Earlier quoted context omitted.
The "chill" comes from legal activities potentially getting you detained and brought up on charges. That's a real cost, even assuming a perfect justice system that can tell they made a mistake. For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops could…
>the cops couldn't tell the difference is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?
Arrest of WannaCry researcher sends chill through security community
181–190 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#182Earlier quoted context omitted.
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
A general question not directly related to the case: Where exactly is the line between criminal conspiracy and writing software tools?
Certainly TOR is used by people to do bad things (and also good things), but almost everyone agrees that no criminal act has been committed by the creation of TOR. Plenty of legitimate businesses sell Remote Access Trojans (RATs) and go unarrested. On the other hand some developers that sell RATs have been arrested.
If someone pays you 2,000 grand to find an exploit have you committed a crime? What if then they use that exploit you sold them to commit a crime? What if you knew beyond all doubt that was their purpose but then the exploit isn't used? Does it matter if they bought an exploit from you or if you are a salaried employee of their company? What if instead of selling them an exploit you configured an email server for them?
Re: Arrest of WannaCry researcher sends chill through security community
#183Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
That means it should be even less likely to be "send a chill through the security community"
Re: Arrest of WannaCry researcher sends chill through security community
#184Earlier quoted context omitted.
I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.
Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.
Plus it's in the middle of a desert, so options are pretty limited.
Re: Arrest of WannaCry researcher sends chill through security community
#185Earlier quoted context omitted.
But he wasn't arrested for any normal thing a security researcher would do - he's arrested for creating and selling malware... big difference. The FBI could be wrong and that'd suck. I'm just assuming that the FBI and their resources have enough evidence to reasonably believe he's the creator. And again, your last comment doesn't fit this article. They aren't overextending and arresting a security researcher (althoug…
The implication is that the FBI may believe him to be the creator of Kronos based on something he did as part of security research, eg. gaining access to a control panel or taking over a CnC server.
Re: Arrest of WannaCry researcher sends chill through security community
#186Earlier quoted context omitted.
A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…
Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.
Re: Arrest of WannaCry researcher sends chill through security community
#187Earlier quoted context omitted.
> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. “Innocent until proven guilty” is a legal standard applied where “guilty” means having one’s liberty taken away. And in that context it’s a perfectly appropriate standard. But as mere spectators, where the harm caused by mistakenly believing he’s guilty is minimal, I think we shou…
So you're basically saying that if the police took him there must be a good reason for that to happen therefore guilty as charged. You have a peculiar interpretation of justice, one that makes you pretty much like those that liked to burn people on fire pyres on the basis of allegations made by socially relevant people.
Why is it the appropriate standard? Because as a society, we believe that taking away an innocent person's liberty is far worse than letting a guilty person go free. For the expected value (in the statistical sense) of the legal system's benefit to society to be positive, the prevalence of the former should be a tiny fraction of the prevalence of the latter. (How tiny that fraction actually is, in the US or anywhere else, is debatable - you could look at the number of convicts who were proved innocent upon the advent of DNA testing - but that's not the point.) Thus we should only convict if the apparent probability of guilt is extremely high.
But if I as a bystander believe an innocent person is guilty, it's not as big a deal. True, if a lot of people believe that, it causes some reputational damage, which can be bad. If someone with a connection to the person makes decisions disfavorable to them based on that belief, that's quite bad. But this risk is mitigated by the fact that soon enough the police will be required to present their evidence in court, which should help drive our assessments with more certainty to one possibility or the other. And in any case, these harms are far lesser than the harm of subjecting the person to prison, or worse punishments.
Perhaps I misstated the ideal standard for bystanders. Perhaps it should not be literally whichever possibility is more likely; perhaps we should give people some "benefit of the doubt", due to the above harms. But there's no need for the extreme standard demanded by the actual justice system. A reasonably high probability of guilt is enough, at least to treat guilt as a working hypothesis.
In a legal system such as the United States', "if the police took him" (specifically, indicted him), I'd say there's a high probability - at least 75% or so, probably higher - that there's a "good reason for that to happen". (At least in the sense of "he did what they say he did"; whether that thing ought to be illegal or not is typically more subjective.) It's not certain; there could be some sort of corruption or unethical behavior by the police, or they could simply be mistaken. But it's enough to form a working hypothesis, to use until we gain more information.
Re: Arrest of WannaCry researcher sends chill through security community
#188Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.
>Extradition before the event was feasible
It wasn't feasible for political reasons. By attempting to extradite yet another sympathetic character from the UK the US would have risked undermining the extradition treaty for no gain.
Anyway, I don't understand how extraditing him from the UK would've been any more honorable.
Re: Arrest of WannaCry researcher sends chill through security community
#189I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
I've read the indictment but we'll have to wait and see how the government argues its case when this comes to trial.
Re: Arrest of WannaCry researcher sends chill through security community
#190Earlier quoted context omitted.
"Type of bug"? Sorry, I don't follow.
Banking trojans. They're saying that the DOJ might convict people for selling trojans in the course of their security work. I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.
A lot of AC software runs in ring0 and behaves a lot like a Trojan. I remember nProtect specifically injecting DLLs into explorer.exe among other nasty "black hat" techniques.