Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>If it gets big enough then people just hear from each other if paying unlocks the data or not.

The idea would be to create "fake" ransomware that looks exactly like the real one

>The best way to end ransomware is to get serious about security

No matter how serious you get there always gonna be bugs, there isn't a single piece of mass distributed software in human history without bugs. That said, we should try to improve security of software but expecting it to be THE solution is wrong.

>Also, I imagine it gets easier after you wrote one i.e. many ransomewares come from the same author. So he could gain a reputation by signing messages saying that yes, this is our ransomware, we always unlock after receiving the payment.

Forging a signature is not that hard.



If forging digital signature is not that hard, then you can release some great scientific paper moving crypto decades ahead, or alternatively you can make billions.


I was talking about pixel-made signatures; you know, the one the user actually sees when the computer its already infected; not cryptography between public/private keys; otherwise its a chicken and egg problem; how do you know what signature its the "real"; you google it and hope nobody added its own search results? Go to the official website of the ransomware developer?


The ransomware can present the key fingerprint for example.

But even without it, there are so many options, e.g. timestamp signed message on the blockchain before the release. After just one confirmed message you don't care about pretenders because people can check if the signature matches with the previous message.


I think you are overestimating the technical capacities of the average randomware victim.


It's enough that some technical people verify it. The average random victim gets his info from news sites and more technical friends.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: