Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

251–260 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#251
post #206
post #47

Earlier quoted context omitted.

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

Why is there a tone that he's already found guilty without a trial?

> Hutchins is accused...

i thought it was pretty clear

Re: Arrest of WannaCry researcher sends chill through security community

#252
post #225
post #187

Earlier quoted context omitted.

Being burned at stake would count as "having one's liberty taken away", and is therefore a case where, as I said, "innocent until proven guilty" is the appropriate standard. Why is it the appropriate standard? Because as a society, we believe that taking away an innocent person's liberty is far worse than letting a guilty person go free. For the expected value (in the statistical sense) of the legal system's benefit…

I am sure people like Richard Jewell would share belief that "as a bystander believe an innocent person is guilty, it's not as big a deal." Innocent people have their lives for ever ruined with nothing more than false accusations, and not being found not guilty at trial does not change that. Further I would like to see where you get your belief that police are correct 75% or more of the time. It seems to me you have…

Richard Jewell was not indicted for anything.

Re: Arrest of WannaCry researcher sends chill through security community

#253

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

"White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets.

People on this thread have a lot of strange ideas about what infosec people do in their jobs.

Re: Arrest of WannaCry researcher sends chill through security community

#254
post #47

Earlier quoted context omitted.

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

It seems like he may not have created the trojan, but simply created a bootkit that it utilized. A fairly common thing for security researchers to do.

Re: Arrest of WannaCry researcher sends chill through security community

#255

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

While the tools, methods and knowledge might be similar or the same... to say "the thinnest of lines between the two" exists is a bit disingenuous.

There is a MASSIVE difference between researching security holes... and then selling the exploits for those security holes or tools that use said security holes.

Again... if the chatter here is accurate, he's not being "arrested" for research... he's being arrested for tools created and sold with the knowledge gained by said research.

There's a difference between discovering a hole in a banks security... and robbing a bank using that hole.

Massive difference.

Re: Arrest of WannaCry researcher sends chill through security community

#256

Why? The arrest of a mall cop who was also doing burglaries wouldn't send a chill through the security guard community, except perhaps for those who were moonlighting as burglars.

The arrest of a mall cop who wasn't proved to be doing burglaries might send a chill, no?

Arrest is an early step in a process to prove guilt or acquit. The "burglary" did occur, and a grand jury did examine evidence and determine it was sufficient to start that process.

Re: Arrest of WannaCry researcher sends chill through security community

#257

Why? The arrest of a mall cop who was also doing burglaries wouldn't send a chill through the security guard community, except perhaps for those who were moonlighting as burglars.

If he was arrested for burglarizing a mall he worked in, though, and you didn't have any evidence other than the claim of the arresting authorities that he wasn't merely present in the mall (as security guards are wont to be) where a burglary had taken place, you might be somewhat concerned.

Fair enough, but I don't think that the FBI conspires to frame people for crimes all that often, nor that many security researchers believe that they do. Also, the fact that a grand jury handed down an indictment indicates that there is evidence that will be shared at trial. Unless the grand jury is also part of the conspiracy, of course.

Re: Arrest of WannaCry researcher sends chill through security community

#258

Earlier quoted context omitted.

Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.

Indoor smoking, 110F weather, and universally crappy, over-priced food.

Okay, so @arthulia and @hueving, is it "good restaurants" or "crappy, over-priced food"? Never been there, but could somewhat imagine either scenario. Actually I could imagine multiple possibilities for each:

"good restaurants": (1) lots of top-tier cooks go there because money and it's cheap because Vegas, or (2) lots of off-strip places with good chefs trying to make it big.

"crappy, overpriced food": (1) Wolfgang Puck etc, or (2) Even off-strip food is bad and expensive because they can't afford water.

So in reality which is it?

Re: Arrest of WannaCry researcher sends chill through security community

#259

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

White hats have to traffic in

I feel like you're changing the terminology here in order to confuse the pretty clear lines.

Obtaining and analysing != creating and selling.

Re: Arrest of WannaCry researcher sends chill through security community

#260
post #140

Earlier quoted context omitted.

Again, no contradiction here. There is a fear that a white hat is being accused of black hat behavior. Not a claim. A fear. And a reality that a person (maybe white hat, maybe black hat, we don't know) is being accused of black hat behavior. Nothing surprising here. He may, or may not, be a black hat. The fear of unjust accusation is still valid. We will have to see if the DOJ will share the evidence, and what that e…

>The fear of unjust accusation is still valid. Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.

> If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.

How do you know that it doesn't? White hats are counterintel agents effectively. If a counterintel agent is arrested for doing something that could be deemed as part of his job, why wouldn't it 'send a chill' through the community?

Post reply on HN