Live data from Hacker News

Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

motherboard.vice.com

131–140 of 268 posts

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#131

Earlier quoted context omitted.

It's not clear to me why he should've expected arrest. He didn't write the virus, he shut it down. The arrest makes no sense. It's not a reasonable thing to have expected. I was at DEF CON too, for what it's worth.

There's almost zero chance that he was arrested for stopping Wannacry. I'd guess a 23-year old in that business has a history of "less-than-white-hat" activities...

There's several other comments in this thread now saying things to that effect. I suppose that's not too surprising.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#132
post #31

No good deed goes unpunished. But why is DefCon still in the US? I think the creators of the conference might want to seriously think about holding it somewhere that isn't so hostile to pretty much everyone who attends.

You mean like Defcon Beijing?

FYI for those reading this, that's not a joke. Defcon actually seems to be hosting a con in Beijing in the near future.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#133
post #92

Earlier quoted context omitted.

I always assumed the two to be different people. The log shows the two of them talking at the same time, and I remember the two of them having very different attitudes in general. I know TouchMe is malwaretech but would be inclined to assume that BetaMonkey isn't. TouchMe was still a malware developer though, and apparently used to run voidptr before handing it over to BetaMonkey.

I was pretty sure TouchMe was BetaMonkey's new nick, I don't think it was Ntoskrnl (MalwareTech). From what I've heard TouchMe continued support of his drone's users until he dissapeared without a trace. This was so long ago and my memory isn't amazing.

TouchMe is MalwareTech, 0 doubt https://twitter.com/touchmymalware

If BetaMonkey==TouchMe then they were trying really hard to conceal that.

Here's a hackforums thread mentioning some other malware TouchMe was distributing though https://hackforums.net/showthread.php?tid=3786935

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#134
The Guardian has more:

https://www.theguardian.com/technology/2017/aug/03/researche...

He may have a shady past:

  According to an indictment released by the US Department of Justice, Hutchins is accused of having helped to spread and maintain the banking trojan Kronos between 2014 and 2015"

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#135

Earlier quoted context omitted.

There are zero details on this story...calm down..

There are absolutely details: > Motherboard verified that a detainee called Marcus Hutchins, 23, was being held at the Henderson Detention Center in Nevada early on Thursday. So at least we know he was detained. This one relies on a friend, so presumably it's "less verified" as far as these things go: > A few hours after, Hutchins was moved to another facility, according to a close personal friend. I don't know if Mo…

Detained for what? You don't know.

I mean, I agree, detainment isn't usually the way to make friends, but those are not specific details of the incident.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#136
post #19

Maybe he violated WannaCry's terms of service. The DoJ are pretty down on that kind of thing.

Indeed. If he didnt get permission to stop WanaCry, then he violated the CFAA. No, a "crime" is not good justification of a different crime. I wish I was making this stuff up, but thank overly-broad '80s laws regarding "access", "permission", and that sort of language which weaponizes EULAs.

UK is no better.

http://www.legislation.gov.uk/ukpga/1990/18

That thing is 27 years old.

Massively over broad.

> Section 37 (Making, supplying or obtaining articles for use in computer misuse offences) inserts a new section 3A into the 1990 Act and has drawn considerable criticism from IT professionals, as many of their tools can be used by criminals in addition to their legitimate purposes, and thus fall under section 3A.

Basically supplying a disassembler to someone who then uses it for a crime is itself possibly covered for example.

It's the possibly that's the problem, when you can't tell if an offence has actually been committed you leave it open for abuse.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#137

This reminds me of Kevin Mitnick: https://en.wikipedia.org/wiki/Kevin_Mitnick#Arrest.2C_convic... Do we need to create some "Free Marcus" bumper stickers?

Mitnick was actually a criminal. He was living off stolen credit cards.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#138

Earlier quoted context omitted.

It's not clear to me why he should've expected arrest. He didn't write the virus, he shut it down. The arrest makes no sense. It's not a reasonable thing to have expected. I was at DEF CON too, for what it's worth.

There's almost zero chance that he was arrested for stopping Wannacry. I'd guess a 23-year old in that business has a history of "less-than-white-hat" activities...

> I'd guess a 23-year old in that business has a history of "less-than-white-hat" activities...

Indeed, and given that he's only 23 years old, there's a good chance the statute of limitations has not been reached for those activities.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#140

Earlier quoted context omitted.

I guess not everyone was happy that he stopped Wannacry. US agencies in particular.

This is utter nonsense. He didn't stop Wannacry. The Wannacry devs stopped Wannacry, if he didn't grab the domain it'd have been picked up by some other TI firm within minutes or hours.

I mean, he literally stopped WannaCry.

Just because someone else could have stopped it, doesn't mean he didn't stop it. That's... just a fact...

Post reply on HN