Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

201–210 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#201

There's regular security solutions then there's those meant to stop High Strength Attackers. I warned ProtonMail's team and infrastructure wouldn't handle the latter. I was expecting stealth 0-days, though, given there's DDOS mitigations available. That they went down due to DDOS was a bit of a surprise. "Cost estimates for these solutions are around $100,000 per year since there are few service providers able to fig…

You mentioned that you warned ProtonMail's team about High Strength Attackers. What else did you warn them about? What other security flaws do they have in your opinion?

I warned others about them. I rarely warn projects any more because my associates and I have done that until we were blue in the face with little effort. My MO is to just post good stuff in forums that attract talent so they might see and adopt it. In any case, I posted a write-up on what real security is and what goes into it on Schneier's blog in response to a [false] comment saying secure coding is all you need. Here's the Pastebin of it:

http://pastebin.com/y3PufJ0V

Here's a specific example where I try to make a step-by-step guide for high assurance Tor without knowing its internals. Just drew on my prior work:

https://www.schneier.com/blog/archives/2014/09/identifying_d...

Hope what High Assurance Security takes is more clear now. Unless you get lucky (eg GPG), you need high assurance to resist TLA's successfully and that might just be delaying inevitable. Still need monitoring & tamper-detection.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#202

Earlier quoted context omitted.

Muggers are typically not going to come across the same victim twice and word does not spread that you are 'an easy mark'. So the advice to people being mugged is to simply give your stuff rather than to try to put up a fight. But extortion is different than mugging. See, in extortion you have a perceived weakness other than that you fear for your life and that weakness has subscription possibilities, unlike mugging…

How many of the people who pay these ransoms do you really think are hit again? Very, unlikely.

How can we even know the answer to that question?

Additionally: How many of the people who do not pay these ransoms do you really think are hit again?

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#203
post #190

Earlier quoted context omitted.

would you rather had the British empire or the Belgium or Germans as your colonial masters?

If you're genuinely interested in an answer, then like a sibling said, its "neither". Colonialism wasn't as inevitable as its made out to be, and the countries that were colonized weren't "uncivilized" or "barbaric": things that world history (amazingly) continues to propagate. e.g. Colonialism in India was an incredible amount of good luck and some wily statesmanship, and not due to lack of technological progress. O…

True and India is a good example of why relying on foreign mercenary's to fight your wars has its downside.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#204
post #102

Earlier quoted context omitted.

Napier is one of my favorite historical figures, but wasn't sati banned based on the requests of (native) Hindu reformers, and Napier merely spoke in favor of the ban when other Hindu priests complained? It seems like a stretch to argue that it was Napier who worked to put an end to sati.

None of the other sensible men like Napier gave such a pithy and powerful quote on the topic.

Ah, yes, pithy and powerful quotes! I should be thankful for colonialism for providing pithy and powerful quotes. Take up the white man's burden of speechwriting.

Seriously, there are much better arguments for the position you're espousing. I can come up with half a dozen without trying. If you're really interested in contributing to discourse, try making them.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#205

Earlier quoted context omitted.

"This was a collective decision taken by all impacted companies" I think they were put under pressure by other companies using the same IPS, not their customers.

That's even weirder. They have obligations to their customers not to their neighbors in the same DC, that's the territory of whoever handles their hosting.

>that's the territory of whoever handles their hosting.

Yes. And what does a provider do when a customer is getting hit so hard by a ddos that it is pushing their other customers offline? they blackhole the target at their upstream (usually starting on a per-IP basis, but that will widen as the attacker shifts the target)

So... most likely, the isp said "if this continues, we will need to finish the job and shut you off" - which is what every other ISP is going to do in the case of an attack that is large enough to knock the ISP in question offline.

Check out the legalese on your hosting contract; everyone reserves the right to dump you as a customer in these sorts of cases.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#206

Earlier quoted context omitted.

The datacenter is not going to be happy if they are offline due to attacks targeting one of their customers. The datacenter has an obligation to their customers, and if that means cutting off ProtonMail so that other customers stay online, then that's what the datacenter has to do. Then, ProtonMail is under pressure to pay the ransom fee to avoid having services terminated by the datacenter.

