Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

231–240 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#231

Earlier quoted context omitted.

Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?

lets take away the feelings by saying... if someone were to deliberately sell a pair of shoes to someone that they new would attempt to j-walk with their shoes, do you think they should be partially liable for the j-walking? > no.

sentencing is based around severity, change the severity of the situation and we are no longer talking about the same thing.

Re: Arrest of WannaCry researcher sends chill through security community

#232
post #74
post #41

Earlier quoted context omitted.

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

If you wrote some malware and people were passing around copies of it, wouldn't you want to see the source of what they were passing around?

[deleted]

Re: Arrest of WannaCry researcher sends chill through security community

#234

Why? The arrest of a mall cop who was also doing burglaries wouldn't send a chill through the security guard community, except perhaps for those who were moonlighting as burglars.

The arrest of a mall cop who wasn't proved to be doing burglaries might send a chill, no?

Re: Arrest of WannaCry researcher sends chill through security community

#235
post #37

Earlier quoted context omitted.

> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…

>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.

I think the worry here is that he now has no way of returning to the U.K. where he earns his income. He is stuck in jail in the US without reasonable access to a good lawyer (an appointed lawyer won't understand this case). His outcome looks bleak, guilty or innocent.

Re: Arrest of WannaCry researcher sends chill through security community

#236
post #227
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

You know why it's called a hat? Cause you can take it off and put another one on. Or even be extra silly and wear two or more at the same time. It's tongue in cheek but there is some truth there. In this case he was selling malware so I think this about a time when head gear was of a darker color...

It's a reference to Spy vs spy, a comic strip in mad magazine. The good guy had a white hat, the bad guy black.

Re: Arrest of WannaCry researcher sends chill through security community

#237
post #37

Earlier quoted context omitted.

> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…

>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.

He is not a dangerous criminal, who is going to suddenly kill hundreds of people if he's released. He could have gone back to the UK and the US gov't could have requested his extradition. The fact that they didn't (and my natural tendency to consider governments evil) hint to me that they didn't have that strong a case.

Re: Arrest of WannaCry researcher sends chill through security community

#238
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way.

There is only the thinnest of lines between the two.

White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be necessary to infiltrate black hat collectives.

The clearest way to tell the difference is that a real black hat will be breaking some other law. Committing credit card fraud or misappropriation of trade secrets or something like that.

But that doesn't appear to be the case here. And the fear is that because the law around this is so uncertain, if the government is going to use it in cases like this without any independent bad acts then nobody knows where the line is supposed to be.

Re: Arrest of WannaCry researcher sends chill through security community

#239

Earlier quoted context omitted.

That's one thing that might happen. Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).

Which of the two outcomes do you prefer to happen: 1. True malware creator and seller is sent to prison. 2. True malware creator and seller is not sent to prison. Whether he pleads guilty or not has nothing to do with him being a security researcher. I'd much rather have more false positives than false negatives. You, and the rest of Europe, would too.

I really hope that last statement isn't true. Do you have any idea how horrible being in prison is when you are innocent? Your values are twisted if you think the innocent having their lives ruined is better than a criminal going free.

Re: Arrest of WannaCry researcher sends chill through security community

#240
post #220
post #217

Earlier quoted context omitted.

I'm a pretty big fan of firearms. I disagree. If you had knowledge before hand, of the crime, and a reasonable expectation, you are culpable, to some percentage. The law usually agrees with me, if that helps.

I does not, the vast majority of the law I disagree with See I can not support the concept of 3rd party lability. I should only ever be responsible for my actions, not the actions of others, and I have no responsibility or obligation to stop any crime.

I wish there was a way to flag a user as "favorite"... so far I agree with all your comments on this page :)
Post reply on HN