Live data from Hacker News

ProtonMail pays $6k ransom, gets taken out by DDoS anyway

arstechnica.com

211–220 of 233 posts

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#211
post #32

It is always a temptation to an armed and agile nation To call upon a neighbour and to say: -- "We invaded you last night--we are quite prepared to fight, Unless you pay us cash to go away." And that is called asking for Dane-geld, And the people who ask it explain That you've only to pay 'em the Dane-geld And then you'll get rid of the Dane! It is always a temptation for a rich and lazy nation, To puff and look impo…

(Off-topic)

That story is absurd, considering that a lot of modern diplomacy is essentially deciding how much Dane-geld you should pay to appease America, Russia, or (insert your regional power here), and how much you could expect in return for promising that you will not pay the Dane-geld to the other side.

If you don't play, you end up like North Korea, ever so proud for their fierce independence, cut off from everyone else.

I find this cute tale, from a subject of the British Empire, doubly insulting. If you are powerful and you can extract Dane-geld from others, fine, but stop insinuating that other people pay Dane-geld because they're stupid.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#212

Earlier quoted context omitted.

How many of the people who pay these ransoms do you really think are hit again? Very, unlikely.

How can we even know the answer to that question? Additionally: How many of the people who do not pay these ransoms do you really think are hit again?

> How can we even know the answer to that question?

Huh? People report extortion and muggings to the authorities routinely. Combining that with surveys to estimate non-reports should allow us to get a very good estimate.

> How many of the people who do not pay these ransoms do you really think are hit again?

About the same number as people who do pay: Few.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#213

Earlier quoted context omitted.

From their blog: https://protonmaildotcom.wordpress.com/ At around 2PM, the attackers began directly attacking the infrastructure of our upstream providers and the datacenter itself. The coordinated assault on our ISP exceeded 100Gbps and attacked not only the datacenter, but also routers in Zurich, Frankfurt, and other locations where our ISP has nodes. This coordinated assault on key infrastructure eventually manag…

So if you start following what flows out of that bitcoin account, couldn't you find out who it benefits?

No. They ran the coins through a Coin Mixer: https://coinmixer.net

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#214
post #89
post #63

I suspect, sadly, this is why Gmail and sites like it will continue to win. Secure email always sounds like a good thing, but it's less important in practice than accessible email. If you have to make a choice between confidentiality, integrity, and availability, for day-to-day email, very few people will choose anything other than availability. (The email deliverability problem doesn't help matters, of course.)

an email server doesn't need to be accessible 100% of the time to guarantee deliverability

Protonmail's e-mail servers were off line for multiple days. With an outage of that length mail will start to bounce. It depends on the local configuration. But, 3 days/72 hours is pretty standard.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#215
post #4

Earlier quoted context omitted.

But if it buys you time to upgrade your infrastructure it could be worth it.

It's never worth it. For $6k you can get actual protection for some time before you upgrade your infrastructure.

For a site the size of ProtonMail, $6K is the cost for protection for a single month. Most of the companies that offer this kind of protection require you to sign a one to three year contract.

There are two kinds of protection, basic HTTP/HTTPS and DNS only (done with DNS and CDN like servers co-located at peering points), and traffic filtering that is done through BGP with and a GRE tunnel. While you can get basic HTTP/HTTPS and DNS from CloudFlare for $200/month on a business account, what ProtonMail needed was a BGP/GRE which at it's lowest price is a multiple and an order of magnitude more expensive.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#216
post #62

Why couldn't they put it on Cloudflare?

Because ProtonMail would have been required to give CloudFlare encryption keys that would have 1) allowed CloudFlare to inject JavaScript to steal decryption passwords and keys 2) Allowed CloudFlare to collect metadata on traffic for individual users

ClouldFlare are a bunch of great guys. And, they wouldn't do any of that unless they were delivered a National Security Letter forcing them to.

If ProtonMail signed up with CloudFlare, like HushMail did, ProtonMail would have no way to know if these types of code modification attacks or metadata collections were happening.

