I always assumed it used asymmetric encryption, and that the decryption key would never hit the victim's premises.
Definitely not computer gods.
I always assumed it used asymmetric encryption, and that the decryption key would never hit the victim's premises.
Definitely not computer gods.
Or is the reality of this that it's just encrypting a symmetric key with the asymmetric cipher, and then encrypting data using that key?
Than you store that random key encrypted with asymmetric algorithm.
Same goes for things like disk encryption. You never use the users key for encrypting the data. You always encrypt using random large key that is not brute-forcable and encrypt that one with user password, so the process of changing the user password is just decrypting the random key and encrypting it back with new password. Or you would have to re-encrypt the whole disk on password change
Most ransomware authors, I'd wager, have not been reading since before 1997.