Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

81–90 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#81

Earlier quoted context omitted.

There is nothing altruistic about businesses not paying extortionists. Sure they may come to (some, hopefully limited) harm. But once you as a business pay an extortionist you have just taken on another partner in your business, who will do none of the work and who will take almost all of your profits. So paying out of pragmatism will actually have the exact opposite effect of what you intend to achieve (to make the…

you misread jessriedel. >> The only way spam will go away is if everybody will finally stop responding to spam. > Right, which is why "never pay extortion fees" doesn't make much more sense for combatting this stuff ... It's unrealistic to think we will convince enough businesses to altruistically not pay extortionists, jessriedel is not saying it's altruistic to pay, it's altruistic not to pay.

[deleted]

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#82
It seems like the largest threat to the "ransom seeking industry" is for the public to come to believe that paying the the ransom will do no good. Sometimes, such as in cases like this, it becomes publicly known that a ransom is sought before it is paid. An interesting aspect of a Bitcoin ransom is that third parties can verify that a ransom was paid.

Would it be in the legitimate interest of the public as a whole for a third party (possibly governmental) to carry through on the threat as soon as the ransom is paid? This would be to the detriment of the victim, but reduce the likelihood that future ransoms would be paid, and thus eventually might reduce the number of future victims.

Might that be what's happened here?

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#83
post #76

Earlier quoted context omitted.

Cloudflare's $200/month business plan includes DDoS mitigation. It's self-serve and there's an "I'm Under Attack!" button in every account. There's no extra cost for the bandwidth.

So $6000 would get them over two years of self-service DDoS mitigation. Ouch.

If you are in the privacy business, a man-in-the-middle like CloudFlare, is not the thing you try first.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#84
post #55

Earlier quoted context omitted.

> Also, tell your clients to back their stuff up with their own methods, too, just in case you come under heavy attack. This goes for any 'in the cloud' data that you might have. In the end it's your data and your company that is at stake. Not all data wipe-outs are malicious, sometimes accidents do happen.

Except that it seems when it comes to Azure everyone feels safe then also backing up to Azure (specifically talking about SQL database here). Sigh...

Every time I hear stuff like that I point people to this link:

http://www.theregister.co.uk/2014/06/18/code_spaces_destroye...

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#86
post #82

It seems like the largest threat to the "ransom seeking industry" is for the public to come to believe that paying the the ransom will do no good. Sometimes, such as in cases like this, it becomes publicly known that a ransom is sought before it is paid. An interesting aspect of a Bitcoin ransom is that third parties can verify that a ransom was paid. Would it be in the legitimate interest of the public as a whole fo…

That's an interesting angle, but if traced to the source that source would still be 100% on the hook for any and all fall-out from such an attack and I really wonder if any government entity would be willing to sign off on such a vaccination service.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#87
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

Cloudflare don't proxy mail though, which is ProtonMail's main business, so that wouldn't have done much for keeping their services up.

Additionally, I don't see ProtonMail as the kind of company that'll let other third parties terminate their SSL connections/proxy all their traffic.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#88
post #38

Earlier quoted context omitted.

Paying ransom is never worth the long-term costs. Once you've proven to the criminal that you're someone who will pay, they usually try again in the future because you're an easy mark. Not only that, there is a power imbalance that shouldn't be ignored: the criminal has more experience in these kinds of confrontations than you do. Sam Harris has a very good article on this topic[1]; while he is discussing violent int…

> Paying ransom is never worth the long-term costs. I am amazed about how many people are making this claim confidently in this thread. It's clearly wrong. Very, very often it's definitely worth the cost, because very often you will never see the same criminal again. Consider: "Don't pay ransoms, because (1) you'll get extorted again once the criminal knows you're an easy mark and (2) if everyone always refuses to pa…

Muggers are typically not going to come across the same victim twice and word does not spread that you are 'an easy mark'. So the advice to people being mugged is to simply give your stuff rather than to try to put up a fight.

But extortion is different than mugging. See, in extortion you have a perceived weakness other than that you fear for your life and that weakness has subscription possibilities, unlike mugging people. For instance one simple defence against muggers would be to have nothing on your person. Hard to mug you in that case. But since the ransom victim can't really change the nature of his business (short of removing themselves from being online) they will always be open to a replay.

Individuals are not the parties being extorted here, it's companies with some degree of success and visibility. I pretty much guarantee you that every larger entity online has either been prodded by extortionists or will be prodded in the near future. This is a very large business and everybody that pays makes it a bigger issue because of the perceived easy money drawing in ever more prospective extortionists.

Muggers != extortionists. Blackmailers are extortionists and they always come back until they get stopped through some other means (for instance the authorities) or until you tell them to do their worst.

In the case of one Dutch bank this led to intermittent outages over the course of several weeks but eventually they got things under control and there hasn't been a problem since. If on the other hand they had paid I'm pretty sure that they'd be paying a nice monthly protection fee. "It'd be a terrible thing if something happened to that nice website of yours.", it's just the same tactic as the mob employs against shops.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#89
post #63

I suspect, sadly, this is why Gmail and sites like it will continue to win. Secure email always sounds like a good thing, but it's less important in practice than accessible email. If you have to make a choice between confidentiality, integrity, and availability, for day-to-day email, very few people will choose anything other than availability. (The email deliverability problem doesn't help matters, of course.)

an email server doesn't need to be accessible 100% of the time to guarantee deliverability
Post reply on HN