And, as people saw with Hushmail, since CloudFlare does not do SMTP proxying (filtering/challenging) a DDoS could have still taken down ProtonMail's mail servers offline. While CloudFlare allowed Hushmail to get it's website back online, mail to my Hushmail account is currently delayed by several hours due to DDoS of their mail servers.

From https://hushmailstatus.com/ :

"We're investigating reports of incoming and outgoing email delivery delays. We'll update this page as more information becomes available."

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#217
post #43

Cloudflare should have an emergency hotline for situations like this. Charge half the ransom to handle the traffic for the duration of the attack. Offer contract afterwards.

CloudFlare was the first company ProtonMail called (with in 5 minutes of the DDoS starting). Unfortunately, they couldn't help ProtonMail. But, thanks to @rdl for responding to a txt on his cell phone at an inopportune time and mobilizing CloudFlare's sales and engineering teams to talk with Proton (during the company's retreat no less)!

For all the people getting nasty and arm chair quarter backing this on little to no information or trying to claim credit for things they did not do- understand that once you start working in venture funded startups pretty much everyone knows each other and many people have worked together before.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#218

Earlier quoted context omitted.

The datacenter is not going to be happy if they are offline due to attacks targeting one of their customers. The datacenter has an obligation to their customers, and if that means cutting off ProtonMail so that other customers stay online, then that's what the datacenter has to do. Then, ProtonMail is under pressure to pay the ransom fee to avoid having services terminated by the datacenter.

This is a risk the datacenter exposes their customers to by nature of how they operate. It's a major selling point to me that AWS employs some more sophisticated countermeasures to attacks like these. If their typical response to ransom requests was "you need to consider how you're impacting our business", I would take my business elsewhere.

The problem with ProtonMail is that their business model and brand are based on being domiciled in Switzerland and operating under Swiss law. Their datacenter threatened them if they didn't pay the attackers and no other datacenter in Switzerland was willing to take them. They tweeted out for help finding one after everyone with sufficient bandwidth to withstand the attacks rejected them: https://twitter.com/ProtonMail/status/662212032368889856 Eventually, one came forward. But, the ransom had already been paid at that point.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#219
post #51

Earlier quoted context omitted.

This is the first case I've seen where a digital blackmailer didn't follow through with their promise. It's bad for business for them to renege as it increases the chance that their next victim wont pay.

I have no idea how to verify the statements, but I found some comments on the blockchain.info page for the bitcoin address regarding the DoS. It is supposedly from the blackmailers: https://blockchain.info/address/1FxHcZzW3z9NRSUnQ9Pcp58ddYaS... "Somebody with great power, who wants ProtonMail dead, jumped in after our initial attack!" "We have no such power to crash data center and no reason to attack ProtonMail any…

Verified. ProtonMail received no additional requests for money. And, those are the attackers' words. The original attackers claim they stopped. They hit many other Swiss companies and stopped after they were paid, as well. They are screwed now (and seem to be panicking a bit) because the size of the secondary attack was enough to knock a portion of Swiss internet infrastructure off line, anger some high profile businesses (including banks), anger the Swiss Government, and cause the matter to become a high profile case for Europol.

Re: ProtonMail pays $6k ransom, gets taken out by DDoS anyway

#220
post #204

Earlier quoted context omitted.

None of the other sensible men like Napier gave such a pithy and powerful quote on the topic.

Ah, yes, pithy and powerful quotes! I should be thankful for colonialism for providing pithy and powerful quotes. Take up the white man's burden of speechwriting. Seriously, there are much better arguments for the position you're espousing. I can come up with half a dozen without trying. If you're really interested in contributing to discourse, try making them.

The topic was the banning of Sati. It was just one example of the benefits of British rule. That it is such a salutary example is why I mentioned it. You are welcome to keep crying on Twitter that people said things you don't like but I have nothing further to say to you.
Post reply on HN