4 ms·
> So long as there's one private key corresponding to a pinned public key, the malware's defeated if the private key can be recovered (assuming I'm understandin
by TimWolla 11y ago
> So long as there's one private key corresponding to a pinned public key, the malware's defeated if the private key can be recovered (assuming I'm understanding your suggestion correctly).
Once the ransomware delivered the page to enough users (for some number of enough) it can permanently remove the key used to do so. The header now contains the just-removed key used to poison the browser and a randomly generated hash that does not correspond to a valid key. This assumes that the administrator does not detect the ransomware before it does so.