3 ms·
I was talking about pixel-made signatures; you know, the one the user actually sees when the computer its already infected; not cryptography between public/priv
by notgood 9y ago
I was talking about pixel-made signatures; you know, the one the user actually sees when the computer its already infected; not cryptography between public/private keys; otherwise its a chicken and egg problem; how do you know what signature its the "real"; you google it and hope nobody added its own search results? Go to the official website of the ransomware developer?
- comboy 9y agoThe ransomware can present the key fingerprint for example. But even without it, there are so many options, e.g. timestamp signed message on the blockchain before the release. After just one confirmed message you don't care about pretenders because people can check if the signature matches with the previous message.