Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

301–310 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#303

Earlier quoted context omitted.

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

"White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. People on this thread have a lot of strange ideas about what infosec people do in their jobs.

> "White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets.

The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it.

And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.

Re: Arrest of WannaCry researcher sends chill through security community

#304

Earlier quoted context omitted.

There is a due process to catch an ally's civilian, that's called an extradition, that process is important.

The parties involved probably judged correctly that if they attempted to extradite him, he would be the subject of a prolonged media campaign against the government in the UK to keep him here. What I don't understand is why the FBI didn't just hand the evidence to the NCA in the UK and have them arrest him.

Well the government shouldn't modulate how it executes the law based on the optics or media impact. And as you said, this move shows that they didn't think the UK would agree with their evidence, which is far more reason for this snatching to be worrying.

Re: Arrest of WannaCry researcher sends chill through security community

#305

Earlier quoted context omitted.

>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.

I think the worry here is that he now has no way of returning to the U.K. where he earns his income. He is stuck in jail in the US without reasonable access to a good lawyer (an appointed lawyer won't understand this case). His outcome looks bleak, guilty or innocent.

Though as I understood it he was working remotely for a California based company. So not being in the UK is not the problem here.

Though I am not sure even if on bail if has access to his computers?

Re: Arrest of WannaCry researcher sends chill through security community

#306

Earlier quoted context omitted.

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

White hats have to traffic in I feel like you're changing the terminology here in order to confuse the pretty clear lines. Obtaining and analysing != creating and selling.

Creating and selling is also normal course of operation, penetration testing tools, offensive tools used by various gov. entities, rootkits used by some entertainment conglomerates to "protect their ip" they are routinely created and sold.

Re: Arrest of WannaCry researcher sends chill through security community

#307
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Ok, so to this point (and I'm not a security researcher, so forgive my ignorance) couldn't a legit malware creator call their work "research"? I feel like a malware creator could throw this smoke screen whenever they wanted. It's not a free pass...

Re: Arrest of WannaCry researcher sends chill through security community

#308
post #224

Earlier quoted context omitted.

I don't know what these terms even mean. "White hat hacker"? Is that what we call "everyone who does anything in infosec but doesn't sell stolen financial information obtained from botnets"? The attempt to divide the whole world into "people irrationally attacking 'hackers' and 'the good kind of hackers'" isn't doing anyone any favors. If Hutchins has nothing to do with a criminal conspiracy to profit from a truly aw…

>People love to talk about how the FBI has a history of framing people --- and in other fields they might. But there is no track record I'm aware of for the FBI to make up a story like this out of whole cloth. No? It is fairly common in Terrorism cases. I fail to see why they could not do it for Cyber Crime as well https://www.techdirt.com/articles/20120917/05193620404/fbi-c... https://www.nytimes.com/2016/06/08/us/f…

> Want more?

Well, yes, since none of those are actually examples of the FBI framing anyone. Stings are not the same thing as framing, no matter how much sarcasm techdirt uses to describe them.

A sting is law enforcement creating a situation where someone can demonstrate clear evidence of their intent to break the law. Framing is law enforcement MANUFACTURING evidence that someone broke or intended to break the law.

In the terrorism cases, a sting would be the FBI giving someone a fake bomb and that person trying to blow people up. Framing would be the FBI arresting someone and falsely claiming they found a bomb and plans for the local stadium in the persons's house. It's an important distinction. In the former case, the person clearly tried to kill people while in the latter case they did not.

Re: Arrest of WannaCry researcher sends chill through security community

#309

Earlier quoted context omitted.

> The point the poster was making is that the US happily arrests foreigners who set foot in the US and regardless of your guilt or innocence you get trapped in the US justice system which is essentially a system to tie you up in court and legal processes that you cannot afford so that you accept a plea deal, possibly for something you have not done, because otherwise you face never seeing the outside world again. Any…

Good to see he definitely violated US law. If I had created “Kronos” I sure as fuck would not head to defcon, but then I’m too paranoid to even download Tor, let alone put myself on the radar of the FBI. His arrest proves my thoughts for a while; the US is not a safe place to travel to - the legal system will destroy you should you be accused of any crime, and as a foreign person you have even fewer rights than a US…

The expressions "arrested for X" is not a statement of guilt or innocence regarding crime X. It's a factual statement about why someone was arrested. Maybe you're not a native speaker of American English, but it's a typical expression and doesn't, on its own, imply judgement.

I'm honestly surprised by this reaction to his arrest. He may turn out to be innocent, but it's not like US authorities are grabbing random foreigners off the streets and applying arbitrary charges here. They (per the reporting so far) have evidence connecting him to Kronos in a criminal way (not as a researcher). He's in the US. They have enough to believe they can charge him and prove their case. Why would they not arrest him? Your country would almost certainly do the same to any foreigner who they believed violated their laws and still entered your country.

Re: Arrest of WannaCry researcher sends chill through security community

#310
post #270

Earlier quoted context omitted.

Given his life style at Vegas and that he didn't even attend the conference, just went there for partying and meetups, the "chills" are different to the "chills" one would assume from reading the headline. http://www.dailymail.co.uk/news/article-4762608/Marcus-Hutch... They just caught another criminal hacker who was stupid and earned a lot of money from his Kronos hacks. The one chill is how stupid was he? Lamborghi…

If you're not from the UK, just take everything the Daily Mail prints with a gain ( well, a handful ) of salt.

Yes, I know the reputation of the Daily Mail. But there are too many facts in there. The mansion, the admittance, the lamborghini.
Post reply on HN