Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

71–80 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#71

As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…

I don't think that's what these researchers are saying. I think they are saying more along the lines of: "Hutchins has shown that he is a security researcher through his work on wannacry. As a security researcher, he probably has researched other problems as well, possibly including Kronos. The fact that he was arrested with little to no evidence could be showing that the DOJ is willing to arrest people who have copies of virus source code on their computers, even if they only accessed it for research purposes. In fact he may have updated Kronos code or written some part of Kronos as part of research to validate a hypothesis or test a theory. Such actions are ordinary actions for researchers, so this puts at risk most computer security research across the world."

Re: Arrest of WannaCry researcher sends chill through security community

#72
post #65
post #58

Earlier quoted context omitted.

But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

Correct, I don't think the FBI is making up evidence about Marcus and they actually believe he's the creator of Kronos. Sounds crazy, I know.

Re: Arrest of WannaCry researcher sends chill through security community

#73
post #58
post #50

Earlier quoted context omitted.

>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…

But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…

The implication is that the FBI may believe him to be the creator of Kronos based on something he did as part of security research, eg. gaining access to a control panel or taking over a CnC server.

Re: Arrest of WannaCry researcher sends chill through security community

#74
post #41
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

If you wrote some malware and people were passing around copies of it, wouldn't you want to see the source of what they were passing around?

Re: Arrest of WannaCry researcher sends chill through security community

#75
post #47

Earlier quoted context omitted.

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

If I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank?

In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to require direct knowledge of malicious intent of the software in the sale.

Re: Arrest of WannaCry researcher sends chill through security community

#76
post #69
post #54

Earlier quoted context omitted.

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

It depends how you define “research”. - Weev’s harvesting and publication of iPad owners’ email addresses was far from benevolent, but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. As you know, it’s not that far from what white hats sometimes do, in terms of probing public websites - with the obvious exception that they’d usually responsibly disclose the vulnerability to the site owne…

I follow what you're saying, but look at these cases: Aurenheimer was confronted with IRC logs in which he discussed selling the information he got from the website, and Barrett Brown was accused of actively assisting the people who breached Stratfor.

What ever you think of the actual prosecutions here, neither of those are cases of security research being mistaken for something else. The most you can say, for instance, about Brown is that he is not as closely connected to an extraordinarily serious crime as the DOJ believed he was.

Re: Arrest of WannaCry researcher sends chill through security community

#77
post #75
post #47

Earlier quoted context omitted.

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

If I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank? In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to re…

If you know the person licensing it from you is going to use it to steal financial information, and the clear purpose of the tool you've built is to steal financial information, then I would say you should definitely make sure you have a criminal defense lawyer you trust and can afford.

Re: Arrest of WannaCry researcher sends chill through security community

#78
post #65
post #58

Earlier quoted context omitted.

But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty.

“Innocent until proven guilty” is a legal standard applied where “guilty” means having one’s liberty taken away. And in that context it’s a perfectly appropriate standard. But as mere spectators, where the harm caused by mistakenly believing he’s guilty is minimal, I think we should feel free to simply believe in the most likely possibility (aka preponderance of the evidence). You may disagree on that point, and that’s your right. However, if we agree to apply that standard, I don’t think it’s reasonable to believe that the FBI’s allegations being false is actually more likely than the alternative.

> I never take the government word for anything, and generally assume the government is lying at all times. History supports my position.

[citation needed]

Re: Arrest of WannaCry researcher sends chill through security community

#79
post #54
post #50

Earlier quoted context omitted.

>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

Actual prosecutions of malware creators are exceedingly rare to almost none existent. As such I believe there are extreme pressure on law enforcement to "Make an example" of some malware creator, or anyone they can even remotely connect to the creation of malware.

This pressure I believe will lead them to over reach on CFAA like they have in the past in other "hacking" cases

https://www.wired.com/2015/10/cfaa-computer-fraud-abuse-act-...

So while I can not point to an example right now, that is simply because there is a general lack of case law in the field to begin with, nor does that support a position that the FBI is correct in this case, or would never go after a innocent security research, their history defies that completely.

Re: Arrest of WannaCry researcher sends chill through security community

#80
post #37
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…

>The court case should be public, so we'll be able to judge the evidence ourselves.

Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.

Post reply on HN