Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

121–130 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#121

Earlier quoted context omitted.

That's naive. If you pay a ransom they'll be back shortly for more. You've just turned yourself into an ATM for your attackers.

as someone who actually did this in their teens, i ddosed someone for 1 day then asked for a couple thousand bucks, but they wouldnt give any so they were ddosed for like 2 weeks. they ended up paying like 750 and i left them alone after that. they ended up losing like 250 grand in sales, could have been prevented by just paying a measly 2

https://www.reddit.com/r/thathappened

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#122
post #119
post #83

Earlier quoted context omitted.

If you are in the privacy business, a man-in-the-middle like CloudFlare, is not the thing you try first.

Really? Do men-in-the-middle matter if your communications are encrypted (be it HTTPS, PGP)?

In this case yes, because users don't get an encrypted channel with the site's servers, only with Cloudflare. Cloudflare isn't acting as a dumb TCP proxy which would allow that. When it hosts an HTTPS website, it does so by terminating the HTTPS connections itself. Cloudflare has the private key, and can see the content of every request/response. That's necessary to compress images, inject scripts, minify code and do all the other optimization/CDN stuff they do -- but it also means making them an MITM between a site and its users.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#123

Earlier quoted context omitted.

That's a false dichotomy if there ever was one. The alternative to being colonized by the British was not to be colonized by Belgium but not to be colonized at all.

It is arguable that India benefitted from being under British rule compared to be in under the rule of mad Moghal emperors though. I'd say gp was not a false dichotomy. Of the options available, British rule was not the worst possible outcome in hindsight. To my Indian friends, please be wary of ultranationalism and the far right. It never does anyone any good. Just look at us and learn from US' shortcomings.

It is amusing to see English-speaking Indians pulling down healthy salaries working in the American tech sector so adamant about the evils of British colonialism and how much it allegedly retarded their country's progress.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#125

NEVER EVER PAY RANSOM MONEY. Please. Even if your business will suffer it will suffer a lot more if you do pay since now it is known you'll cave. Also: you are making the problem larger for others.

What's your opinion on settling bogus litigation?

Hire a hitman, kill main lawyer and go up from there. Will be cheaper than settlement, not to mention full lawsuit.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#126

Earlier quoted context omitted.

> Paying ransom is never worth the long-term costs. I am amazed about how many people are making this claim confidently in this thread. It's clearly wrong. Very, very often it's definitely worth the cost, because very often you will never see the same criminal again. Consider: "Don't pay ransoms, because (1) you'll get extorted again once the criminal knows you're an easy mark and (2) if everyone always refuses to pa…

Muggers are typically not going to come across the same victim twice and word does not spread that you are 'an easy mark'. So the advice to people being mugged is to simply give your stuff rather than to try to put up a fight. But extortion is different than mugging. See, in extortion you have a perceived weakness other than that you fear for your life and that weakness has subscription possibilities, unlike mugging…

How many of the people who pay these ransoms do you really think are hit again? Very, unlikely.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#127

Earlier quoted context omitted.

> The only way spam will go away is if everybody will finally stop responding to spam. Right, which is why "never pay extortion fees" doesn't make much more sense for combatting this stuff than "never click on spam links" makes for combating spam. It's unrealistic to think we will convince enough businesses to altruistically not pay extortionists, just like it's unrealistic to think you'll get your grandmother to sto…

There is nothing altruistic about businesses not paying extortionists. Sure they may come to (some, hopefully limited) harm. But once you as a business pay an extortionist you have just taken on another partner in your business, who will do none of the work and who will take almost all of your profits. So paying out of pragmatism will actually have the exact opposite effect of what you intend to achieve (to make the…

People have offered both self-interested and altruistic arguments for not paying in this thread. Neither are convincing.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#128
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

Wasnt Cloudflare founded by ex fed or something? Hosting isis chat rooms that somehow are not being taken down by US fed is also slightly suspicious.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#129

Earlier quoted context omitted.

The datacenter is not going to be happy if they are offline due to attacks targeting one of their customers. The datacenter has an obligation to their customers, and if that means cutting off ProtonMail so that other customers stay online, then that's what the datacenter has to do. Then, ProtonMail is under pressure to pay the ransom fee to avoid having services terminated by the datacenter.

This is a risk the datacenter exposes their customers to by nature of how they operate. It's a major selling point to me that AWS employs some more sophisticated countermeasures to attacks like these. If their typical response to ransom requests was "you need to consider how you're impacting our business", I would take my business elsewhere.

> I would take my business elsewhere.

Great in theory, but surely nobody "elsewhere" will host you securely if hosting you means all their other customers get hosed.

"the attack against ProtonMail can be divided into two stages. The first stage is the volumetric attack which was targeting just our IP addresses. The second stage is the more complex attack which targeted weak points in the infrastructure of our ISPs. This second phase has not been observed in any other recent attacks on Swiss companies and was technically much more sophisticated. This means that ProtonMail is likely under attack by two separate groups, with the second attackers exhibiting capabilities more commonly possessed by state-sponsored actors. It also shows that the second attackers were not afraid of causing massive collateral damage in order to get at us."

Protonmail could just be talking this up, but if your ISP's (or AWS's) fancy countermeasures don't deal with this, why would they keep you? And why would any other ISP want or accept your business?

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#130
post #53

Earlier quoted context omitted.

Bomb their families instead?

If victims need to be consistent. When terrorists are shown that they'll either get a bomb through the roof or nothing, but never payment, then they'll change their business plan.

The goal of most contemporary terrorist is not personal enrichment.
Post reply on HN