Earlier quoted context omitted.
Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?
lets take away the feelings by saying... if someone were to deliberately sell a pair of shoes to someone that they new would attempt to j-walk with their shoes, do you think they should be partially liable for the j-walking? > no.
Arrest of WannaCry researcher sends chill through security community
231–240 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#232Earlier quoted context omitted.
There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...
If you wrote some malware and people were passing around copies of it, wouldn't you want to see the source of what they were passing around?
Re: Arrest of WannaCry researcher sends chill through security community
#233Re: Arrest of WannaCry researcher sends chill through security community
#234Why? The arrest of a mall cop who was also doing burglaries wouldn't send a chill through the security guard community, except perhaps for those who were moonlighting as burglars.
Re: Arrest of WannaCry researcher sends chill through security community
#235Earlier quoted context omitted.
> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…
>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.
Re: Arrest of WannaCry researcher sends chill through security community
#236Earlier quoted context omitted.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
You know why it's called a hat? Cause you can take it off and put another one on. Or even be extra silly and wear two or more at the same time. It's tongue in cheek but there is some truth there. In this case he was selling malware so I think this about a time when head gear was of a darker color...
Re: Arrest of WannaCry researcher sends chill through security community
#237Earlier quoted context omitted.
> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…
>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.
Re: Arrest of WannaCry researcher sends chill through security community
#238Earlier quoted context omitted.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…
There is only the thinnest of lines between the two.
White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be necessary to infiltrate black hat collectives.
The clearest way to tell the difference is that a real black hat will be breaking some other law. Committing credit card fraud or misappropriation of trade secrets or something like that.
But that doesn't appear to be the case here. And the fear is that because the law around this is so uncertain, if the government is going to use it in cases like this without any independent bad acts then nobody knows where the line is supposed to be.
Re: Arrest of WannaCry researcher sends chill through security community
#239Earlier quoted context omitted.
That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).
Which of the two outcomes do you prefer to happen: 1. True malware creator and seller is sent to prison. 2. True malware creator and seller is not sent to prison. Whether he pleads guilty or not has nothing to do with him being a security researcher. I'd much rather have more false positives than false negatives. You, and the rest of Europe, would too.
Re: Arrest of WannaCry researcher sends chill through security community
#240Earlier quoted context omitted.
I'm a pretty big fan of firearms. I disagree. If you had knowledge before hand, of the crime, and a reasonable expectation, you are culpable, to some percentage. The law usually agrees with me, if that helps.
I does not, the vast majority of the law I disagree with See I can not support the concept of 3rd party lability. I should only ever be responsible for my actions, not the actions of others, and I have no responsibility or obligation to stop any crime.