Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

161–170 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#161
The article is light on details and leave an important question's answer very vague: Did Hutchins sell his product in an underground market to an unknown identity? How much was the compensation?

These questions answered would make the case a "clear-cut".

And there is a big difference between selling your code in an underground market for $250k* with bitcoin, and open sourcing it for free.

*I come up with this number as an example.

Re: Arrest of WannaCry researcher sends chill through security community

#162
post #94

Earlier quoted context omitted.

That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer.

> That's not what he's saying. He's saying that independent of how easy it is to do, it's also something that professional security people do routinely. And he's right. But that's not the basis of the charge against Aurenheimer. It's certainly part of what he said: > but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. The difficulty of carrying out an action is completely irrelevant to…

Even if he did attempt to sell the data, is it illegal to sell data that is freely available on the internet (honest question, I couldnt find a solid answer via googling)? It might be against TOS.

Re: Arrest of WannaCry researcher sends chill through security community

#163

Earlier quoted context omitted.

My point isn't that I have a huge of trust and goodwill in the criminal justice system, but rather that almost nobody in the security community does the stuff that this person is accused of doing. Do you build banking trojans and then arrange for them to be sold to anonymous strangers on Darknet forums? If not: what does this case have to do with your security work?

It seems to me that this is kind of a litmus situation - this case reveals what you think of the DOJ. If you think that they somewhat routinely frame people that they are "after", then you look at the fact of the accusation and see this case as more proof that security researchers should be cautious (and maybe avoid entering the US). On the other hand, if you think that the DOJ, while subject to making mistakes, does…

I think there's very little evidence that the DOJ routinely frames accused computer criminals --- or even that they routinely make mistakes with them. The reality is that so few computer crimes are prosecuted that the ones that are are usually smoking-gun cases.

I can't speak to any other aspect of federal prosecution. My thoughts about computer crime prosecution definitely can't be extrapolated to my thoughts about criminal justice in general.

Re: Arrest of WannaCry researcher sends chill through security community

#164
post #153
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

Why is there a law against selling malware? Couldn't a comparison be made with regards to firearms? He created the malware but didn't deploy it live

Not a good anology. What's a legitimate use for banking malware? A more apt analogy would be selling an IED.

Re: Arrest of WannaCry researcher sends chill through security community

#165
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

[deleted]

Re: Arrest of WannaCry researcher sends chill through security community

#166
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

From my limited perspective, the U.S. is continuing to transition more fully to "rubber hose" policing, for lack of a better term.

If they decide you are a problem for any reason or decide to put you in their sites, perhaps for their own political agenda, you will face an overwhelming range of charges and immediate legal expenses.

The goal isn't truth; the goal is to break you and so further their agenda.

I'm not saying there isn't legitimate law enforcement occurring within the mix.

But, in terms of the overall picture as opposed to court etiquette itself, "benefit of the doubt" seems to have long since gone out the window.

Now imagine being a foreigner, away from family and local support networks, and not knowing whether you've landed on some very political person's list (and prosecutors in the U.S. are very political creatures).

Imagine you work in an area engendering much controversy, such as computer systems security.

And finally, take it a step further, even sitting home or traveling in e.g. Europe: Just how far and pervasive are the FBI et al. willing to reach with politically aided extradition requests?

Political forces in the U.S. want to "stop" "cybercrime" by physically insisting that people they don't like "stop" doing those things. Not a technical solution. Not improving systems and systems management. Nope, get out the rubber hose.

And wield it based upon political calculation, more so than actual, (legally) substantiated fact.

Re: Arrest of WannaCry researcher sends chill through security community

#167
post #20

If your code is used in an exploit and that is now a punishable crime, maybe next the NSA will be in the hot seat since the code that was used in wanacry was their own. Or perhaps Israel for their effort in Stuxnet. I hope he takes it to trial and we find out what is really happening here. Pretty suspicious that this happens years after the fact and only weeks after he helped prevent the further spread of wannaCry. W…

Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?

lets take away the feelings by saying...

if someone were to deliberately sell a pair of shoes to someone that they new would attempt to j-walk with their shoes, do you think they should be partially liable for the j-walking?

> no.

Re: Arrest of WannaCry researcher sends chill through security community

#168
post #78
post #65

Earlier quoted context omitted.

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. “Innocent until proven guilty” is a legal standard applied where “guilty” means having one’s liberty taken away. And in that context it’s a perfectly appropriate standard. But as mere spectators, where the harm caused by mistakenly believing he’s guilty is minimal, I think we shou…

So you're basically saying that if the police took him there must be a good reason for that to happen therefore guilty as charged.

You have a peculiar interpretation of justice, one that makes you pretty much like those that liked to burn people on fire pyres on the basis of allegations made by socially relevant people.

Re: Arrest of WannaCry researcher sends chill through security community

#169
post #75
post #47

Earlier quoted context omitted.

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

If I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank? In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to re…

honest question: if your code is open source, why would someone pay you for further research? why would you charge for that?

Re: Arrest of WannaCry researcher sends chill through security community

#170
post #140

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

Again, no contradiction here. There is a fear that a white hat is being accused of black hat behavior. Not a claim. A fear. And a reality that a person (maybe white hat, maybe black hat, we don't know) is being accused of black hat behavior. Nothing surprising here. He may, or may not, be a black hat. The fear of unjust accusation is still valid. We will have to see if the DOJ will share the evidence, and what that e…

>The fear of unjust accusation is still valid.

Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.

Post reply on HN