Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

171–180 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#171

Earlier quoted context omitted.

That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).

Which of the two outcomes do you prefer to happen: 1. True malware creator and seller is sent to prison. 2. True malware creator and seller is not sent to prison. Whether he pleads guilty or not has nothing to do with him being a security researcher. I'd much rather have more false positives than false negatives. You, and the rest of Europe, would too.

Until it's your sorry ass that gets booted to the slammer.

Unless of course you're so mediocre that you'll never ever risk doing anything even remotely significant; in which case, whatever.

Re: Arrest of WannaCry researcher sends chill through security community

#172
post #106

Earlier quoted context omitted.

So I take it you're not a fan of Vegas?

I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.

Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.

Re: Arrest of WannaCry researcher sends chill through security community

#173
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

The "chill" comes from legal activities potentially getting you detained and brought up on charges. That's a real cost, even assuming a perfect justice system that can tell they made a mistake.

For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops couldn't tell the difference between you wanting to help drug addicts and being a drug dealer, and arrested you based on frequently being in the wrong part of town and showing an interest in drug literature, then it would send a clear message to go no where near these people in need. And that would be a shame.

Re: Arrest of WannaCry researcher sends chill through security community

#174

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

The "chill" comes from legal activities potentially getting you detained and brought up on charges. That's a real cost, even assuming a perfect justice system that can tell they made a mistake. For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops could…

>the cops couldn't tell the difference

is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?

Re: Arrest of WannaCry researcher sends chill through security community

#175
post #106

Earlier quoted context omitted.

So I take it you're not a fan of Vegas?

I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.

I think we should move it to Cuba.

Re: Arrest of WannaCry researcher sends chill through security community

#176
post #24
post #9

Earlier quoted context omitted.

I was just at this past DEF CON. The good majority of attendees were from the United States. It doesn't make sense to move it to the Caribbean. That would cause attendance to drop by a lot, and some other organization would just start another conference in the US, and most people would go to that one.

If our justice system behaves dishonorably, then the world's information security industry should certainly abandon the U.S. We can have our solo conferences, but we can't ask foreigners to risk incarceration for our convenience. The Bahamas might also be a reasonable choice, as they only declared independence from Britain in 1973.

Except BlackHat happens annually on multiple continents. Sure, DEF CON doesn't, but there are comparable conferences elsewhere (CCC for example).

Re: Arrest of WannaCry researcher sends chill through security community

#177
The lines between security researcher and malware creator is becoming increasingly murky.

When is it research, pretending to be a bad egg to get more info or actually being one?

As long as its was fun and games no one really minded, but now malware is used to hold schools and hospitals to ransom. Even criminals don't go after schools and hospitals. Extreme greed and criminality can't be minimized away as 'hacking'.

The infosec community likes to be edgy but they need to clean up their act and not give airtime and cover to criminals, and its difficult to believe they don't know who these are.

Re: Arrest of WannaCry researcher sends chill through security community

#178
post #82

He's not indicted for doing security research, he's indicted for stealing people's bank accounts. The indictment may end up being bullshit, but it has not been for any of his white-hat, or grey-hat activities.

I don't defend him in any way but he is not indicted for stealing people's bank account just for writing software that does that, please don't spread disinformation about this.

Re: Arrest of WannaCry researcher sends chill through security community

#179

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

The "chill" comes from legal activities potentially getting you detained and brought up on charges. That's a real cost, even assuming a perfect justice system that can tell they made a mistake. For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops could…

> >the cops couldn't tell the difference

> is there any indication that's the case here? the FBI isn't a bunch of complete incompetents.

if they arrested someone selling the malware (which they did), and to get free that person say they can deliver the author (which they did), but instead point to any random security researcher he found working on that malware (we dont know). now, this plus the person whitehat research, the circle is closed and it would take one lifetime and imense legal fees to prove otherwise.

Re: Arrest of WannaCry researcher sends chill through security community

#180
post #76
post #69

Earlier quoted context omitted.

It depends how you define “research”. - Weev’s harvesting and publication of iPad owners’ email addresses was far from benevolent, but it also wasn’t exactly hardcore hacking; IIRC he just changed a URL parameter. As you know, it’s not that far from what white hats sometimes do, in terms of probing public websites - with the obvious exception that they’d usually responsibly disclose the vulnerability to the site owne…

I follow what you're saying, but look at these cases: Aurenheimer was confronted with IRC logs in which he discussed selling the information he got from the website, and Barrett Brown was accused of actively assisting the people who breached Stratfor. What ever you think of the actual prosecutions here, neither of those are cases of security research being mistaken for something else. The most you can say, for instan…

Regarding Weev, should planning on selling the data really affect the legality of his behavior? I mean, there are services that sell data they scrape from websites after all.
Post reply on HN