Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

71–80 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#71
post #70

Earlier quoted context omitted.

Kidnapped kid versus restoring a back-up. That's not a fair comparison.

If you have a working backup you are not really held hostage in the first place. But many people backup to an external drive or a NAS, which unless they happened to be offline at the time of the attack would also be compromised.

A backup is a copy of your files on another medium physically disjoint in space and not connected to the original in any way that you verify is correct after having written a copy.

Anything less than that is not a backup but a mirror and mirrors while useful are not at the same level of security that a backup is.

Some copies are backups, but not all of them and most copies on spinning or re-writeable media especially when they are networked are not actually backups. Somebody tell backblaze ;).

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#72

Earlier quoted context omitted.

Let me make a spam analogy: the reason we are drowning in spam is because it works. If even 0.00001% of the spam recipients enters into a financially beneficial relationship with the spammers then everybody will get spammed. The only way spam will go away is if everybody will finally stop responding to spam. So you just simply do not pay extortion fees unless you want to become part of the problem. In the case of an…

> The only way spam will go away is if everybody will finally stop responding to spam. Right, which is why "never pay extortion fees" doesn't make much more sense for combatting this stuff than "never click on spam links" makes for combating spam. It's unrealistic to think we will convince enough businesses to altruistically not pay extortionists, just like it's unrealistic to think you'll get your grandmother to sto…

There is nothing altruistic about businesses not paying extortionists. Sure they may come to (some, hopefully limited) harm.

But once you as a business pay an extortionist you have just taken on another partner in your business, who will do none of the work and who will take almost all of your profits. So paying out of pragmatism will actually have the exact opposite effect of what you intend to achieve (to make the problem go away).

A good parasite does not kill the host, merely takes all the resources they can get and it certainly won't stop with one attempt at extortion. And judging from the blog post linked they learned their lesson.

edited for clarity, thanks ghotifish.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#73

Earlier quoted context omitted.

From their blog: https://protonmaildotcom.wordpress.com/ At around 2PM, the attackers began directly attacking the infrastructure of our upstream providers and the datacenter itself. The coordinated assault on our ISP exceeded 100Gbps and attacked not only the datacenter, but also routers in Zurich, Frankfurt, and other locations where our ISP has nodes. This coordinated assault on key infrastructure eventually manag…

They put their customers in charge of the company? This gets weirder all the time. The problem is that they asked their customers in the first place. They should have simply communicated the fact that they would be under attack shortly and indicate that they would never ever pay a red cent . That would give their customers time to batten the hatches and/or migrate off the system for the time being while sending a cle…

"This was a collective decision taken by all impacted companies"

I think they were put under pressure by other companies using the same IPS, not their customers.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#74
I'm not recommending it, but it should be noted that this does sometimes work as when Kim DotCom paid for the LizardSquad DDOS of XBox and PS4 networks to be halted last Christmas: https://torrentfreak.com/kim-dotcom-stops-xbox-and-playstati...

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#75
post #70

Earlier quoted context omitted.

If you have a working backup you are not really held hostage in the first place. But many people backup to an external drive or a NAS, which unless they happened to be offline at the time of the attack would also be compromised.

A backup is a copy of your files on another medium physically disjoint in space and not connected to the original in any way that you verify is correct after having written a copy. Anything less than that is not a backup but a mirror and mirrors while useful are not at the same level of security that a backup is. Some copies are backups, but not all of them and most copies on spinning or re-writeable media especially…

Large companies do have this sort of backups. But cryptolocker's target population is individuals and small businesses. Having to manually plug and unplug a drive every day is an unreasonable burden for this population, and may not even help if the drive is connected while the user is unaware of being infected. WORM NAS volumes or NAS volumes that do incremental snapshots behind the scene are a better solution but I am not aware that major consumer NAS manufacturers (Synology, etc) offer that.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#76
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

Cloudflare's $200/month business plan includes DDoS mitigation. It's self-serve and there's an "I'm Under Attack!" button in every account. There's no extra cost for the bandwidth.

So $6000 would get them over two years of self-service DDoS mitigation. Ouch.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#77

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

It would only make sense if you're doing it as a delaying tactic.

There is a chance they could be 'honorable' thieves and desist, but it's likely having had someone cave in once, they'd cave in again, and again... So, it only makes sense as a delaying tactic, in the long run it's mostly a losing proposition, unless you're setting them up for a sting or something.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#78

Earlier quoted context omitted.

> The only way spam will go away is if everybody will finally stop responding to spam. Right, which is why "never pay extortion fees" doesn't make much more sense for combatting this stuff than "never click on spam links" makes for combating spam. It's unrealistic to think we will convince enough businesses to altruistically not pay extortionists, just like it's unrealistic to think you'll get your grandmother to sto…

There is nothing altruistic about businesses not paying extortionists. Sure they may come to (some, hopefully limited) harm. But once you as a business pay an extortionist you have just taken on another partner in your business, who will do none of the work and who will take almost all of your profits. So paying out of pragmatism will actually have the exact opposite effect of what you intend to achieve (to make the…

you misread jessriedel.

>> The only way spam will go away is if everybody will finally stop responding to spam.

> Right, which is why "never pay extortion fees" doesn't make much more sense for combatting this stuff ... It's unrealistic to think we will convince enough businesses to altruistically not pay extortionists,

jessriedel is not saying it's altruistic to pay, it's altruistic not to pay.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#80
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

No, profiting in any way off blackmailers looks really bad... Reminds me of when Uber had that surge pricing scandal during the Sydney hostage crisis.

I think the OP meant it as a discount. (E.g. if cloudflare blocking the attack would cost 10k (for 5 sites) for a month, offer a discount at half the ransom (3k) for however long the attack lasts days).
Post reply on HN