Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

321–330 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#321

Earlier quoted context omitted.

There is apparently going to be a DEF CON event in Beijing. But I'm not sure that will be any better in terms of not going to prison.

Got any details on that?

No, Dark Tangent just mentioned it at the closing at DEF CON 25, I can't find any more details than that.

Re: Arrest of WannaCry researcher sends chill through security community

#322
post #310

Earlier quoted context omitted.

If you're not from the UK, just take everything the Daily Mail prints with a gain ( well, a handful ) of salt.

Yes, I know the reputation of the Daily Mail. But there are too many facts in there. The mansion, the admittance, the lamborghini.

You've got to make sure you have all the facts though. Renting a $1,900 per night mansion looks a lot less extravagant when that cost is being split by 7 people.

And renting a fancy car for a few days might not be that much money. I recently used Turo to rent a gold Cadillac for a trip up to Marin County. Pretty nice, huh? It cost less than renting a Nissan Altima from Budget. (I checked.)

Re: Arrest of WannaCry researcher sends chill through security community

#323
post #100
post #64

Earlier quoted context omitted.

We don't know whether he did or not. But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. And there very well may be evidence, especially if the timing is related to something new obtained from the Alpha Bay takedown and it happening when he happened to visit the US for DEFCON was a coincidence.…

> But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. Is this just for alleged computer crimes, or would you apply that to all alleged crimes? For example, suppose I run a fraudulent mail order business targeting people in, say, France, and this is a crime in France. Would you argue that if I vi…

Somewhat. The distinction I would make is not computer crimes vs other crimes, but rather the timeliness of the situation. For an emergency situation, or a case where a wanted individual enters the country anyway, I agree they'd be foolish to let them return home and only then try to have an arrest made. But there's also no reason prosecutors should lie in wait until you visit the US to even bring charges. They should decide you're being charged, issue a warrant, and try have the arrest made, including asking other countries for cooperation.

But the alleged crime here is years old, and I have don't remember anything (or find anything in a google news search-by-date) to suggest there were charges or an arrest warrant before July 2017. That makes it seem like they didn't think the evidence was strong enough to get British cooperation, and waited to even mention it until they'd have have a chance to act alone.

Either that, or they really had nothing linking Hutchins to Kronos until very recently. If it turns this really was based on new information, and the timing really was coincidental, I'll be a lot more comfortable with how it was handled. But that's sure not what it looks like right now...

Re: Arrest of WannaCry researcher sends chill through security community

#324
post #152

Earlier quoted context omitted.

> A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? If I was greedy and in the security field, with identities (or middlemen) on both sides of the game, I would be terribly tempted to play those identities to support each other. For example when blackhat-me would be selling an exploit, whitehat-me could cre…

I feel like you just described the business model of every anti-virus company ever.

Are they petty enough to sell exploits? Kaspersky, for example, is so deep in bed with FSB that it's hard to tell exactly where one ends and the other starts; I really doubt FSB would bother selling exploits to anyone.

Re: Arrest of WannaCry researcher sends chill through security community

#325

Earlier quoted context omitted.

> It bears mentioning that accused does not mean convicted. That means it should be even less likely to be "send a chill through the security community"

Accused may not mean convicted, but it probably does mean a year in jail awaiting trial, and at trial, and paying for a lawyer that costs tens of thousands of dollars, maybe hundreds of thousands. They don't give you back your lawyer money if you're found innocent. They don't give you back any job that you may have lost, and they certainly don't give you back the money you would have earned during that time.

> a year in jail awaiting trial

Only in the most exceptional cases is someone held without bail.

> They don't give you back your lawyer money if you're found innocent.

Federal courts can award legal costs "where the court finds that the position of the United States was 'vexatious, frivolous, or in bad faith.'" https://en.wikipedia.org/wiki/Hyde_Amendment_(1997)

---

But yes, your broader point is correct that it's certain to be a very bad experience.

