Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

41–50 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#41
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos.

A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code?

There's also little/no published information to back up the statement that he ever sold Kronos.

[1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

Re: Arrest of WannaCry researcher sends chill through security community

#43
post #20

If your code is used in an exploit and that is now a punishable crime, maybe next the NSA will be in the hot seat since the code that was used in wanacry was their own. Or perhaps Israel for their effort in Stuxnet. I hope he takes it to trial and we find out what is really happening here. Pretty suspicious that this happens years after the fact and only weeks after he helped prevent the further spread of wannaCry. W…

Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?

Re: Arrest of WannaCry researcher sends chill through security community

#45
post #6
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

Extradition needn't have come into it. The US authorities could have sent their evidence to the UK police to deal with (assuming the UK police didn't have it to start with). If we want justice to be seen to be done, we shouldn't encourage "forum-shopping" by law-enforcement, letting them bring prosecutions in a country where the defendent will be artificially disadvantaged.

This isn't "forum-shopping". Not every crime is going to get someone extradited, which is a huge hassle, but if the person accused is going to be entering the country of course you grab him.

Re: Arrest of WannaCry researcher sends chill through security community

#46
Perhaps you are being deliberately obtuse I'm not sure. The point the poster was making is that the US happily arrests foreigners who set foot in the US and regardless of your guilt or innocence you get trapped in the US justice system which is essentially a system to tie you up in court and legal processes that you cannot afford so that you accept a plea deal, possibly for something you have not done, because otherwise you face never seeing the outside world again. The US justice system then acts like the guilty plea is enough to warrant their behaviour even though many times it is accepted by the defendant because they have no other options.

This also applies if you are a poor American citizen, the rich can buy their release with sufficient payment to lawyers, plus the courts tend to be more lenient on the rich over there, especially if they are white. Rich coloured people have a tough time because the justice system likes to make examples of them and claim the example is being made because they are rich and not because they are non-white.

Re: Arrest of WannaCry researcher sends chill through security community

#47
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

Re: Arrest of WannaCry researcher sends chill through security community

#48

I hope it goes to trial, and he is not found guilty. Should be a relatively easy case to win.

The US will try to force him into a plea deal where the alternative is 50 years in prison so that they can say "see we were justified in arresting him because he wouldn't plead guilty of he hadn't done anything wrong"

Re: Arrest of WannaCry researcher sends chill through security community

#49
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

So many extradition experts visiting Hacker News these days.

Re: Arrest of WannaCry researcher sends chill through security community

#50
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

>>Why is this "sending a chill through the security community"?

because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field.

The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view completely innocent actions as something else. No room for the FBI to be in error, no room for the FBI to be wrong.

The government has routinely, time and time again, over extended and prosecuted several people wrongly under CFAA, which is a terrible and broad law that can be applied at will to many innocent every day computer actions.

Post reply on HN