Earlier quoted context omitted.
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
Arrest of WannaCry researcher sends chill through security community
91–100 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#92Earlier quoted context omitted.
This isn't "forum-shopping". Not every crime is going to get someone extradited, which is a huge hassle, but if the person accused is going to be entering the country of course you grab him.
Yeah everyone is just emotional and not using their brains. This is clearly the easiest route to take for the fbi. I appreciate our government being resourceful. However, if it turns out that the allegations are false and that this is harassment I will grab my pitchfork as well.
Re: Arrest of WannaCry researcher sends chill through security community
#93Earlier quoted context omitted.
What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?
"can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?" Randal Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz
Re: Arrest of WannaCry researcher sends chill through security community
#94Earlier quoted context omitted.
It depends how you define “research”. - Weev’s harvesting and publication of iPad owners’ email addresses was far from benevolent, but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. As you know, it’s not that far from what white hats sometimes do, in terms of probing public websites - with the obvious exception that they’d usually responsibly disclose the vulnerability to the site owne…
As to your first example, there seems to be this pervasive idea in tech culture that something shouldn't be a serious crime or tort because it is so easy to do. I see the argument very often in cases of unauthorized access and copyright infringement. Murder is also rather easy, and we execute people for it.
Re: Arrest of WannaCry researcher sends chill through security community
#95As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…
I don't think that's what these researchers are saying. I think they are saying more along the lines of: "Hutchins has shown that he is a security researcher through his work on wannacry. As a security researcher, he probably has researched other problems as well, possibly including Kronos. The fact that he was arrested with little to no evidence could be showing that the DOJ is willing to arrest people who have copi…
Do you really think they are loosely tying Marcus to Kronos with little to no evidence? Why go through all the trouble? Just because they haven't shared evidence in a sealed case doesn't mean they have no evidence. It's safe to assume there is evidence and it'll be interesting to see what it is.
Re: Arrest of WannaCry researcher sends chill through security community
#96Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
Yes, that's what they're saying. Consider the source.
Re: Arrest of WannaCry researcher sends chill through security community
#97Earlier quoted context omitted.
As to your first example, there seems to be this pervasive idea in tech culture that something shouldn't be a serious crime or tort because it is so easy to do. I see the argument very often in cases of unauthorized access and copyright infringement. Murder is also rather easy, and we execute people for it.
That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.
It's certainly part of what he said:
>but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter.
The difficulty of carrying out an action is completely irrelevant to its legality.
Re: Arrest of WannaCry researcher sends chill through security community
#98As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…
I don't think that's what these researchers are saying. I think they are saying more along the lines of: "Hutchins has shown that he is a security researcher through his work on wannacry. As a security researcher, he probably has researched other problems as well, possibly including Kronos. The fact that he was arrested with little to no evidence could be showing that the DOJ is willing to arrest people who have copi…
How do you know what evidence does or doesn't exist? The case hasn't even been brought to trial yet.
Re: Arrest of WannaCry researcher sends chill through security community
#99Earlier quoted context omitted.
That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.
> That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer. It's certainly part of what he said: > but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. The difficulty of carrying out an action is completely irrelevant to…
Re: Arrest of WannaCry researcher sends chill through security community
#100Earlier quoted context omitted.
I might be misunderstanding your point but I don't understand what they did that was so dishonorable? I thought that this guy produced malware
We don't know whether he did or not. But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. And there very well may be evidence, especially if the timing is related to something new obtained from the Alpha Bay takedown and it happening when he happened to visit the US for DEFCON was a coincidence.…
Is this just for alleged computer crimes, or would you apply that to all alleged crimes?
For example, suppose I run a fraudulent mail order business targeting people in, say, France, and this is a crime in France. Would you argue that if I visit France, and the French authorities want to arrest me and bring me to trial, they should let me go home and use extradition to try to force me back, rather than arrest me while I am in France?