Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

81–90 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#81
I feel like no one here remembers when Dmitry Sklyarov was arrested under similar circumstances. The US government has no obligation to seek out every potential arrestee no matter where they are in the world for every single crime that the US has laws for. But if the target of an investigation (whether they know it or not) sets foot in the US, then we shouldn't be surprised when they are arrested. And this is just another case with Def Con (so no, it's probably not moving out of the US, it didn't 15 years ago), I'm quite certain that these sorts of things happen frequently for other crimes of (relatively) low priority that are just outside our primary focus on this forum (technology).

And is the US any worse for this than other nations? Probably not. They just get more publicity when it happens. But every nation that has a legal system will do the same thing. If the Russians or the Brits or the Germans or the Swiss decide that Jtsummers is a suspect in a crime, and I visit and they realize it, I shouldn't be surprised to find myself arrested and barred from leaving the country.

[0] https://www.cnet.com/g00/news/russian-crypto-expert-arrested... - may not be the best article, it's the first one that came up on Google for me.

Re: Arrest of WannaCry researcher sends chill through security community

#83
post #54
post #50

Earlier quoted context omitted.

>>Why is this "sending a chill through the security community"? because a lot of legitimate security research when viewed through the myopic and cynical lens of a Federal Agent can be seen as illegal, this is an ongoing and ever present fear for people in the field. The FBI claims he is a malware creator and arrested him for it, you seem to believe fully this narrative of the FBI with no room for the FBI to view comp…

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

"can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?"

Randal Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz

Re: Arrest of WannaCry researcher sends chill through security community

#84
post #47

Earlier quoted context omitted.

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished.

>Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

You say that as though you are contradicting NateJay.

But the fear NateJay is highlighting is exactly that a white hat is being accused. And that (whether ultimately borne out in this case, or not) this kind of thing could happen to people who are conducting innocent security research.

Re: Arrest of WannaCry researcher sends chill through security community

#85
post #20

If your code is used in an exploit and that is now a punishable crime, maybe next the NSA will be in the hot seat since the code that was used in wanacry was their own. Or perhaps Israel for their effort in Stuxnet. I hope he takes it to trial and we find out what is really happening here. Pretty suspicious that this happens years after the fact and only weeks after he helped prevent the further spread of wannaCry. W…

Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?

Firearms are legal. If you create an illegal firearm (banking trojan), and did the same, yes - you'd be partially liable.

Re: Arrest of WannaCry researcher sends chill through security community

#86
post #72
post #65

Earlier quoted context omitted.

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

Correct, I don't think the FBI is making up evidence about Marcus and they actually believe he's the creator of Kronos. Sounds crazy, I know.

>> Sounds crazy, I know.

At least you admit that believing the FBI is crazy, maybe there is hope for you.

Re: Arrest of WannaCry researcher sends chill through security community

#87
post #10

Sad to see it confirmed that it's not worth the risk going to America to visit DEFCON. I hope they'll host it in Europe someday.. To see no statement by DEFCON on this whole thing is almost equally sad.

There already is a security conference in Europe just as large run by the chaos computer club in Germany.

Re: Arrest of WannaCry researcher sends chill through security community

#88
post #65
post #58

Earlier quoted context omitted.

But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty.

Is indicting people for crimes they are alleged to have committed consistent with your position? Because that's all that's happened so far.

The FBI asserts that he created malware. He denies it. An indictment and a trial will figure out which of them is lying.

Re: Arrest of WannaCry researcher sends chill through security community

#89
post #6

Earlier quoted context omitted.

Extradition needn't have come into it. The US authorities could have sent their evidence to the UK police to deal with (assuming the UK police didn't have it to start with). If we want justice to be seen to be done, we shouldn't encourage "forum-shopping" by law-enforcement, letting them bring prosecutions in a country where the defendent will be artificially disadvantaged.

This isn't "forum-shopping". Not every crime is going to get someone extradited, which is a huge hassle, but if the person accused is going to be entering the country of course you grab him.

Yeah everyone is just emotional and not using their brains. This is clearly the easiest route to take for the fbi. I appreciate our government being resourceful. However, if it turns out that the allegations are false and that this is harassment I will grab my pitchfork as well.

Re: Arrest of WannaCry researcher sends chill through security community

#90
post #69
post #54

Earlier quoted context omitted.

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

It depends how you define “research”. - Weev’s harvesting and publication of iPad owners’ email addresses was far from benevolent, but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. As you know, it’s not that far from what white hats sometimes do, in terms of probing public websites - with the obvious exception that they’d usually responsibly disclose the vulnerability to the site owne…

As to your first example, there seems to be this pervasive idea in tech culture that something shouldn't be a serious crime or tort because it is so easy to do. I see the argument very often in cases of unauthorized access and copyright infringement.

Murder is also rather easy, and we execute people for it.

Post reply on HN