Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

121–130 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#121
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.

Re: Arrest of WannaCry researcher sends chill through security community

#122

Is it me or the DOJ so the flight manifest and then went to a grand jury to indict? He did what he did in 2014-2015 and the charges were filed in July 2017, a couple of weeks before Defcon...

AlphaBay takedown. I suspect that they found something there.

If that's the case, this is a pretty fast turnaround, actually.

And, given the tiny amounts of money I have seen being quoted (Kronos banking trojan sold for $3000? really?), they probably arrested him with the intention to get him to roll over on somebody much bigger.

The question is whether they've shot themselves in the foot. Did the FBI intend for this to be a quiet nab, but his celebrity from WannaCry hosed them up? Given how quickly they seem to be moving, it's certainly possible.

Re: Arrest of WannaCry researcher sends chill through security community

#123
post #65
post #58

Earlier quoted context omitted.

But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

> I never take the government word for anything, and generally assume the government is lying at all times. History supports my position.

Do you habitually eat food that has been left out for longer than government guidelines allow because you generally assume the government is lying at all times?

Do you increase your speed when you see a sign that says REDUCE SPEED, SHARP TURNS AHEAD because you generally assume the government is lying at all times?

Re: Arrest of WannaCry researcher sends chill through security community

#124
post #52
post #41

Earlier quoted context omitted.

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

He's not personally accused of selling Kronos in the indictment; his unnamed co-conspirator is. (That co-conspirator is unnamed to us , but most probably is someone clearly known to the DOJ). The indictment itself is pretty bare. But an indictment isn't a trial; the DOJ will need to prove its charges to a jury with a considerable amount of evidence, and, as Orin Kerr pointed out last night, they have an uphill climb…

> most probably is someone clearly known to the DOJ

not probably. the first line of the indictment is "Defendant [redacted] used the online aliases [redacted].

https://www.documentcloud.org/documents/3912549-MalwareTechB...

Re: Arrest of WannaCry researcher sends chill through security community

#125
post #88

Earlier quoted context omitted.

> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. Is indicting people for crimes they are alleged to have committed consistent with your position? Because that's all that's happened so far. The FBI asserts that he created malware. He denies it. An indictment and a trial will figure out which of them is lying.

That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).

Which of the two outcomes do you prefer to happen:

1. True malware creator and seller is sent to prison.

2. True malware creator and seller is not sent to prison.

Whether he pleads guilty or not has nothing to do with him being a security researcher. I'd much rather have more false positives than false negatives. You, and the rest of Europe, would too.

Re: Arrest of WannaCry researcher sends chill through security community

#126

Earlier quoted context omitted.

The parent post thread is about why researchers were afraid as a result of the arrest. While it might unfold and get a not guilty, in the mean time he's in jail. If you were a malware researcher with good intentions, you might rightly think it's a mistake and one that could get you in the same kind of trouble.

My point isn't that I have a huge of trust and goodwill in the criminal justice system, but rather that almost nobody in the security community does the stuff that this person is accused of doing. Do you build banking trojans and then arrange for them to be sold to anonymous strangers on Darknet forums? If not: what does this case have to do with your security work?

I doubt the type of bug will matter unless people need license to sell trojans by law.

Re: Arrest of WannaCry researcher sends chill through security community

#128

Earlier quoted context omitted.

My point isn't that I have a huge of trust and goodwill in the criminal justice system, but rather that almost nobody in the security community does the stuff that this person is accused of doing. Do you build banking trojans and then arrange for them to be sold to anonymous strangers on Darknet forums? If not: what does this case have to do with your security work?

I doubt the type of bug will matter unless people need license to sell trojans by law.

"Type of bug"? Sorry, I don't follow.

Re: Arrest of WannaCry researcher sends chill through security community

#129
post #36

Earlier quoted context omitted.

You're commenting on an article about how the FBI arrested someone for creating malware. If you haven't been creating malware, then I don't see how this article has anything to do with the issues you face as someone with a middle-eastern last who uses privacy tools like Tor. Hutchins wasn't targeted because of CBP's stance on things it associates with terrorism. He was targeted because the FBI believes he authored ma…

Believe it or not, it's possible to be suspected or even accused of something you didn't actually do, whether through a misunderstanding or otherwise. And factors such as ethnicity and personal associations can influence the chance of this occurring.

Hutchens is a British man, not someone of an ethnicity that makes people wary. The arrest of Hutchens shouldn't have any relevance whatsoever to worries about being flagged for ethnicity.

Re: Arrest of WannaCry researcher sends chill through security community

#130
post #88

Earlier quoted context omitted.

> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. Is indicting people for crimes they are alleged to have committed consistent with your position? Because that's all that's happened so far. The FBI asserts that he created malware. He denies it. An indictment and a trial will figure out which of them is lying.

That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).

> Another is that he might plead guilty and we'll never know whether he was guilty or innocent

Yes, that might happen. Taking that position to its logical conclusion, nobody should be indicted for anything.

There are serious problems with the US justice system. As far as I can tell, there is nothing at face value that's unreasonable about this indictment.

Post reply on HN