Earlier quoted context omitted.
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…
Given his life style at Vegas and that he didn't even attend the conference, just went there for partying and meetups, the "chills" are different to the "chills" one would assume from reading the headline. http://www.dailymail.co.uk/news/article-4762608/Marcus-Hutch... They just caught another criminal hacker who was stupid and earned a lot of money from his Kronos hacks. The one chill is how stupid was he? Lamborghi…
Arrest of WannaCry researcher sends chill through security community
291–300 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#292Earlier quoted context omitted.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
> It bears mentioning that accused does not mean convicted. That means it should be even less likely to be "send a chill through the security community"
They don't give you back your lawyer money if you're found innocent. They don't give you back any job that you may have lost, and they certainly don't give you back the money you would have earned during that time.
Re: Arrest of WannaCry researcher sends chill through security community
#293Earlier quoted context omitted.
I am sure people like Richard Jewell would share belief that "as a bystander believe an innocent person is guilty, it's not as big a deal." Innocent people have their lives for ever ruined with nothing more than false accusations, and not being found not guilty at trial does not change that. Further I would like to see where you get your belief that police are correct 75% or more of the time. It seems to me you have…
Richard Jewell was not indicted for anything.
it was the FBI that pointed the Media to him as a suspect.
Re: Arrest of WannaCry researcher sends chill through security community
#294Earlier quoted context omitted.
Wait, what? How does a person accused of development and direct distribution of malware qualify as a white hat? Because he pulled the plug on some ransomware and put his name in global households? There are a lot of logic jumps here that you have simply glossed over.
The same way someone accused of murder qualifies as not-a-murderer. "Accused" just means someone said it, it doesn't make it true.
If not, you're all being targeted so you should grab a new career before you get feds at the door.
Re: Arrest of WannaCry researcher sends chill through security community
#295Earlier quoted context omitted.
The same way someone accused of murder qualifies as not-a-murderer. "Accused" just means someone said it, it doesn't make it true.
That itself is a huge logic jump that is being made, both by the DoJ and the infosec community. His bail was set at 30k, the 10% rule makes his bail 3k, so he should be out by tomorrow if he really deved that malware. If not, you're all being targeted so you should grab a new career before you get feds at the door.
You can put up $30,000 Cash or some other asset as BAIL then that is returned to you in full after the trail
Or you can pay a Bails Bondsmen 10% of that, as a fee, they will put up the court a 30K BOND then assure the court they will make you appear or pay the court the 30K if skip
You as the individual however lose that $3k.
Re: Arrest of WannaCry researcher sends chill through security community
#296Earlier quoted context omitted.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
Which is why he was arrested. He is accused of a crime, and will stand trial.
FBI is known for arresting, and indicted people with crimes that carry LARGE sentences to use that a leverage to turn those people into informants.
Extortion is a power tool used by the US Government
Re: Arrest of WannaCry researcher sends chill through security community
#297I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
When he found his hooking code in a malware sample (presumably Kronos), he expressed his disappointment / frustration with this (ab)use of his work on twitter. Whether or not this is truthful or just public posturing remains to be seen.
None of this is recent news - it played out in early 2016, so his arrest now is a little odd, unless the DOJ has uncovered new details that have not been publicly disclosed.
If it turns out he is arrested for some of his public code in a piece of malware, it should worry both security researchers and open source developers a lot.
Re: Arrest of WannaCry researcher sends chill through security community
#298Earlier quoted context omitted.
It seems to me that this is kind of a litmus situation - this case reveals what you think of the DOJ. If you think that they somewhat routinely frame people that they are "after", then you look at the fact of the accusation and see this case as more proof that security researchers should be cautious (and maybe avoid entering the US). On the other hand, if you think that the DOJ, while subject to making mistakes, does…
I think there's very little evidence that the DOJ routinely frames accused computer criminals --- or even that they routinely make mistakes with them. The reality is that so few computer crimes are prosecuted that the ones that are are usually smoking-gun cases. I can't speak to any other aspect of federal prosecution. My thoughts about computer crime prosecution definitely can't be extrapolated to my thoughts about…
Wanncry was a massive black eye of the US Government, I think everyone believing there is zero connection between his involvement in that and this indictment is also naive.
I also fail to understand why you believe "computer crimes" are handled differently than any other type of crime, why you believe the DOJ would frame people for "other types of crimes" but never computer crimes, like there is some prohibition on entrapment when it comes to computers...
Re: Arrest of WannaCry researcher sends chill through security community
#299Earlier quoted context omitted.
I does not, the vast majority of the law I disagree with See I can not support the concept of 3rd party lability. I should only ever be responsible for my actions, not the actions of others, and I have no responsibility or obligation to stop any crime.
> and I have no responsibility or obligation to stop any crime. You don't have to ask someone if he wants to commit a crime, so that is not the problem. It is when someone explicitly asks for your help in commiting a crime and you think to yourself "yes I want to be complicit in this" that lands you in legal trouble. If someone asks you for a handgun to kill someone you don't have to stop him, you just aren't allowed…
Instead most often these types of laws are used to prosecute people under a "should have known" scenario.
Examples of real situations of 3rd party liability that have been used to send people to prison
1. Jim takes a friend to a bank, the friend goes in and robs the bank. Jim though the friend was just withdrawing some money from his account but Jim is arrested and convicted of aiding his friend in the robbery
2. Jane does not have a license, a police officer attempts to stop Jane, Jane panics and runs from the police. The Police officer runs through a red light while in pursuit and kills a bystander, Jane is charged with murder.
Re: Arrest of WannaCry researcher sends chill through security community
#300Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.
There is apparently going to be a DEF CON event in Beijing. But I'm not sure that will be any better in terms of not going to prison.