Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

151–160 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#152
post #41
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

> A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code?

If I was greedy and in the security field, with identities (or middlemen) on both sides of the game, I would be terribly tempted to play those identities to support each other. For example when blackhat-me would be selling an exploit, whitehat-me could create buzz by talking about it. Later, when the exploit's market value drops towards zero (ip enforcement is weak on the darknet), whitehat-me could reap the glory of discovering all the details about the exploit, maybe even using some "mistakes" blackhat-me left in the code to facilitate plausible parallel construction.

What are all those ifs having to do with the WannaCry situation? Probably nothing, hopefully nothing. Or maybe hopefully a lot, because it would mean that the FBI did not lock up the wrong guy?

Re: Arrest of WannaCry researcher sends chill through security community

#153
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

Why is there a law against selling malware? Couldn't a comparison be made with regards to firearms? He created the malware but didn't deploy it live

Re: Arrest of WannaCry researcher sends chill through security community

#154
post #68

Perhaps you are being deliberately obtuse I'm not sure. The point the poster was making is that the US happily arrests foreigners who set foot in the US and regardless of your guilt or innocence you get trapped in the US justice system which is essentially a system to tie you up in court and legal processes that you cannot afford so that you accept a plea deal, possibly for something you have not done, because otherw…

I guess I am obtuse. I see this as the FBI believes Marcus created and sold/conspired to sell malware. This is illegal. Now we will see evidence and a trial. The responses are ridiculous. - Muslim last names ?? - US happily arrests foreigners - Plea deal or never see the outside world again - White rich people are favoured - Rich black people have a tough time Seriously?

Reread the question you asked. You asked for elaboration on the feeling of insecurity about visiting US. The response was to the point.

Re: Arrest of WannaCry researcher sends chill through security community

#155

Earlier quoted context omitted.

You're kidding, right? Looks like slam dunk aiding and abetting wire fraud.

I am not kidding, but rather parroting Orin Kerr, an expert on this subject, who does not think this case is a slam dunk. (Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)

Thanks for the cite. Interesting.

Re: Arrest of WannaCry researcher sends chill through security community

#156

Earlier quoted context omitted.

"Type of bug"? Sorry, I don't follow.

Banking trojans. They're saying that the DOJ might convict people for selling trojans in the course of their security work. I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.

I'd say making them is legal and using them on systems you own is completely legal... selling them or using them on machines you are not allowed to access are illegal. Giving them away to someone that sells them or uses them to commit a crime would be a grey area but likely illegal.

Re: Arrest of WannaCry researcher sends chill through security community

#157
post #110

Earlier quoted context omitted.

I think that a Black Hat convention that attracts many federal employees who work in computer security should be especially sensitive to "snatch and grab" operations. The pall which is descending over foreign attendees is a harbinger of either relocation or vastly reduced attendance.

What kind of an arrest isn't a "snatch and grab", in your mind? I think we can all rest assured, unfortunately, that Black Hat isn't going anywhere.

Obviously, the polite thing to do would be to send a letter. "You have been charged with a crime. Please report to the local police station at your earliest convenience."

Re: Arrest of WannaCry researcher sends chill through security community

#158

Why? The arrest of a mall cop who was also doing burglaries wouldn't send a chill through the security guard community, except perhaps for those who were moonlighting as burglars.

If he was arrested for burglarizing a mall he worked in, though, and you didn't have any evidence other than the claim of the arresting authorities that he wasn't merely present in the mall (as security guards are wont to be) where a burglary had taken place, you might be somewhat concerned.

Re: Arrest of WannaCry researcher sends chill through security community

#159

Earlier quoted context omitted.

The parent post thread is about why researchers were afraid as a result of the arrest. While it might unfold and get a not guilty, in the mean time he's in jail. If you were a malware researcher with good intentions, you might rightly think it's a mistake and one that could get you in the same kind of trouble.

My point isn't that I have a huge of trust and goodwill in the criminal justice system, but rather that almost nobody in the security community does the stuff that this person is accused of doing. Do you build banking trojans and then arrange for them to be sold to anonymous strangers on Darknet forums? If not: what does this case have to do with your security work?

It seems to me that this is kind of a litmus situation - this case reveals what you think of the DOJ. If you think that they somewhat routinely frame people that they are "after", then you look at the fact of the accusation and see this case as more proof that security researchers should be cautious (and maybe avoid entering the US).

On the other hand, if you think that the DOJ, while subject to making mistakes, does not often knowingly and deliberately falsely accuse people, then you look at the alleged behavior, and realize that it is well outside the bounds of whitehat behavior.

Re: Arrest of WannaCry researcher sends chill through security community

#160
post #130

Earlier quoted context omitted.

That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).

> Another is that he might plead guilty and we'll never know whether he was guilty or innocent Yes, that might happen. Taking that position to its logical conclusion, nobody should be indicted for anything. There are serious problems with the US justice system. As far as I can tell, there is nothing at face value that's unreasonable about this indictment.

I'm never entirely sure what people mean by "taking something to its logical conclusion", but if you mean something like "giving that consideration the greatest possible weight" I think where you end up is "end all reductions in sentence for pleading guilty", not "nobody should be indicted for anything".
Post reply on HN