Slashdot Mirror


What's Up With ProtonMail Outages? (bleepingcomputer.com)

ProtonMail, a secure email service provider used by more than two million users and references of which has been made in shows like Mr. Robot, has been facing outages for the last two days as it fights numerous DDoS attacks. "The attacks went on for several hours, although the outages were far more brief, usually several minutes at a time with the longest outage on the order of 10 minutes," a ProtonMail spokesperson told BleepingComputer, adding that it has tracked the attack to a group that claims to have ties to Russia. But things are more complicated than that, and it appears ProtonMail users, who are already annoyed at the frequent outages over the last few days, are up for more such downtimes in the coming days. BleepingComputer: But in reality, the DDoS attacks have no ties to Russia, weren't even planned to in the first place, and the group behind the attacks denounced being Russian, to begin with. Responsible for the attacks is a hacker group named Apophis Squad. In a private conversation with Bleeping Computer today, one of the group's members detailed yesterday's chain of events. The Apophis member says they targeted ProtonMail at random while testing a beta version of a DDoS booter service the group is developing and preparing to launch.

The group didn't cite any reason outside "testing" for the initial and uncalled for attack on ProtonMail, which they later revealed to have been a 200 Gbps SSDP flood, according to one of their tweets. "After we sent the first attack, we downed it for 60 seconds," an Apophis Squad member told us. He said the group didn't intend to harass ProtonMail all day yesterday or today but decided to do so after ProtonMail's CTO, Bart Butler, responded to one of their tweets calling the group "clowns."

This was a questionable response on the part of the ProtonMail CTO, as it set the hackers against his company even more. "So we then downed them for a few hours," the Apophis Squad said. Subsequent attacks included a whopping TCP-SYN flood estimated at 500 Gbps, as claimed by the group.

88 comments

  1. Not clowns by Anonymous Coward · · Score: 5, Insightful

    Not clowns. Assholes is the proper term.

  2. Not clowns. Ass clowns. by Anonymous Coward · · Score: 0

    That is the proper term.

    They are one of the lowest forms of life on the net. When they get renditioned to some USian bunker in the third world no one will shed a tear or notice.

  3. Probably somebody's heroes by Anonymous Coward · · Score: 0

    though it's hard to imagine who.

  4. Get medieval... by Anonymous Coward · · Score: 0

    It wouldn't bother me to see these clowns get dragged out of their houses and kicked in the back of their heads until they stopped moving. Over and over.

    1. Re:Get medieval... by Anonymous Coward · · Score: 0

      I wouldn't mind seeing you dragged from your mom's basement and kicked in the back of the head. Over and over.

    2. Re:Get medieval... by mnemotronic · · Score: 3, Funny

      Ok kids! Group Hug!

      --
      The Russians have won. They have made the world a cesspool of distrust, greed, fear and hate.
    3. Re:Get medieval... by l0ungeb0y · · Score: 0

      Going off on someones angry, violent rant with an angry, violent rant of your own Please just STFU, because as high and mighty and better than others as you might think you are, you are in fact just another fucking moron who is merely too self-deluded an idiot to see it. Get help, get education, don't speak at all and you might learn a few things

  5. Do Not Taunt Hacker Fun Group by Anonymous Coward · · Score: 0

    That's it.

  6. I see by cascadingstylesheet · · Score: 5, Interesting

    The group didn't cite any reason outside "testing" for the initial and uncalled for attack on ProtonMail

    As opposed to, er, "called for" (justified?) attacks?

    He said the group didn't intend to harass ProtonMail all day yesterday or today but decided to do so after ProtonMail's CTO, Bart Butler, responded to one of their tweets calling the group "clowns."

    Oh. Well then. That's perfectly reasonable then ...

    They are a bunch of clowns. Or paid by GMail ...

    1. Re:I see by Anonymous Coward · · Score: 1

      There's also the issue of taking admitted criminals at their word.

      Given that the gross majority of for-profit cyber crime operations are Eastern European, Russian, or Russian state affiliated (Or all of the above) it's not a bad assumption either.

    2. Re:I see by Zontar+The+Mindless · · Score: 1

      Wondering whether they have anything to do with Slack being DOA world wide for a good part of yesterday?

      --
      Il n'y a pas de Planet B.
    3. Re:I see by Anonymous Coward · · Score: 0

      The should take down Government Propaganda Websites like the US President and Congress.

    4. Re:I see by tattood · · Score: 1

      The group didn't cite any reason outside "testing" for the initial and uncalled for attack on ProtonMail

      As opposed to, er, "called for" (justified?) attacks?

