3 ms·
This must be a result of pure ignorance of the victims. As far as I understand, ransomware simply applies RSA on the victim's data. If the victims understood w
by hackerbabz 7y ago
This must be a result of pure ignorance of the victims.
As far as I understand, ransomware simply applies RSA on the victim's data. If the victims understood what that meant, they would understand that it is entirely unrecoverable. The data is simply gone without the private key.
If the data were recoverable that would mean RSA had been broken, and the entire world would know about that. Normal people would understand because the global financial system would need to stop entirely while they switched to a new algorithm.
- deleted 7y ago[deleted]
- john_moscow 7y agoThere are implementation details that could make the data recoverable even when RSA is used. The data itself is typically encrypted using a symmetric cipher (e.g. AES) and the key used for it would be encrypted using RSA. However, if the key for the symmetric algorithm was generated in a predictable way (e.g. using a pseudo-RNG initialized from the system time), it could be possible to bruteforce it in reasonable time.
- deleted 7y ago[deleted]
- chillacy 7y agoThat assumes they applied the encryption correctly. There are many ways to mess it up, and there have been anti-ransomware software made for buggy versions of ransomeware in the past.
- davidgerard 7y agoIt's worth checking it's not fake ransomware - that claims to encrypt your files, but ... doesn't actually bother! c.f. https://www.infoworld.com/article/3062552/how-to-tell-if-youve-been-hit-by-fake-ransomware.html https://www.infoworld.com/article/3062552/how-to-tell-if-you...
- SmellyGeekBoy 7y agoJust because RSA is secure doesn't mean that the specific implementation will be. I've read about versions of this where the decryption key was held in a specific location in RAM for example.
- cyphar 7y agoThere have been plenty of documented cases of crypto-related software having bugs which allowed for full decryption (including many examples of it happening in the land of ransomware which doesn't need strong encryption to extort money out of technically-illiterate people). If you are being sold a product which is based on a lie (let alone a lie that you won't pay criminals and skim money off the proceeds of the crime), then it is always the fault of the seller. Blaming the people who were lied to as being ignorant is a bit rich. (Also, RSA is not really efficient for encrypting large amounts of data. I'm willing to bet that most ransomware uses secret-key crypto like AES or ChaCha20 for the actual encryption and then transmits the secret key back to the C&C server or does some form of key-exchange to generate a secret key. Which means that the attacked machine had a copy of the secret key at some point.)