This is a risk the datacenter exposes their customers to by nature of how they operate. It's a major selling point to me that AWS employs some more sophisticated countermeasures to attacks like these. If their typical response to ransom requests was "you need to consider how you're impacting our business", I would take my business elsewhere.

> It's a major selling point to me that AWS employs some more sophisticated countermeasures to attacks like these.

There are very good clean pipe services available; the major limitation is that the clean pipe provider must have enough capacity to absorb any attack... something that can be quite difficult unless you are someone like L3.

However, the good clean pipe services are all very expensive. (I don't mean the "http only" service like cloudflare; that is a very different sort of thing.) - this is because of that aforementioned limitation; you need a lot of headroom in your bandwidth to run a clean pipe service.

But yeah, amazon charges a lot more for bandwidth than you'd expect to pay direct from a transit provider at small-ISP scale, so I would hope that they have enough capacity and technology to filter fairly large attacks.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#207

Earlier quoted context omitted.

I guess Kipling's knowledge of this had a practical basis, since he was one of the chief apologists for the systematic extortion the British Empire used to enrich itself.

(Note - I am from one of the countries invaded and occupied by Britain) I must come to Britain's defence here - it's behaviour was normal in those times but it did eventually give up most of its "ownership" without actually being defeated in wars. That was pretty amazing. By modern standards, British behaviour was despicable, but a lot of the invaded countries got enormous benefits - rule of law, economic infrastruct…

Would those countries have the same benefits without British rule? I think they would.

And as for Britain "giving up" their claims, they simply couldn't afford to keep India after the Indian military rebelled, and without India, they simply had not enough colonies to make profitable quickly after the devastation of WWII.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#208

Earlier quoted context omitted.

That's a false dichotomy if there ever was one. The alternative to being colonized by the British was not to be colonized by Belgium but not to be colonized at all.

If it were my country, I'd have picked British rule over self-rule. A robust system of laws is nothing to sneeze at. Look all over the former British Empire, and you'll see robust, healthy democracies peacefully trading with their former rulers. Countries that were never colonized got left out of the huge technological race that modernized the rest of the world after WW2. The Anglosphere nations are among the most po…

Most of the colonised countries were left out of the technological race too.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#209

Earlier quoted context omitted.

Every time I hear stuff like that I point people to this link: http://www.theregister.co.uk/2014/06/18/code_spaces_destroye...

Damn, I feel for them. That said, I feel better about how I've incessantly posted Wheeler's page over the years whenever source control comes up. Despite many being annoyed, they have no idea how important it is to have great security, storage, and recovery on this stuff. Between Wheeler's page & Orange Book A1 stuff, the practices today look kind of abysmal and ripe for the taking. http://www.dwheeler.com/essays/scm…

I come from a banking background so that stuff seems normal to me but what I find in the wild every now and then has me wondering how long it will be before a major service will go off-line due to some act of premeditated vandalism. It can't go on forever like this.

SoD alone would go a very long way to close some of the larger holes (dd question: who has access to your backups?) but even that is something that a lot more people seem to be aware of than is put into practice.

The amount of trust placed in the hands of a very few people is scary, and to do all that without real backups is something that would keep me awake at night if my bread and butter depended on it.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#210
post #205

Earlier quoted context omitted.

That's even weirder. They have obligations to their customers not to their neighbors in the same DC, that's the territory of whoever handles their hosting.

>that's the territory of whoever handles their hosting. Yes. And what does a provider do when a customer is getting hit so hard by a ddos that it is pushing their other customers offline? they blackhole the target at their upstream (usually starting on a per-IP basis, but that will widen as the attacker shifts the target) So... most likely, the isp said "if this continues, we will need to finish the job and shut you…

Yes, absolutely. And that's acceptable. If your customers can't deal with the realities of the internet today then you're better off without them anyway, no service will be able to guarantee 100% uptime and if major banks can be taken out by DDoS then so can a small time operator like this. That's no news and should not suprise anybody.
Post reply on HN