Re: Arrest of WannaCry researcher sends chill through security community

#326
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

This makes me hope hackers go back to selling vulns online.

Re: Arrest of WannaCry researcher sends chill through security community

#327
post #311

Earlier quoted context omitted.

>In the terrorism cases, a sting would be the FBI giving someone a fake bomb No that should be entrapment A Sting is where they get a tip that criminal action might be happening and they are there to catch the criminals in the act Not where the FBI creates the plan, induces people into the plan, provides support for the plan, provide materials for the plan, then arrests everyone. That is or should be considered entra…

If I ask the FBI for a bomb and they give it to me and then arrest me that isn’t entrapment. That’s me being a jackass. If the FBI put cocaine in my car and then pulled me over, that’s framing. I’m not entirely sure what either of these things have to do with getting arrested for creating and selling exploits.

IANAL, but I entrapment can occur when law officers enticies the suspect to commit a crime the wouldn't normally https://en.m.wikipedia.org/wiki/Entrapment

The definition of "wouldn't normally" looks like some hairy case law, but it isn't as simple as you are saying. If they are offered a bomb for sale after a lengthy conversation about how great terrorism is and how important it would be for them to take the bomb, you could possibly have an entrapment case for example.

Re: Arrest of WannaCry researcher sends chill through security community

#328

Earlier quoted context omitted.

Arrest is an early step in a process to prove guilt or acquit. The "burglary" did occur, and a grand jury did examine evidence and determine it was sufficient to start that process.

A couple of your friends get arrested. Do you think about it a little bit?

Whether or not Hutchins' friends are concerned isn't the question. Whether or not the entire security research community are or should be "chilled" is. There's no evidence that he was arrested for being a security researcher. There is evidence that he was arrested because there was probable cause to believe he had committed a crime.

Re: Arrest of WannaCry researcher sends chill through security community

#329

Earlier quoted context omitted.

Okay, so @arthulia and @hueving, is it "good restaurants" or "crappy, over-priced food"? Never been there, but could somewhat imagine either scenario. Actually I could imagine multiple possibilities for each: "good restaurants": (1) lots of top-tier cooks go there because money and it's cheap because Vegas, or (2) lots of off-strip places with good chefs trying to make it big. "crappy, overpriced food": (1) Wolfgang…

Both. There are a lot of chains and mid-grade restaurants where you will pay an arm and a leg for mediocre food. However, there are also some of the best buffets in the world there (if you're into that). There are also some awesome high-end restaurants: https://www.tripsavvy.com/michelin-guide-rated-restaurants-l... Because Vegas is a massive tourist destination where you are guaranteed to have a deep market of peopl…

There are lots of high-end restaurants, because every celebrity chef in America seems to open an outpost there. But if you're familiar with the originals, the Vegas versions tend to be overpriced tourist versions with limited menus. There are some great restaurants to be sure, but it's kind of a dice roll.

We've gone off the strip for sushi, Korean bbq, Thai, and Ethiopian and had good luck; I don't know enough about greater Las Vegas to judge it. But the strip is bad.

Re: Arrest of WannaCry researcher sends chill through security community

#330

Earlier quoted context omitted.

Yes? Of course it would?

I guess I'm looking at it like this: 1. Someone physically breaks into factory, steals a list of customers for the purpose of (selling to competitors/personal interest) 2. Someone drives around the country and records locations of $company infrastructure, in an industry where optimal placement provides a major competitive advantage, for the purpose of (selling to competitors/personal interest) In both cases, the pers…

There are two elements to almost every crime in the US criminal justice: conduct and intent. Without provable intent, inappropriate conduct is often excused. Without inappropriate conduct, predatory intent is almost never prosecutable.

Your first case has both prohibited conduct and intent (actually, with or without the intent to sell the data, I think deliberately breaking into a factory is itself criminal).

Your second case does not.

Post reply on HN