Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

91–100 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#91
post #47

Earlier quoted context omitted.

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

Yes, that's what they're saying. Consider the source.

Re: Arrest of WannaCry researcher sends chill through security community

#92

Earlier quoted context omitted.

This isn't "forum-shopping". Not every crime is going to get someone extradited, which is a huge hassle, but if the person accused is going to be entering the country of course you grab him.

Yeah everyone is just emotional and not using their brains. This is clearly the easiest route to take for the fbi. I appreciate our government being resourceful. However, if it turns out that the allegations are false and that this is harassment I will grab my pitchfork as well.

Agreed. I will be really upset if this is all just a colossal f-up on the part of the feds.

Re: Arrest of WannaCry researcher sends chill through security community

#93
post #83
post #54

Earlier quoted context omitted.

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

"can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?" Randal Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz

Yeah, I think you'll find when you dig into the details that that case is not a great example for you.

Re: Arrest of WannaCry researcher sends chill through security community

#94
post #69

Earlier quoted context omitted.

It depends how you define “research”. - Weev’s harvesting and publication of iPad owners’ email addresses was far from benevolent, but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. As you know, it’s not that far from what white hats sometimes do, in terms of probing public websites - with the obvious exception that they’d usually responsibly disclose the vulnerability to the site owne…

As to your first example, there seems to be this pervasive idea in tech culture that something shouldn't be a serious crime or tort because it is so easy to do. I see the argument very often in cases of unauthorized access and copyright infringement. Murder is also rather easy, and we execute people for it.

That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.

Re: Arrest of WannaCry researcher sends chill through security community

#95
post #71

As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…

I don't think that's what these researchers are saying. I think they are saying more along the lines of: "Hutchins has shown that he is a security researcher through his work on wannacry. As a security researcher, he probably has researched other problems as well, possibly including Kronos. The fact that he was arrested with little to no evidence could be showing that the DOJ is willing to arrest people who have copi…

>> The fact that he was arrested with little to no evidence...

Do you really think they are loosely tying Marcus to Kronos with little to no evidence? Why go through all the trouble? Just because they haven't shared evidence in a sealed case doesn't mean they have no evidence. It's safe to assume there is evidence and it'll be interesting to see what it is.

Re: Arrest of WannaCry researcher sends chill through security community

#96
post #91
post #47

Earlier quoted context omitted.

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

Yes, that's what they're saying. Consider the source.

I'm not convicting him, and if you put a gun to my head and forced me to render a verdict based on what's public now, I'd say "not guilty". What do you want from me? Cases like this unfold over time. We don't get to know everything we want to know the moment we want to know it.

Re: Arrest of WannaCry researcher sends chill through security community

#97
post #94

Earlier quoted context omitted.

As to your first example, there seems to be this pervasive idea in tech culture that something shouldn't be a serious crime or tort because it is so easy to do. I see the argument very often in cases of unauthorized access and copyright infringement. Murder is also rather easy, and we execute people for it.

That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.

>That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.

It's certainly part of what he said:

>but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter.

The difficulty of carrying out an action is completely irrelevant to its legality.

Re: Arrest of WannaCry researcher sends chill through security community

#98
post #71

As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…

I don't think that's what these researchers are saying. I think they are saying more along the lines of: "Hutchins has shown that he is a security researcher through his work on wannacry. As a security researcher, he probably has researched other problems as well, possibly including Kronos. The fact that he was arrested with little to no evidence could be showing that the DOJ is willing to arrest people who have copi…

> The fact that he was arrested with little to no evidence

How do you know what evidence does or doesn't exist? The case hasn't even been brought to trial yet.

Re: Arrest of WannaCry researcher sends chill through security community

#99
post #94

Earlier quoted context omitted.

That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.

> That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer. It's certainly part of what he said: > but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. The difficulty of carrying out an action is completely irrelevant to…

I agree with you that the "hardcoreness" of what Aurenheimer did is a red herring.

Re: Arrest of WannaCry researcher sends chill through security community

#100
post #64
post #30

Earlier quoted context omitted.

I might be misunderstanding your point but I don't understand what they did that was so dishonorable? I thought that this guy produced malware

We don't know whether he did or not. But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. And there very well may be evidence, especially if the timing is related to something new obtained from the Alpha Bay takedown and it happening when he happened to visit the US for DEFCON was a coincidence.…

> But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest.

Is this just for alleged computer crimes, or would you apply that to all alleged crimes?

For example, suppose I run a fraudulent mail order business targeting people in, say, France, and this is a crime in France. Would you argue that if I visit France, and the French authorities want to arrest me and bring me to trial, they should let me go home and use extradition to try to force me back, rather than arrest me while I am in France?

Post reply on HN