Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

31–40 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#31

Is it me or the DOJ so the flight manifest and then went to a grand jury to indict? He did what he did in 2014-2015 and the charges were filed in July 2017, a couple of weeks before Defcon...

If that is the case, it would not be remarkable. Prosecutors have a responsibility to only pursue cases that are likely to result in conviction. If extradition was considered impossible, then there would not be much point in pursing an indictment.

Re: Arrest of WannaCry researcher sends chill through security community

#32
post #26
post #21

Earlier quoted context omitted.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

No I haven't created or sold malware. But i have this; A middle-eastern last name, I use Tor, I use Linux, and I use Telegram, I am active in the field of IT and especially enjoy IT security. I know that I can be held indefinitely if I visit the USA. In the USA you're guilty until proven innocent, unlike the rest of the western world. Simply going to the USA is more risk than it is for practically every other country…

Ok... but what does that have to do with this article or these comments? In this case a banking trojan creator was arrested.

He wasn't middle eastern, he wasn't arrested for using Tor, Linux, or Telegram.

Re: Arrest of WannaCry researcher sends chill through security community

#33
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The quotes came from people who only knew him as a WannaCry researcher, due the fact that the DoJ took forever to say why they were arresting him. It's as if a prominent anti-spammer were to get arrested with no explanation. A naive guess would be that it was due to their anti-spam work. Even though this arrest wasn't related to his WannaCry, that was his most recent exposure to the public and I think assuming it was related to that can be forgiven

Re: Arrest of WannaCry researcher sends chill through security community

#34
post #21

Earlier quoted context omitted.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

Was Marcus Hutchins arrested for selling malware online?

Yes. https://www.documentcloud.org/documents/3912524-Kronos-Indic...

Re: Arrest of WannaCry researcher sends chill through security community

#35
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

You state he is a malware creator b cause the FBI and their indictment told you he is.

The FBI claim he created the software in July 2014, the exact month that he asked on twitter for a copy of the software. Now I am not saying he is innocent but I am also not assuming his guilt because the FBI said he was guilty.

What proof do you have that he is a malware creator selling malware?

Re: Arrest of WannaCry researcher sends chill through security community

#36
post #26
post #21

Earlier quoted context omitted.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

No I haven't created or sold malware. But i have this; A middle-eastern last name, I use Tor, I use Linux, and I use Telegram, I am active in the field of IT and especially enjoy IT security. I know that I can be held indefinitely if I visit the USA. In the USA you're guilty until proven innocent, unlike the rest of the western world. Simply going to the USA is more risk than it is for practically every other country…

You're commenting on an article about how the FBI arrested someone for creating malware. If you haven't been creating malware, then I don't see how this article has anything to do with the issues you face as someone with a middle-eastern last who uses privacy tools like Tor. Hutchins wasn't targeted because of CBP's stance on things it associates with terrorism. He was targeted because the FBI believes he authored malware.

Re: Arrest of WannaCry researcher sends chill through security community

#37
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

> He's not a "hacker" who is doing security research, he's a malware creator selling malware.

There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos.

Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to judge the evidence ourselves.

Re: Arrest of WannaCry researcher sends chill through security community

#39
Lot's of comments about moving DEFCON out of US jurisdiction. DEFCON officially flaunts the fact that both criminals and law enforcement attend the event.[0] If that is the approach of the con, this interaction is built-in.

This isn't about DEFCON.

[0] https://defcon.org/html/links/dc-faq/dc-faq.html

Post reply on HN