      As opposed to paid-for attacks, which is what their system is intended to be used for.

      --
      WTB [sig], PST!!!
  7. So they act like APK by Khyber · · Score: 4, Interesting

    Little short bursts, and then when someone does anything they perceive as a slight, constant shitstorm until they autistic-fit themselves to exhaustion.

    Amusing. I wonder what they'd have done had the CTO called them fags instead.

    And only a mere 200 Gbit? That's child's play, I've got an easy order of magnitude more bandwidth than that just on my remote office servers alone.

    Betting none of them are over the age of 25, otherwise they'd know where to get real bandwidth.

    --
    Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
    1. Re:So they act like APK by Anonymous Coward · · Score: 0

      > And only a mere 200 Gbit?

      That's BS. I have equipment in four data centers, and the fast connection I can get to one of our racks is 40Gbps Ethernet, and that is terribly expensive. Good bandwidth with good connectivity to other networks is still expensive.

    2. Re:So they act like APK by greenwow · · Score: 2

      What are you using for the physical layer? I call BS on your 2 Tbps claim. I manage 100 Mbps connections to Level 3, Wave, and Verizon, and we're paying over $1k per month each for a connection 20,000 slower than your ridiculous claim.

    3. Re:So they act like APK by Anonymous Coward · · Score: 0

      So you've never worked for a telecom company I imagine?

    4. Re:So they act like APK by Anonymous Coward · · Score: 0

      Where can you get this magical order of a magnitude greater than 200 Gbps connection you claim? I'm in one of the largest exchange points on the west coast, and they're just now rolling out 100 Gbps ethernet.

    5. Re:So they act like APK by greenwow · · Score: 2

      No, but I've seen OC-768 equipment owned by AT&T in a datacenter which is huge, but still less than 40 Gbps. Still waiting on the answer as to how to get a 2 Tbps connection that was claimed. Even OC-3840, which I last I heard isn't being deployed yet, is still only 1/10 of the claimed speed.

    6. Re:So they act like APK by Anonymous Coward · · Score: 0

      Oh please. Even Yahoo was shutdown a few years ago by a DoS attack. It's impossible to have enough bandwidth to mitigate a large scale attack like this with just bandwidth.

    7. Re:So they act like APK by Anonymous Coward · · Score: 0

      >> on my remote office servers
      Maybe he's implying he manages a large number of servers distributed to many locations, at remote offices.

    8. Re:So they act like APK by Anonymous Coward · · Score: 0

      lol 100 gbit of transit costs about 0.13/mbps

    9. Re:So they act like APK by tattood · · Score: 1

      Where can you get this magical order of a magnitude greater than 200 Gbps connection you claim? I'm in one of the largest exchange points on the west coast, and they're just now rolling out 100 Gbps ethernet.

      You could have 20 100 Gbps links. That would give you 2Tbps.

      --
      WTB [sig], PST!!!
    10. Re:So they act like APK by Anonymous Coward · · Score: 0

      Well, 200 Gb is next to nothing for a down direction (which is what would have been flooded), especially at a data center. And then you can divide that by the number of locations. I think that is the point that was being made.

    11. Re:So they act like APK by Khyber · · Score: 1

      " remote office servers"

      I mean, if you can't even think that particular statement through, you shouldn't even be in IT, son.

      As in, GLOBAL REMOTE. When you run a remote virtual office company, you need fucking BANDWIDTH, son.

      --
      Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
    12. Re:So they act like APK by Khyber · · Score: 1

      Your answer was provided.

      And so you know what equipment is used - https://i.imgur.com/wZ0cjjt.pn... in each and every location I have servers.

      Come back when you actually do real global networking, boss. You're about 15 years behind me.

      --
      Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
  8. Worse than clowns by Dog-Cow · · Score: 2, Insightful

    I hope every member of this group that is identified has his balls ripped off.

    1. Re:Worse than clowns by Anonymous Coward · · Score: 0

      What if there are LADIES in this group??

    2. Re:Worse than clowns by Anonymous Coward · · Score: 0

      That's a bit sexist, isn't it?
      Why can't girls also be asshats? ;)

    3. Re:Worse than clowns by Luckyo · · Score: 1

      Ovaries perform the comparable function in ladies.

  9. Free advertising for hacker group by InvalidsYnc · · Score: 1

    Great, all this does is provide advertising for people that will want to contract for their "new and improved" DDoS service.. Nice.

  10. DDoS booter services are illegal by Anonymous Coward · · Score: 0

    Didn't another group just recently get arrested for providing such a "service?"

