Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

51–60 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#51
As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after him for WannaCry." Additionally, there may well be other arguments in his favor that I'm not even thinking of.

But those arguments need to be made (and the one I outlined would need decent factual details). That said...maybe glossing over (or even totally ignoring) Kronos is the best way for Hutchins supporters to go...but if it is, that seems an unfortunate reflection on society.

Re: Arrest of WannaCry researcher sends chill through security community

#52
post #41
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

He's not personally accused of selling Kronos in the indictment; his unnamed co-conspirator is.

(That co-conspirator is unnamed to us, but most probably is someone clearly known to the DOJ).

The indictment itself is pretty bare. But an indictment isn't a trial; the DOJ will need to prove its charges to a jury with a considerable amount of evidence, and, as Orin Kerr pointed out last night, they have an uphill climb ahead of themselves, because the letter of the law is favorable to people who create and sell banking trojans.

Re: Arrest of WannaCry researcher sends chill through security community

#53
post #20

If your code is used in an exploit and that is now a punishable crime, maybe next the NSA will be in the hot seat since the code that was used in wanacry was their own. Or perhaps Israel for their effort in Stuxnet. I hope he takes it to trial and we find out what is really happening here. Pretty suspicious that this happens years after the fact and only weeks after he helped prevent the further spread of wannaCry. W…

Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?

No.

Re: Arrest of WannaCry researcher sends chill through security community

#54
post #50
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

Re: Arrest of WannaCry researcher sends chill through security community

#55
post #34

Earlier quoted context omitted.

Was Marcus Hutchins arrested for selling malware online?

Yes. https://www.documentcloud.org/documents/3912524-Kronos-Indic...

The indictment doesn't say that Hutchins sold Kronos.

It claims that Hutchins was part of a conspiracy to sell Kronos, and that defendant [redacted] sold Kronos, but doesn't state that Hutchins advertised or sold Kronos.

The only solid claim against Hutchins is that he created Kronos, which doesn't stack up with his tweet asking for a sample of Kronos.

The following claim is that Hutchins and [redacted] updated Kronos.

It's not exactly a smoking gun.

Re: Arrest of WannaCry researcher sends chill through security community

#56
post #21
post #10

Sad to see it confirmed that it's not worth the risk going to America to visit DEFCON. I hope they'll host it in Europe someday.. To see no statement by DEFCON on this whole thing is almost equally sad.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

*potentially.

Re: Arrest of WannaCry researcher sends chill through security community

#57
post #5
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

Maybe Sir Richard Branson could host it on Neckar and stream it live on Virgin.com -- I'm only slightly kidding.

Nowhere near enough space on Necker (my friend just went there) for a massive conference like this. Would be cool, though.

Re: Arrest of WannaCry researcher sends chill through security community

#58
post #50
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…

But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference.

The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator.

And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (although he is one), they're arresting someone whom they believe is a malware creator and distributor.

Re: Arrest of WannaCry researcher sends chill through security community

#59
post #50
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…

> because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field.

While I tend to agree that this is possible, the parent's point was how unrelated this was to WC and to any research occurring in the field. It's strictly a case of "this guy wrote malware and sold it".

> you seem to believe fully this narrative of the FBI with no room for the FBI to view completely innocent actions as something else. No room for the FBI to be in error, no room for the FBI to be wrong.

I'm confused. The parent simply stated he was arrested for that. How does that translate into "Parent believes 100% what the FBI states with no room for the FBI to be wrong"?

Re: Arrest of WannaCry researcher sends chill through security community

#60
post #41
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

I would imagine when he allegedly sold the malware it wasn't named "Kronos". He could have had no idea at the time that the specific campaign was his code, or perhaps had a suspicion and wanted to confirm it.
Post reply on HN