Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

191–200 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#191

Earlier quoted context omitted.

I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.

Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.

Indoor smoking, 110F weather, and universally crappy, over-priced food.

Re: Arrest of WannaCry researcher sends chill through security community

#192
post #152
post #41

Earlier quoted context omitted.

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

> A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? If I was greedy and in the security field, with identities (or middlemen) on both sides of the game, I would be terribly tempted to play those identities to support each other. For example when blackhat-me would be selling an exploit, whitehat-me could cre…

I feel like you just described the business model of every anti-virus company ever.

Re: Arrest of WannaCry researcher sends chill through security community

#193

Earlier quoted context omitted.

Banking trojans. They're saying that the DOJ might convict people for selling trojans in the course of their security work. I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.

Is selling Trojans illegal? If so, why are companies like Punkbuster and nProtect allowed to develop anticheat software? A lot of AC software runs in ring0 and behaves a lot like a Trojan. I remember nProtect specifically injecting DLLs into explorer.exe among other nasty "black hat" techniques.

Intent matters.

Re: Arrest of WannaCry researcher sends chill through security community

#194

Earlier quoted context omitted.

I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.

Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.

The gambling doesn't do much for me, but I'm a drinker and a social smoker. It's hard to put my finger on what's so grating about the Vegas strip, but something about it puts my teeth on edge. It's a really fake and touristy place, and it's not fake and touristy in a pleasant way.

Re: Arrest of WannaCry researcher sends chill through security community

#195
post #76

Earlier quoted context omitted.

I follow what you're saying, but look at these cases: Aurenheimer was confronted with IRC logs in which he discussed selling the information he got from the website, and Barrett Brown was accused of actively assisting the people who breached Stratfor. What ever you think of the actual prosecutions here, neither of those are cases of security research being mistaken for something else. The most you can say, for instan…

Regarding Weev, should planning on selling the data really affect the legality of his behavior? I mean, there are services that sell data they scrape from websites after all.

Yes? Of course it would?

Re: Arrest of WannaCry researcher sends chill through security community

#196
post #140

Earlier quoted context omitted.

Again, no contradiction here. There is a fear that a white hat is being accused of black hat behavior. Not a claim. A fear. And a reality that a person (maybe white hat, maybe black hat, we don't know) is being accused of black hat behavior. Nothing surprising here. He may, or may not, be a black hat. The fear of unjust accusation is still valid. We will have to see if the DOJ will share the evidence, and what that e…

>The fear of unjust accusation is still valid. Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.

I think it was just a lazy way to write a headline about how everyone in the security community is talking about this case --- which they are. It's a lot more interesting for readers if something important is at stake --- which I think really nothing is.

Re: Arrest of WannaCry researcher sends chill through security community

#197

Earlier quoted context omitted.

Banking trojans. They're saying that the DOJ might convict people for selling trojans in the course of their security work. I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.

Is selling Trojans illegal? If so, why are companies like Punkbuster and nProtect allowed to develop anticheat software? A lot of AC software runs in ring0 and behaves a lot like a Trojan. I remember nProtect specifically injecting DLLs into explorer.exe among other nasty "black hat" techniques.

It's a difference in kind, not degree. The trojan in this case was meant to harvest banking and Amazon logins.

Re: Arrest of WannaCry researcher sends chill through security community

#199
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The quotes came from people who only knew him as a WannaCry researcher, due the fact that the DoJ took forever to say why they were arresting him. It's as if a prominent anti-spammer were to get arrested with no explanation. A naive guess would be that it was due to their anti-spam work. Even though this arrest wasn't related to his WannaCry, that was his most recent exposure to the public and I think assuming it was…

[deleted]

Re: Arrest of WannaCry researcher sends chill through security community

#200
post #62
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

You think the FBI is going to interdict a computer criminal before they spend a week in Las Vegas associating with computer security professionals, any of whom could be criminal co-conspirators?† That would be exceptionally nice of them, but also extremely poor investigative practice. I will say, though, as one of the many people in my field that is bone-tired of schlepping out to the worst place in the United States…

You forgot to mention having the opportunities to electronically surveil his activities while he's physically located in the United States, to attempt to possibly catch him soliciting a plant, bragging to a stripper while drunk, or attempt to catch him in some other questionable activities that they could use as the basis of an arrest or further warrants without having to play their hand as to what they think he's actually guilty of (and therefore being able to possibly turn him as an informant).

There's a brazillion reasons not to arrest someone the minute you think you've got them.

Post reply on HN