TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bitcrypt broken

221 pointsby pedro84over 11 years ago

13 comments

jewelover 11 years ago
This is one reason why I tell people to have both offsite backups (in case of fire, theft, etc.) and <i>offline</i> backups. There are a lot of us that are just one SSH worm away from having all of our files destroyed.<p>I&#x27;ve been thinking about ways to create an offline-equivalent backup, so that it can be automated. One way would be to have a computer that is only connected via serial cable, which only accepts new files to be backed up. (No ability to delete via the serial cable.)
评论 #7274373 未加载
评论 #7275310 未加载
评论 #7274317 未加载
评论 #7276557 未加载
评论 #7276403 未加载
评论 #7276348 未加载
评论 #7274282 未加载
评论 #7274532 未加载
评论 #7275144 未加载
pedro84over 11 years ago
Ransomware crypto fail:<p><pre><code> The number has 128 digits, which could indicate a (big) mistake from the malware author, who wanted to generate a 128 bytes key. Finally, we simply deal with RSA-464 encryption, which can easily be broken on a standard PC in a matter of hours.</code></pre>
评论 #7274295 未加载
CharlesMerriam2over 11 years ago
Every article on security ends with:<p>* Update your anti-virus software * Apply all software updates * Pick a hard password<p>Rarely do these matter: ransomware, Target, etc., are exploits unrelated to these defenses. Why do we push them so hard? Does anyone feel safer and more righteous from advocating this security theatre?
评论 #7274648 未加载
评论 #7274817 未加载
评论 #7274356 未加载
评论 #7274440 未加载
评论 #7280745 未加载
nwhover 11 years ago
Malware aside, it&#x27;s annoying that people still think Bitcoin payments come &quot;from&quot; an address. It&#x27;s not something you can rely on or expect in Bitcoin, and certainly shouldn&#x27;t be used to identify payments by a client. A unique address per payment requested is the proper, expected method.
评论 #7274512 未加载
评论 #7274605 未加载
评论 #7274748 未加载
评论 #7275468 未加载
Tegranover 11 years ago
Malware author probably uses a multitude of wallets, but the one shown in that screenshot has received a few actual payments:<p><a href="https://blockchain.info/address/1HKCHx1RFhNHuF3NxLviHdrjNFzJbCTvrC" rel="nofollow">https:&#x2F;&#x2F;blockchain.info&#x2F;address&#x2F;1HKCHx1RFhNHuF3NxLviHdrjNFzJ...</a>
评论 #7274656 未加载
dreamfactory2over 11 years ago
Isn&#x27;t this the kind of thing the NSA should be spending their time and our money on?
评论 #7275784 未加载
评论 #7275055 未加载
goldenkeyover 11 years ago
Could it be the author made it crackable because he wanted to be able to help anyone recover their files if there was some mishap? Just a thought.
评论 #7274564 未加载
评论 #7274709 未加载
wyagerover 11 years ago
&gt;So, things were clear: the cybercriminal wants 0.4 Bitcoin, which made about 260 Euros at the time of infection, but only 89 Euros at the time of writing (Once again this shows how unreliable the Bitcoin money is, but that is something else).<p>Sigh. The author is using the MtGox price. Mtgox is one of the smaller Bitcoin exchanges these days. Due to their legendary incompetence, they got hacked a while back and disabled Bitcoin withdrawals. As a result, their &quot;Bitcoin&quot; trading price fluctuated from 1&#x2F;2 to 1&#x2F;6th that of other exchanges. The current market value of Bitcoin on <i>all</i> other exchanges is actually 400+ euros right now.
评论 #7277613 未加载
dewizover 11 years ago
Is it just me, or a random new aes pwd for each file makes perfect sense? Otherwise once you brute force one file you could decrypt all the other ones.
评论 #7276132 未加载
mmlover 11 years ago
nb: crashplan will encrypt &amp; back up your stuff locally &amp; remotely (in multiple locations) and keep a version history, which pretty much nips this sort of crap in the bud.<p>(not affiliated with those guys, just a happy user)
rackoons44over 11 years ago
That&#x27;s why you have online and offline backups.
whogothackedover 11 years ago
an Amazing tech system ...
gwernover 11 years ago
&gt; So, things were clear: the cybercriminal wants 0.4 Bitcoin, which made about 260 Euros at the time of infection, but only 89 Euros at the time of writing (Once again this shows how unreliable the Bitcoin money is, but that is something else).<p>Fail.
评论 #7274331 未加载
评论 #7274429 未加载
评论 #7274534 未加载
评论 #7274879 未加载