  11. They're still clowns. by Anonymous Coward · · Score: 0

    Doubling down on their stupidity doesn't change that.

  12. NSA, as always by Anonymous Coward · · Score: 0

    the greatest surveilance state and most paranoid country on the planet, the U.S., is usually the ones behind this. And they are very good at what they call "attribution", making it seem like someone else is doing it. Preferably a scapegoat chosen to stir even more shit up.

    1. Re:NSA, as always by Anonymous Coward · · Score: 0

      And to add: by attacking non-U.S. services, you can slowly herd e-mail users to the large American providers, which is good for American business and surveilance. If the large foreign services are attacked, most likely, America is behind it.

    2. Re: NSA, as always by Anonymous Coward · · Score: 0

      Do you think I'd stop using protonmail to use an american internet provider when our courts ignore the constitution and continually bullshit away our rights? I think not.

    3. Re: NSA, as always by Anonymous Coward · · Score: 0

      Good.

  13. Internet infrastructure is retarded by Pinky's+Brain · · Score: 2

    As an owner of an IP I should be able to tell a service provider to simply cut off traffic from given IPs on his network (or his entire network if they don't do effective ingress/egress filtering). Start up internet 2 with a less retarded infrastructure already, this shit got ridiculous 20 years ago and the fact that we haven't even attempted to fix it is just insane.

    1. Re:Internet infrastructure is retarded by ilsaloving · · Score: 3

      The problem is scale. It's not just a couple machines doing this... It's thousands or 10s of thousands of machines that are usually spread across entire countries or multiple countries. And those machines don't even do sustained traffic anymore. Maybe 20% of them will do The Thing(tm), then they'll go quiet and another batch will start doing The Thing(tm).

      That's why DDOS' ard so hard to mitigate against.

    2. Re:Internet infrastructure is retarded by Anonymous Coward · · Score: 0

      you are retarded, and have no idea about firewalls

    3. Re:Internet infrastructure is retarded by Pinky's+Brain · · Score: 1

      It's not like they can afford to only send a single packet per compromised device, there are still limits to their pool. They each send hundreds of thousands of packets in an attack, if you can detect an IP as an attacker after say a 100 packets and push a rule to their provider which blocks them for a couple of days it will put a huge crimp on the potential.

      Also you can create IP blacklists and ISP blacklists (for the ones with no ingress/egress filtering) similar to the email blacklists. Being attacked, just push the blacklist upstream and if it catches some innocents, oh well ...

    4. Re:Internet infrastructure is retarded by Pinky's+Brain · · Score: 1

      Firewalls don't help unless they are way upstream, that's my point ... as the owner of an IP I should be able to put up a firewall upstream, preferably all the way at the ISP of the attacker (or blocking an entire ISP at the backbone level if the ISP is a known attacker which doesn't bother with ingress/egress filtering).

    5. Re:Internet infrastructure is retarded by SuiteSisterMary · · Score: 1

      In other words, you want to set up an official, institutionalized DDOS?

      I mean, what's the prevent a bad actor from pushing this list to providers which will cut off people for days, with no oversight?

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    6. Re:Internet infrastructure is retarded by Pinky's+Brain · · Score: 1

      PKI based proof of ownership of the IP.

    7. Re:Internet infrastructure is retarded by Pinky's+Brain · · Score: 1

      PS. I should add that if it were not clear, you only block traffic from the suspected attacker's IP to the attacked IP. You don't cut them off the internet, you cut them off from the ability of reaching you. That's why it has to happen at the originator ISP, you can't do it at your own firewall and if you tried to do this even at the backbone level the wire speed and the required sizes of the lookup tables make it all far too expensive. If it happens at the originater's ISPs the resources required are minimal, their existing routers can handle it.

  14. Message to Apophis Squad by Anonymous Coward · · Score: 1

    You guys fucking suck!

    Signed,
    totally the real Microsoft CEO, I swear on his life.

  15. What's up with ProtonMail outages? by DontBeAMoran · · Score: 0

    And what's the deal with airplane peanuts?

    --
    #DeleteFacebook
  16. Given the timing, how about Iran? by Anonymous Coward · · Score: 0

    Large-scale protests in Iran haven't been getting much press in the US the past couple of days because of the Supreme Court news.

    Iran economic protests shut Tehran's Grand Bazaar

    Apparently, crowds in Iran have been shouting "Death to Palestine" and "Our enemy is right here!"

    Maybe the Iranian secret police has caught Iranian civilians using Proton Mail?

  17. Flabby clowns by Anonymous Coward · · Score: 0

    > decided to do so after calling the group "clowns"
    Flabby clowns sounds better?

  18. Impressive numbers by mnemotronic · · Score: 2

    Big numbers. Obviously they have a large botnet. But as soon as they start using it people will figure out the infected units, find the vulns used to subvert them and start unwinding the network.

    And the thing is, what goes around, comes around. Eventually.

    --
    The Russians have won. They have made the world a cesspool of distrust, greed, fear and hate.
    1. Re:Impressive numbers by Anonymous Coward · · Score: 0

      No. If you fight back when NSA or the U.S. government strikes you, then you are a terrorist.

  19. Ask your leader: Putin by Anonymous Coward · · Score: 0

    I'm sure he'll tell you via his employee the steak selling real estate billion dollar money-loser guy.

  20. Sorry, we got the wrong target by mi · · Score: 1

    http://www.nydailynews.com/new-york/ny-metro-teen-murdered-in-bronx-nypd-explorer-20180623-story.html

    --
    In Soviet Washington the swamp drains you.
  21. Thugs feel righteous by mi · · Score: 0

    As opposed to, er, "called for" (justified?) attacks?

    Yeah, such as on the Trump's administration officials...

    --
    In Soviet Washington the swamp drains you.
  22. Clowns? by I-am-a-Banana · · Score: 2

    Calling these guys clowns are an insult to clowns. This group needs jail time and a ban from the internet.

    1. Re:Clowns? by cellocgw · · Score: 2

      Calling these guys clowns are an insult to clowns. This group needs jail time and a ban from the internet.

      So do clowns. Ick Yuck Scary.

      Let alone dealing with Pennywise, who keeps trying to get us to float.

      --
      https://app.box.com/WitthoftResume Code: https://github.com/cellocgw
    2. Re:Clowns? by smooth+wombat · · Score: 1

      Naw. They need to be shot.

      I've gotten to the point where people like this simply need to be removed from society. This isn't an accident or something they didn't know they shouldn't do. They know perfectly well what they're trying to accomplish.

      This goes for all criminals at this point in time. It's not as if the rules of society aren't known. One can't claim they didn't know they shouldn't rob/rape/murder/steal from someone. These basic rules weren't enabled yesterday.

      And yes, this is a reference to ST:TNG, Justice.

      --
      We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
  23. Total American Dude by PopeRatzo · · Score: 4, Funny

    But in reality, the DDoS attacks have no ties to Russia, weren't even planned to in the first place, and the group behind the attacks denounced being Russian, to begin with.

    I'm not sure which language this was translated to English from, but my guess is Russian.

    --
    You are welcome on my lawn.
    1. Re:Total American Dude by Anonymous Coward · · Score: 0

      Actually, it was a Trump Tweet.

    2. Re:Total American Dude by Zontar+The+Mindless · · Score: 1

      Well, yeah--that's sort of the *point*, genius.

      --
      Il n'y a pas de Planet B.
    3. Re:Total American Dude by Anonymous Coward · · Score: 0

      welcome to the new cold war of bullshit....

      this is typical CIA/NSA shit...

      who has most to fear from users with email safe from the eyes of the NSA/CIA? NOT Russia...

  24. Spotted the teenager by Anonymous Coward · · Score: 0

    "retarded"

    Spotted the teenager. Man, did I have to look closely for that one.

  25. Clowns by Anonymous Coward · · Score: 0

    "I don't like warriors. Too narrow-minded, no subtlety. And worse, they fight for hopeless causes. Honor? Huh! Honor's killed millions of people, it hasn't saved a single one. Tell you what I do like though: a killer. A dyed-in-the-wool killer. Cold-blooded, clean, methodical and thorough. Now a real killer, when he picked up the ZF-1, he would have immediately asked about the little red button on the bottom of the gun. [a Mangalore presses the button, detonating a large explosive] Bring me the priest."

    The CTO only needed to call them clowns to make them push the buttons. They're not clowns, they're kids.

  26. Fire the CTO by Anonymous Coward · · Score: 0

    who TF antagonizes hackers when you are a CTO. The majority of the hacker mentality is based off of saying a big screw you to authority. The CTO should have known that the best course of action is to apologizing the down time while not even attributing it to any group or even adding in his personal thoughts of said group. Let the groups claim responsibility them selves rather than letting your ego get the best of you and make smug statements about a group that you are not intimately familiar with.

    When a CTO of a SECURE email provider does not understand the basics of hacker culture and cannot conduct himself with the professionalism that such a position requires then it is time to let him go. FFS, in the end it is inconsequential to him who the attackers are and what his personal feelings on the subject are as it is his job to make sure that his organization has the procedures and processes in place to mitigate such attacks and by contributing his personal opinion of the hackers he is only trying to deflect from his own shortcomings as the CTO.

