Nearly all my personal photos were encrypted by the helprecover@foxmail.com ("HELP") variant of Phobos. I've been holding onto the encrypted copies for a while in hopes that some people were working on a crack, and I'm excited to read this update. Sidecar question: when automating your backups, what's a good way to make sure your rolling backups aren't simply backing up malware-encrypted files? I found out too late t…
A tale of Phobos – How we almost cracked a ransomware using CUDA
11–20 of 65 posts
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#12More secure data storage at companies where otherwise it would be just silently stolen and sold. More backups. Even some incentive to research security of encryption methods.
We won't get more secure systems without some proper incentives.
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#13Overall, cool work! Especially the search space reduction part. I haven't dive into the code, but only 818000/60=13633 attempts per second for 64 SHA-256 rounds plus one AES-256 decryption on a 2080 doesn't sound right. Learn some GPU and tuning the code can likely increase the throughput a lot. Mind you, that's only 25x naive Python implementation on (supposedly) 1 core. Also, hashcat does >1M hash/s for even higher…
Thanks! I wonder if the Python number is correct, I remember Python being prohibitively slow in comparison. But assuming it is: There are 256 sha256 iterations on average, so the number is a bit better - but there's probably still a lot to improve (it's much more optimised than the naive version, but it was written by reverse-engineers, not GPGPU specialists). The PoC was also opensourced [0], it would be great if so…
Now I'm quite fond of python, but largely I read this as the CUDA implementation having quite some room for improvement. Having almost no CUDA experience of my own, that is just a hunch, which I'm glad rfoo supports with (surely) a lot more experience than me.
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#14I know I'm in minority and that this view is not empathetic one, but I really like that ransomware is around. More secure data storage at companies where otherwise it would be just silently stolen and sold. More backups. Even some incentive to research security of encryption methods. We won't get more secure systems without some proper incentives.
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#15So, if you're a victim and you don't want to pay ransom - hire an expert to find out the missing data (timestamp, is it the vulnerable version?, ...), then - rent a GPU server and keep the fingers crossed. I've looked for cheap GPU servers yesterday, the cheapest i found was Ultrarender at 200€ per week for a Dual RTX 3080Ti remote workstation. Which is probably overkill, a single RTX 3080Ti can do it in 33 hours or…
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#16Nearly all my personal photos were encrypted by the helprecover@foxmail.com ("HELP") variant of Phobos. I've been holding onto the encrypted copies for a while in hopes that some people were working on a crack, and I'm excited to read this update. Sidecar question: when automating your backups, what's a good way to make sure your rolling backups aren't simply backing up malware-encrypted files? I found out too late t…
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#17Nearly all my personal photos were encrypted by the helprecover@foxmail.com ("HELP") variant of Phobos. I've been holding onto the encrypted copies for a while in hopes that some people were working on a crack, and I'm excited to read this update. Sidecar question: when automating your backups, what's a good way to make sure your rolling backups aren't simply backing up malware-encrypted files? I found out too late t…
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#18Nearly all my personal photos were encrypted by the helprecover@foxmail.com ("HELP") variant of Phobos. I've been holding onto the encrypted copies for a while in hopes that some people were working on a crack, and I'm excited to read this update. Sidecar question: when automating your backups, what's a good way to make sure your rolling backups aren't simply backing up malware-encrypted files? I found out too late t…
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#19Nearly all my personal photos were encrypted by the helprecover@foxmail.com ("HELP") variant of Phobos. I've been holding onto the encrypted copies for a while in hopes that some people were working on a crack, and I'm excited to read this update. Sidecar question: when automating your backups, what's a good way to make sure your rolling backups aren't simply backing up malware-encrypted files? I found out too late t…
Re: A tale of Phobos – How we almost cracked a ransomware using CUDA
#20phobos is not a moon !!! phobos is the god and personification of fear and panic in Greek mythology. this is crucial in understanding ransomware ;)
Perhaps most importantly, also a knight of Mars, beater of ass [2]
1 https://solarsystem.nasa.gov/moons/mars-moons/phobos/in-dept...