Live data from Hacker News

Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

motherboard.vice.com

211–220 of 268 posts

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#211

Reading the indictment, it seems like his partner ratted him out. Curious though, the indictment seems to list the redacted partner as doing most of the incriminating things (posting a video demonstration, advertising the sale on AlphaBay, etc), it merely accused Marcus as being the author and co-conspirator. I wonder if his partner/friend got caught, and plea bargained to turn state's evidence against Marcus.

> I wonder if his partner/friend got caught, and plea bargained to turn state's evidence against Marcus.

I always wonder a bit about how often these things end up like Rubin Carter, with the guilty party turning state's evidence against someone less guilty or entirely innocent. I mean... one presumes there's more evidence generated by being more involved with the crime, as in this case. If you catch whoever is most identifiable and turn them, there ought to be a lot of cases where you're starting with the worst player and cutting them a deal.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#212

FYI, if you've committed any form of cybercrime in the previous 3 years (edit: the statute of limitations is 5 years for most federal computer crimes, as pointed out below), you should avoid such conferences in the US for exactly this reason. You probably aren't as smart as you think, and there may be a sealed arrest warrant for you. The FBI waits for these kinds of conferences to do exactly what they did here. Anoth…

Wouldn't it be better for everyone if US infosec conferences were hosted in Canada ?

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#213
post #199

Earlier quoted context omitted.

Detained for what? You don't know. I mean, I agree, detainment isn't usually the way to make friends, but those are not specific details of the incident.

We should have overwhelming confidence that people are detained for good reasons. Given US's track record, it is entirely reasonable to think that it's not the case, until demonstrated otherwise by proof brought forward by the agressor.

[deleted]

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#214
post #21

Why are people in this thread so outraged without knowing any of the facts? For all we know there might be a legitimate charge on which he was arrested. As per him being untraceable, if he was not read his rights then the FBI just jeopardized their own case. If no one knows where he is, it's more likely that it's what Marcus wants at the moment rather than what the FBI wants.

> As per him being untraceable, if he was not read his rights

Rights? Which rights?

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#215
post #196

FYI, if you've committed any form of cybercrime in the previous 3 years (edit: the statute of limitations is 5 years for most federal computer crimes, as pointed out below), you should avoid such conferences in the US for exactly this reason. You probably aren't as smart as you think, and there may be a sealed arrest warrant for you. The FBI waits for these kinds of conferences to do exactly what they did here. Anoth…

> FYI, if you've committed any form of cybercrime According to the US definition of cybercrime. So you could be totally innocent in your country, and have done nothing directly in the US.

And according to the US definition of cybercrime, we are probably all guilty of something.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#216
post #7

As much as this article contains very little information,this sounds very much like something the US will do. Whenever someone has to be the butt of some global joke .....somehow the US has to be the one to step up. Taking someone into custody for 18 hours without giving the family or press any information. How different is this from Iran or North Korea? Two things could've happened here IMO. They asked for the domai…

You called it

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#217
post #200
post #51

Earlier quoted context omitted.

He ran a carding forum in the past, malkit.ws and then malkit.su. Virustotal passive DNS shows that it was hosted for a time on the same server as his old irc, irc.voidptr.cz https://www.virustotal.com/en/ip-address/188.190.99.148/info...

I don't think he directly ran his own IRC, it was a "in partnership with another organization" sort of thing.

Here it is

> For anyone still into IRC, MalwareTech has partnered with sigterm.no to launch a new IRC network. It’s still fairly new so don’t expect an instant response, but everyone is welcome (socializing or just asking for help).

https://www.malwaretech.com/2014/10/new-irc-launc.html

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#218

Earlier quoted context omitted.

Why are people in this thread so outraged without knowing any of the facts? For all we know there might be a legitimate charge on which he was arrested. Because US law enforcement have consciously chosen, over the past couple of decades, to engage in activities that make them "the bad guy". It's just abductive inference and a simple bayesian prior at this point. Nobody is reaching any absolute conclusions yet, but a…

US law enforcement would be horrifically, jaw-droppingly corrupt if 20% of arrests were "malicious." But even then, 80% of arrests would be non-malicious, so a very strong prior that a given arrest is malicious would be completely unreasonable. "US law enforcement is the bad guy, therefore any given choice they make is probably evil" is fiction-logic. It works in movies, not in real life.

80% of arrests would be non-malicious, so a very strong prior that a given arrest is malicious would be completely unreasonable.

Sure, but we're not talking about a randomly selected item here. Looking at US arrests w/r/t "cybercrime" and given the history of overly broad interpretations of the CFAA and what-not, I think it's a lot less clear than you are suggesting.

"US law enforcement is the bad guy, therefore any given choice they make is probably evil" is fiction-logic. It works in movies, not in real life.

We're not talking about "logic" (as in "deductive logic") here... w're talking about the kind of fuzzy reasoning, based on abduction and bayesian inference, that human beings use in the face of limited information... and with an understanding that you revise your position as new information is acquired.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#219
post #189

FYI, if you've committed any form of cybercrime in the previous 3 years (edit: the statute of limitations is 5 years for most federal computer crimes, as pointed out below), you should avoid such conferences in the US for exactly this reason. You probably aren't as smart as you think, and there may be a sealed arrest warrant for you. The FBI waits for these kinds of conferences to do exactly what they did here. Anoth…

Shouldn't we all avoid US conferences? Half the people have some day done something which in a generic way is "against US interests" (from a false name on Facebook to competing against a US corp to starting a petition or a secure app). I personally don't go to US conferences or visit US customers, simply because of TSA (same for Japan and China; Europe has a better track record). If you have a choice, it's not really…

Competing against a US corporation is not a crime and neither is a False name on Facebook.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#220
post #10

This sends a clear message to the global whitehat security community: travel to the US at your own peril.

Or, maybe, there's a legit good or bad reason that he is unreachable? But let's just jump to the conclusion that he was blackbagged and in a CIA black site.

How many security researchers have squeaky-clean records, though? In hindsight, gathering all of the hackers under one of the most sophisticated, militant, intelligence systems in the world, might not be a great idea.
Post reply on HN