapped kid only have one solution. It is the authorities role to ensure that the hostage takers end up in a jail or a coffin, otherwise impunity will fuel criminal behavior.

Kidnapped kid versus restoring a back-up. That's not a fair comparison.

If you have a working backup you are not really held hostage in the first place. But many people backup to an external drive or a NAS, which unless they happened to be offline at the time of the attack would also be compromised.
Post reply on HN