    1. Re:Fire the CTO by Zontar+The+Mindless · · Score: 1

      Butt-hurt script-kiddy detected.

      --
      Il n'y a pas de Planet B.
    2. Re:Fire the CTO by dos1 · · Score: 1

      Exactly. "Hacker culture" means something completely different.

  27. Will someone please find these people by fredrated · · Score: 1

    and beat them to within an inch of their lives?

    1. Re:Will someone please find these people by Anonymous Coward · · Score: 0

      And then one more inch.

  28. They *are* clowns, and worse. by Anonymous Coward · · Score: 0

    If you're truly just conducting a test, you let your target know. Otherwise it isn't a test, it's just another DDoS attack, end of story. Even if it's only 60 seconds long, you're still affecting a business and its customers without proper warning or actual justification, all for the benefit of your own business and product. Only a true clown would think they have a free pass to fool around as they wish without being seriously called out for it. And only the worst kind of self-centered assholes intentionally escalate the situation after being called out for their legitimately shitty behavior.

  29. nuke em all and let god sort it out by Anonymous Coward · · Score: 0

    as a species, we're lower than virii. time for another reset.

  30. Re:Pope Ratzo the Idiot by Zontar+The+Mindless · · Score: 0

    His Whollyness doesn't care for the fact the the American people were lied to and manipulated by corrupt politicians who sold themselves out to a foreign power, in order to achieve that vote. And I don't, either.

    But the truth is coming out as more of their activities and connections are being brought out and exposed under the bright light of day.

    #TICKTOCK

    --
    Il n'y a pas de Planet B.
  31. What a bunch of clowns by Anonymous Coward · · Score: 0

    Get a life, dickwads.

  32. Re:Pope Ratzo the Idiot by Anonymous Coward · · Score: 0

    It just happened a few minutes ago.

    DeSantos: Mr. Roseinstein, why are you not recused from running an investigation into obstruction into the President over Comey being fired when you gave the recommendation to fire Comey, and the IG report shows in great detail that Comey should be fired?
    Roseinstein: If I see a reason to recuse myself I will.

    Yep, the guy running an investigation for Trump for following his recommendations, refuses to recuse himself due to his involvement. Corrupt from top to bottom, It is already come out. After that single question and answer, Roseinstein has let us know his is corrupt and believes he doesn't need to answer to Congress or the people.

    #TICKTOCK

  33. Re:Pope Ratzo the Idiot by Anonymous Coward · · Score: 0

    the guy running an investigation for Trump for following his recommendations,

    The guy who was asked by Trump to write a recommendation to justify firing Comey, it's not like he just spontaneously wrote the recommendation.

    And in fact Trump said in a nationally broadcasted interview that he had already decided to fire Comey and he was thinking about the Russia investigation when he did it.

    Just sayin'.

  34. "Hackers" by Anonymous Coward · · Score: 0

    Stop calling stupid script kiddies and botnetters "hackers", that's disrespectful for actual hackers, regardless of what meaning you believe this word has today.

  35. Aphos egos writing checks that the gov will cash by Anonymous Coward · · Score: 0

    We've seen these ego-driven types before. They are "Robin Hood"'s, stealing from the rich to give to the poor, they aren't even ethical. They are just your basic lowlife thieves, who try to avoid working for a living but aren't smart enough to start a business or create a product (that they haven't stolen) or a service other people would want to buy.

    When one of them gets caught (not if) they usually end up turning in their "friends" in Aphos in return for a reduced sentence. Setting in a court docket they aren't full of swagger and making big claims. They set there with a clean haircut and shave, in a suit, trying to look less than what they acted like, in a vain attempt to persuade the judge or jury that they aren't the bad boys the government is making them out to be. Soon, the entire bunch is reeled in, convicted, serve time, and when they get out their future income is garnished to pay back at least some of what they've stolen and squandered.

  36. Hey clowns! by Anonymous Coward · · Score: 0

    I read Slashdot. Do what you will.

  37. Re:Aphos egos writing checks that the gov will cas by Anonymous Coward · · Score: 0

    are NOT the "Robin Hood"'s

  38. Not the brightest of the bunch. by Anonymous Coward · · Score: 0

    Giving interviews, etc. instead of remaining in the dark. Leaving traces.

  39. Do not trash talk in Local by xenog · · Score: 1

    Rule number one of EVE Online: do not be salty in public communication channels when somebody destroys your ship for no good reason.