Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

111–120 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#111

Earlier quoted context omitted.

When you are weak, you take what you can get. It was much better to have been colonized by the British, who actually had an interest in nation-building and respect for law and human rights (to the extent they deemed their subjects capable of handling them), than, say, to have become the personal fiefdom of Leopold II of Belgium.

That's a false dichotomy if there ever was one. The alternative to being colonized by the British was not to be colonized by Belgium but not to be colonized at all.

It is arguable that India benefitted from being under British rule compared to be in under the rule of mad Moghal emperors though. I'd say gp was not a false dichotomy. Of the options available, British rule was not the worst possible outcome in hindsight.

To my Indian friends, please be wary of ultranationalism and the far right. It never does anyone any good. Just look at us and learn from US' shortcomings.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#112

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

What's your opinion on settling bogus litigation?

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#113
post #32

It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…

I guess Kipling's knowledge of this had a practical basis, since he was one of the chief apologists for the systematic extortion the British Empire used to enrich itself.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#114
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

We (CloudFlare) do. We have done onboardings in real time with people under attacks. We do full length contracts because that works better for customers, though.

We don't proxy smtp. There are solutions to deal with that in a hybrid way, though.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#115
post #61

Earlier quoted context omitted.

Ransomware is a different scenario. With ransomware, if you have no backups and absolutely need your files back, paying the ransom is the only sane option. Of course, this can easily be prevented by taking frequent backups. With a DDoS, there are almost no advantages to paying the ransom. Much better to spend the money on DDoS mitigation instead, to help now and in the future. Also, the FBI wasn't making an official…

In fact backups is not enough. It has to be offline backups, which raises the bar quite a bit. Backing up to a network drive doesn't even help, and I am not aware of any wildly used "write once-only" network drive capabilities.

Backup to an external hard drive that you only leave connected during the backup, or a cloud service (ransomware could theoretically target these but so far have not), or do a "pull-style" backup where the machine doesn't have write access to the backup location.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#116
post #32

It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…

Sometimes this is good advice. For some rather vivid counterexamples, read up on Genghis Khan. Computer security is of course a whole different thing.

Yes, pros and cons, its quite possible that by paying one then has enough breathing space to set up better defences.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#118
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

Cloudflare don't proxy mail though, which is ProtonMail's main business, so that wouldn't have done much for keeping their services up. Additionally, I don't see ProtonMail as the kind of company that'll let other third parties terminate their SSL connections/proxy all their traffic.

They have BGP origin protection, where they announce your IP space for enterprise plan, probably expensive though.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#119
post #83
post #76

Earlier quoted context omitted.

So $6000 would get them over two years of self-service DDoS mitigation. Ouch.

If you are in the privacy business, a man-in-the-middle like CloudFlare, is not the thing you try first.

Really? Do men-in-the-middle matter if your communications are encrypted (be it HTTPS, PGP)?

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#120

Earlier quoted context omitted.

That's even weirder. They have obligations to their customers not to their neighbors in the same DC, that's the territory of whoever handles their hosting.

The datacenter is not going to be happy if they are offline due to attacks targeting one of their customers. The datacenter has an obligation to their customers, and if that means cutting off ProtonMail so that other customers stay online, then that's what the datacenter has to do. Then, ProtonMail is under pressure to pay the ransom fee to avoid having services terminated by the datacenter.

This is a risk the datacenter exposes their customers to by nature of how they operate. It's a major selling point to me that AWS employs some more sophisticated countermeasures to attacks like these. If their typical response to ransom requests was "you need to consider how you're impacting our business", I would take my business elsewhere.
Post reply on HN