Skip to content

Comment on The Enemy Within: What is Conficker's Botnet For?parent

Comments

It's layman writing. The worm uses RSA and RC4. SHA1 or MD6 as a hash. Designing these would obviously take a very skilled cryptographer (actually many, many cryptographers). Implementing it just requires a smart programmer who knows a decent amount about cryptography.

And deploying it only requires someone who can import a library and follow instructions.

Eh, not really. If you were talking about a fully defined cryptographic protocol like SSL I would say you were right, but if you're talking about actual cryptographic implementation I would say that it requires a little more knowledge.

See tptacek's post about "Typing the letter's A-E-S'" into your code and cperciva's many post about improper use of secure cryptography.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.