Earlier quoted context omitted.
I would imagine when he allegedly sold the malware it wasn't named "Kronos". He could have had no idea at the time that the specific campaign was his code, or perhaps had a suspicion and wanted to confirm it.
There's a video demonstration of the tool we're talking about. Nobody who has watched it is going to for a moment entertain the idea that the author of this tool didn't understand its intention. Its purpose is extracting financial information from botnets.
Arrest of WannaCry researcher sends chill through security community
131–140 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#132Earlier quoted context omitted.
I doubt the type of bug will matter unless people need license to sell trojans by law.
"Type of bug"? Sorry, I don't follow.
I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.
Re: Arrest of WannaCry researcher sends chill through security community
#133Earlier quoted context omitted.
If I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank? In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to re…
If you know the person licensing it from you is going to use it to steal financial information, and the clear purpose of the tool you've built is to steal financial information, then I would say you should definitely make sure you have a criminal defense lawyer you trust and can afford.
If you haven't already, listen to this podcast about Doug Williams and polygraphs: https://www.thisamericanlife.org/radio-archives/episode/618/...
There's a lot of parallels and how issues of intent can get very grey.
Re: Arrest of WannaCry researcher sends chill through security community
#134Earlier quoted context omitted.
If you know the person licensing it from you is going to use it to steal financial information, and the clear purpose of the tool you've built is to steal financial information, then I would say you should definitely make sure you have a criminal defense lawyer you trust and can afford.
I don't think anyone would disagree with what you just said, but given the way prosecutors deal with "intent" sometimes, I think it would be easy for them to cross a line. If you haven't already, listen to this podcast about Doug Williams and polygraphs: https://www.thisamericanlife.org/radio-archives/episode/618/... There's a lot of parallels and how issues of intent can get very grey.
Re: Arrest of WannaCry researcher sends chill through security community
#135Earlier quoted context omitted.
A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…
Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.
Re: Arrest of WannaCry researcher sends chill through security community
#136Earlier quoted context omitted.
> But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. Is this just for alleged computer crimes, or would you apply that to all alleged crimes? For example, suppose I run a fraudulent mail order business targeting people in, say, France, and this is a crime in France. Would you argue that if I vi…
I think that a Black Hat convention that attracts many federal employees who work in computer security should be especially sensitive to "snatch and grab" operations. The pall which is descending over foreign attendees is a harbinger of either relocation or vastly reduced attendance.
I think we can all rest assured, unfortunately, that Black Hat isn't going anywhere.
Re: Arrest of WannaCry researcher sends chill through security community
#137Earlier quoted context omitted.
If that is the case, it would not be remarkable. Prosecutors have a responsibility to only pursue cases that are likely to result in conviction. If extradition was considered impossible, then there would not be much point in pursing an indictment.
I honestly assume that there's a "list of foreigners we'd like to prosecute" that the US gov't checks visa applications against.
USA probably gets all the flight reservation data and take it from there. If you're a Russian criminal mastermind dying to spend some of that cash in Greek islands, they'll find out. (Better stay in Russia and pay Igor @ Russian Gov his share :) )
Re: Arrest of WannaCry researcher sends chill through security community
#138Earlier quoted context omitted.
Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.
You're kidding, right? Looks like slam dunk aiding and abetting wire fraud.
(Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)
Re: Arrest of WannaCry researcher sends chill through security community
#139Re: Arrest of WannaCry researcher sends chill through security community
#140Earlier quoted context omitted.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…