As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…
Arrest of WannaCry researcher sends chill through security community
71–80 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#72Earlier quoted context omitted.
But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…
The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…
Re: Arrest of WannaCry researcher sends chill through security community
#73Earlier quoted context omitted.
>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…
But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…
Re: Arrest of WannaCry researcher sends chill through security community
#74I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...
Re: Arrest of WannaCry researcher sends chill through security community
#75Earlier quoted context omitted.
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to require direct knowledge of malicious intent of the software in the sale.
Re: Arrest of WannaCry researcher sends chill through security community
#76Earlier quoted context omitted.
What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?
It depends how you define “research”. - Weev’s harvesting and publication of iPad owners’ email addresses was far from benevolent, but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. As you know, it’s not that far from what white hats sometimes do, in terms of probing public websites - with the obvious exception that they’d usually responsibly disclose the vulnerability to the site owne…
What ever you think of the actual prosecutions here, neither of those are cases of security research being mistaken for something else. The most you can say, for instance, about Brown is that he is not as closely connected to an extraordinarily serious crime as the DOJ believed he was.
Re: Arrest of WannaCry researcher sends chill through security community
#77Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
If I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank? In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to re…
Re: Arrest of WannaCry researcher sends chill through security community
#78Earlier quoted context omitted.
But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…
The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…
“Innocent until proven guilty” is a legal standard applied where “guilty” means having one’s liberty taken away. And in that context it’s a perfectly appropriate standard. But as mere spectators, where the harm caused by mistakenly believing he’s guilty is minimal, I think we should feel free to simply believe in the most likely possibility (aka preponderance of the evidence). You may disagree on that point, and that’s your right. However, if we agree to apply that standard, I don’t think it’s reasonable to believe that the FBI’s allegations being false is actually more likely than the alternative.
> I never take the government word for anything, and generally assume the government is lying at all times. History supports my position.
[citation needed]
Re: Arrest of WannaCry researcher sends chill through security community
#79Earlier quoted context omitted.
>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…
What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?
This pressure I believe will lead them to over reach on CFAA like they have in the past in other "hacking" cases
https://www.wired.com/2015/10/cfaa-computer-fraud-abuse-act-...
So while I can not point to an example right now, that is simply because there is a general lack of case law in the field to begin with, nor does that support a position that the FBI is correct in this case, or would never go after a innocent security research, their history defies that completely.
Re: Arrest of WannaCry researcher sends chill through security community
#80I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…
Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.