Oddbean new post about | logout
 If you weren't stupid and lazy... you'd have more answers...

A blind man could see this coming. 
There's a lack of leadership. 

If I were the feds I wouldn't give out more info... and they usually hold back a lot. Which he should know since he's testing them... poorly.


It was longer than a day



"The FBI says they received about 1000 decryptors, a nice figure, but it doesn't look like the truth, yes they received some unprotected decryptors, those builds of the locker that were made without the "maximum decryptor protection" checkbox could only be received by the FBI in the last 30 days, it's not known on what day the FBI got access to the server, but we know exactly the date of CVE disclosure and the date when PHP generated an error, before Feb 19th the attacked companies were regularly paying even for unprotected decryptors, so there is a chance the FBI were only on the server for 1 day, it would be nice if the FBI released all the decryptors to the public, then you could trust them that they really own the decryptors, not bluffing and praising their superiority, not the superiority of 1 smart pentester with a public CVE."