Arrest of WannaCry researcher sends chill through security community
241–250 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#242Earlier quoted context omitted.
The gambling doesn't do much for me, but I'm a drinker and a social smoker. It's hard to put my finger on what's so grating about the Vegas strip, but something about it puts my teeth on edge. It's a really fake and touristy place, and it's not fake and touristy in a pleasant way.
I call it "the Times Square" effect. Every major city has one. Hollywood Boulevard in LA. Fisherman's Wharf in SF. The eponymous Times Square in NY. Etc. I don't know if the Vegas Strip deserves the title for "absolute worse", but it is certainly conceivable.
Re: Arrest of WannaCry researcher sends chill through security community
#243Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.
You think the FBI is going to interdict a computer criminal before they spend a week in Las Vegas associating with computer security professionals, any of whom could be criminal co-conspirators?† That would be exceptionally nice of them, but also extremely poor investigative practice. I will say, though, as one of the many people in my field that is bone-tired of schlepping out to the worst place in the United States…
Very particular definition of a word criminal I guess. Kevin Mitnick, James Clapper, veew, plenty of criminals attend/panel at defcon.
Re: Arrest of WannaCry researcher sends chill through security community
#244Earlier quoted context omitted.
You know why it's called a hat? Cause you can take it off and put another one on. Or even be extra silly and wear two or more at the same time. It's tongue in cheek but there is some truth there. In this case he was selling malware so I think this about a time when head gear was of a darker color...
It's a reference to Spy vs spy, a comic strip in mad magazine. The good guy had a white hat, the bad guy black.
Re: Arrest of WannaCry researcher sends chill through security community
#245Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
There's a big disconnect because people seem to be associating this guy's arrest with his serendipitous Wannacry incident. But there's no correlation at all. He is alleged to have had a shady past (corroborated by many reputable HN commenters) and later turned white hat.
Re: Arrest of WannaCry researcher sends chill through security community
#246Earlier quoted context omitted.
I am not kidding, but rather parroting Orin Kerr, an expert on this subject, who does not think this case is a slam dunk. (Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)
Link to the Orin Kerr article: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201... Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.
If someone manufactures guns, doesn't register them, and knowingly sells them to street gangs, it kind of seems like they're aiding and abetting illegal activities for profit.
Of course there are instances of selling malware you created to parties who generally won't use it illegally, but that's not what's alleged here.
Whether Hutchins truly violated the law, I don't know, but if the allegations are true then he did something very unethical and something I feel should be illegal.
Re: Arrest of WannaCry researcher sends chill through security community
#247Earlier quoted context omitted.
Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?
Yes, the seller would legally be an accessory to the murder, having had knowledge that the crime would be committed and having helped the murderer commit it. https://en.wikipedia.org/wiki/Accessory_(legal_term)
Re: Arrest of WannaCry researcher sends chill through security community
#248He's not indicted for doing security research, he's indicted for stealing people's bank accounts. The indictment may end up being bullshit, but it has not been for any of his white-hat, or grey-hat activities.
I don't defend him in any way but he is not indicted for stealing people's bank account just for writing software that does that, please don't spread disinformation about this.
Re: Arrest of WannaCry researcher sends chill through security community
#249Earlier quoted context omitted.
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
Re: Arrest of WannaCry researcher sends chill through security community
#250Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
it's unclear what "creating" entails. If I write a crypto library that a piece of ransomware uses did I create the ransomware?