Earlier quoted context omitted.
I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.
Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.
Arrest of WannaCry researcher sends chill through security community
191–200 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#192Earlier quoted context omitted.
There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...
> A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? If I was greedy and in the security field, with identities (or middlemen) on both sides of the game, I would be terribly tempted to play those identities to support each other. For example when blackhat-me would be selling an exploit, whitehat-me could cre…
Re: Arrest of WannaCry researcher sends chill through security community
#193Earlier quoted context omitted.
Banking trojans. They're saying that the DOJ might convict people for selling trojans in the course of their security work. I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.
Is selling Trojans illegal? If so, why are companies like Punkbuster and nProtect allowed to develop anticheat software? A lot of AC software runs in ring0 and behaves a lot like a Trojan. I remember nProtect specifically injecting DLLs into explorer.exe among other nasty "black hat" techniques.
Re: Arrest of WannaCry researcher sends chill through security community
#194Earlier quoted context omitted.
I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.
Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.
Re: Arrest of WannaCry researcher sends chill through security community
#195Earlier quoted context omitted.
I follow what you're saying, but look at these cases: Aurenheimer was confronted with IRC logs in which he discussed selling the information he got from the website, and Barrett Brown was accused of actively assisting the people who breached Stratfor. What ever you think of the actual prosecutions here, neither of those are cases of security research being mistaken for something else. The most you can say, for instan…
Regarding Weev, should planning on selling the data really affect the legality of his behavior? I mean, there are services that sell data they scrape from websites after all.
Re: Arrest of WannaCry researcher sends chill through security community
#196Earlier quoted context omitted.
Again, no contradiction here. There is a fear that a white hat is being accused of black hat behavior. Not a claim. A fear. And a reality that a person (maybe white hat, maybe black hat, we don't know) is being accused of black hat behavior. Nothing surprising here. He may, or may not, be a black hat. The fear of unjust accusation is still valid. We will have to see if the DOJ will share the evidence, and what that e…
>The fear of unjust accusation is still valid. Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.
Re: Arrest of WannaCry researcher sends chill through security community
#197Earlier quoted context omitted.
Banking trojans. They're saying that the DOJ might convict people for selling trojans in the course of their security work. I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.
Is selling Trojans illegal? If so, why are companies like Punkbuster and nProtect allowed to develop anticheat software? A lot of AC software runs in ring0 and behaves a lot like a Trojan. I remember nProtect specifically injecting DLLs into explorer.exe among other nasty "black hat" techniques.
Re: Arrest of WannaCry researcher sends chill through security community
#198Re: Arrest of WannaCry researcher sends chill through security community
#199I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
The quotes came from people who only knew him as a WannaCry researcher, due the fact that the DoJ took forever to say why they were arresting him. It's as if a prominent anti-spammer were to get arrested with no explanation. A naive guess would be that it was due to their anti-spam work. Even though this arrest wasn't related to his WannaCry, that was his most recent exposure to the public and I think assuming it was…
Re: Arrest of WannaCry researcher sends chill through security community
#200Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.
You think the FBI is going to interdict a computer criminal before they spend a week in Las Vegas associating with computer security professionals, any of whom could be criminal co-conspirators?† That would be exceptionally nice of them, but also extremely poor investigative practice. I will say, though, as one of the many people in my field that is bone-tired of schlepping out to the worst place in the United States…
There's a brazillion reasons not to arrest someone the minute you think you've got them.