3 ms·
> If it became known that ransomware criminals never actually decrypt your data they would lose their "business", so it is in their interest to actually do it.
by lftl 7y ago
> If it became known that ransomware criminals never actually decrypt your data they would lose their "business", so it is in their interest to actually do it.
This opens up one of those weird moral dilemmas akin to asking whether it's moral to hack someone's exposed device to patch a security hole: Would it actually be a net positive to create a ransomware variant that had no decryption key, but acted like it did?
- shittyadmin 7y agoThere've been a few cases where the ransomware was not decryptable - sites like BleepingComputer frequently discuss which ransomware have been cracked by researchers, which are currently actively run and will provide keys and which are undecryptable and you shouldn't pay in any circumstances. Basically it just makes things more complicated, but people are still willing to pay if they can in their specific case and the one they're infected with is reported as regularly providing good keys.