Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

261–270 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#261

Earlier quoted context omitted.

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

This is complete nonsense.

Maybe there is a case that buying malware is a reasonable thing to do in some circumstances.

Selling your own malware is a different thing. That seems a pretty clear boundary.

Re: Arrest of WannaCry researcher sends chill through security community

#262

Earlier quoted context omitted.

Indoor smoking, 110F weather, and universally crappy, over-priced food.

Okay, so @arthulia and @hueving, is it "good restaurants" or "crappy, over-priced food"? Never been there, but could somewhat imagine either scenario. Actually I could imagine multiple possibilities for each: "good restaurants": (1) lots of top-tier cooks go there because money and it's cheap because Vegas, or (2) lots of off-strip places with good chefs trying to make it big. "crappy, overpriced food": (1) Wolfgang…

Both. There are a lot of chains and mid-grade restaurants where you will pay an arm and a leg for mediocre food.

However, there are also some of the best buffets in the world there (if you're into that). There are also some awesome high-end restaurants: https://www.tripsavvy.com/michelin-guide-rated-restaurants-l...

Because Vegas is a massive tourist destination where you are guaranteed to have a deep market of people eating out every day of the week, it attracts tons of restaurants so you do need to do a little research. Picking a random one will likely get you overpriced 'meh'.

Re: Arrest of WannaCry researcher sends chill through security community

#263
post #83
post #54

Earlier quoted context omitted.

What legitimate security research are we talking about? I work in vulnerability research and not malware research, but: can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?

"can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?" Randal Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz

That isn't a great example. He managed to get his conviction overturned because of the lack of criminal intent, but what he did was pretty stupid.

Rather ill-advisedly, the Perl-programming guru (who's written several books on the subject) tried to prove his worth by running a password cracking package after he'd left in order to produce evidence that security practices had deteriorated since his departure. Instead of re-hiring Schwartz, as he hoped, Intel called in the police and he was charged with hacking offences.

http://www.theregister.co.uk/2007/03/05/intel_hacker_charges...

Re: Arrest of WannaCry researcher sends chill through security community

#264

Earlier quoted context omitted.

The "chill" comes from legal activities potentially getting you detained and brought up on charges. That's a real cost, even assuming a perfect justice system that can tell they made a mistake. For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops could…

>the cops couldn't tell the difference is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?

> The FBI isn't a bunch of complete incompetents.

The FBI is human and therefor make mistakes, and they are a large organization and therefor have an structural inertia that occasionally directs a lot of power and effort at the wrong target.

Also, the price of democracy is eternal vigilance. Citizens have a duty to check the government's use of power. We should be worrying every time the government acts against a citizen until we also see proper due process including any necessary evidence.

> He could be found innocent

He is innocent until proven otherwise.

> what makes this case different

The government hasn't yet shown that they can handle this kind of case properly. That is partly due to the novel nature of situations involving new technology, but it is also from the government's own history of bad behavior. Their reputation means they do not get the benefit of the doubt, and until we see actual evidence that this case (regardless of the outcome) is being handled properly, it's prudent to worry that this might be an overreaching prosecutor (or worse).

Re: Arrest of WannaCry researcher sends chill through security community

#265
post #47

Earlier quoted context omitted.

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

Accusations can be based on bad extrapolation of facts.

Re: Arrest of WannaCry researcher sends chill through security community

#266
post #164
post #153

Earlier quoted context omitted.

Why is there a law against selling malware? Couldn't a comparison be made with regards to firearms? He created the malware but didn't deploy it live

Not a good anology. What's a legitimate use for banking malware? A more apt analogy would be selling an IED.

Hmmm. What are the legitimate uses for firearms again?

Re: Arrest of WannaCry researcher sends chill through security community

#267

Perhaps you are being deliberately obtuse I'm not sure. The point the poster was making is that the US happily arrests foreigners who set foot in the US and regardless of your guilt or innocence you get trapped in the US justice system which is essentially a system to tie you up in court and legal processes that you cannot afford so that you accept a plea deal, possibly for something you have not done, because otherw…

> The point the poster was making is that the US happily arrests foreigners who set foot in the US and regardless of your guilt or innocence you get trapped in the US justice system which is essentially a system to tie you up in court and legal processes that you cannot afford so that you accept a plea deal, possibly for something you have not done, because otherwise you face never seeing the outside world again. Any…

Good to see he definitely violated US law. If I had created “Kronos” I sure as fuck would not head to defcon, but then I’m too paranoid to even download Tor, let alone put myself on the radar of the FBI.

His arrest proves my thoughts for a while; the US is not a safe place to travel to - the legal system will destroy you should you be accused of any crime, and as a foreign person you have even fewer rights than a US citizen.

Finally even if “perfect” digital information exists, all of that can be faked perfectly and it’s certainly something I would think about doing (having a patsy) if I were in the position of creating something like this.

Re: Arrest of WannaCry researcher sends chill through security community

#268
post #27

Earlier quoted context omitted.

I think people who write malware to steal banking info should be prosecuted when possible. It will be interesting to see whether this goes to trial and if so how solid any evidence against him is. However, I do not doubt that a mix of fear & incompetence could have resulted in his arrest as much as any concrete evidence of his involvement in Kronos. I think there's (perhaps rightfully) a culture of distrust and paran…

> people who write malware to steal banking info should be prosecuted I really disagree with you on this. The problem is not the person who researches different exploits (ie who may /write/ the malware) but with the people who /use/ the malware to do bad things. When we keep preventing white hat researchers from doing their job, there's no defense against black hats. If he actually sold Kronos for the sole purpose of…

You can’t just conflate exploit research and trojan creation with some hand waving. They are two very different things - not just different words.

Re: Arrest of WannaCry researcher sends chill through security community

#269
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

Writing malware is not a crime. Using it is. What gets me about this case is that, if I understand it correctly, he is being punished for writing software. I've read the indictment but we'll have to wait and see how the government argues its case when this comes to trial.

If you read the indictment then you’d know he was arrested for selling the trojan and conspiracy, not for writing it.

Re: Arrest of WannaCry researcher sends chill through security community

#270
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Given his life style at Vegas and that he didn't even attend the conference, just went there for partying and meetups, the "chills" are different to the "chills" one would assume from reading the headline. http://www.dailymail.co.uk/news/article-4762608/Marcus-Hutch...

They just caught another criminal hacker who was stupid and earned a lot of money from his Kronos hacks. The one chill is how stupid was he? Lamborghini? The second chill is how naive have I been when reading about the lone hacker fixing WannaCry and saving the world from his mom's house bedroom?

Post reply on HN