Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

341–350 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#341
post #144
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

That's absolutely true, but if the DoJ is acting in good faith (they believe they have sufficient evidence of guilt by this person) then is this really a problem? There are good reasons to be cautious, but this particular case is far from decided either way.

Dan Cowhig, prosecuting, also told the court that Mr Hutchins had made a confession during a police interview.

"He admitted he was the author of the code of Kronos malware and indicated he sold it," said Mr Cowhig.

The lawyer claimed there was evidence of chat logs between Mr Hutchins and an unnamed co-defendant - who has yet to be arrested - where the security researcher complained of not receiving a fair share of the money.

http://www.bbc.com/news/technology-40833951

Re: Arrest of WannaCry researcher sends chill through security community

#342
post #27
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

I think people who write malware to steal banking info should be prosecuted when possible. It will be interesting to see whether this goes to trial and if so how solid any evidence against him is. However, I do not doubt that a mix of fear & incompetence could have resulted in his arrest as much as any concrete evidence of his involvement in Kronos. I think there's (perhaps rightfully) a culture of distrust and paran…

> I think people who write malware to steal banking info should be prosecuted when possible.

If I write a program that can steal banking info, what law have I broken? Isn't it only the actual theft that's a crime?

Re: Arrest of WannaCry researcher sends chill through security community

#343

Earlier quoted context omitted.

"White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. People on this thread have a lot of strange ideas about what infosec people do in their jobs.

> "White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it. And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.

You are suggesting he spent time and energy to build a proof of concept whose explicit task was to demonstrate banking theft from browsers, and he chose to never release it but keep it secret, and a friend decided to sell it on the dark web?

And as a malware researcher when he became aware that his proof of concept was indeed being used to conduct fraud, he turned a blind eye?

Re: Arrest of WannaCry researcher sends chill through security community

#344
post #285

Earlier quoted context omitted.

While the tools, methods and knowledge might be similar or the same... to say "the thinnest of lines between the two" exists is a bit disingenuous. There is a MASSIVE difference between researching security holes... and then selling the exploits for those security holes or tools that use said security holes. Again... if the chatter here is accurate, he's not being "arrested" for research... he's being arrested for to…

What if it turns out that his "co-conspirator" stole and sold his PoC malware? We're talking about thieves and fraudster after all so this doesn't seem like it is outside of the realm of possibility. The only proof to the contrary would be if Hutchins profited from the sale of the malware. Writing malware should not, in and of itself, be a crime. Security researchers need to create proof of concept programs in order…

There's evidence he knew of Kronos in the wild on his twitter feed. Why wouldn't he alert someone that his research proof of concept had been leaked? Provided the source code to LEA.

Re: Arrest of WannaCry researcher sends chill through security community

#345
post #319

Earlier quoted context omitted.

So, to make an analogy representing your position: Watch the video of this horrendous deadly baseball bat attack. Baseball players do not bludgeon people to death with bats all the time. Therefore, baseball players should never worry that they might be falsely accused of an attack. Oh, and the crime was horrible, so that means the evidence must be pretty good. Q.E.D.

That's not analogous as the Bat was not developed for Bludgeoning. This was software designed to steal money / cause issues regardless of whom sold it. I don't know anyone in infosec that regularly creates fully functional and marketable platforms. It's also different than exploit proof of concepts, as again, this is designed to steal.

We don't know that he created the malware. He is accused of creating it. How hard is it to understand the difference between being accused and being guilty? It's been explained to death here that they are not the same thing.

Re: Arrest of WannaCry researcher sends chill through security community

#346
There's so much strange hand-wringing in a loud subset of the security community. The DoJ has a 93% conviction rate because they pursue strong cases that usually end in a plea-bargain. The FBI aren't spooks. The evidence will become public. If this guy profited off of banking trojans then I, for one, hope he ends up in the clink.

Re: Arrest of WannaCry researcher sends chill through security community

#347
post #338

It's a bit odd you can make a knife or gun and sell it but if you sell malware that's illegal.

What? This makes no sense: you can write software legally & sell it too. But conspiracy is a completely different matter. If you made a gun with a feature to make it a full auto weapon & just assumed people knew what it was, then sold it THAT is more akin to selling malware that was intended to do harm. The bits aren't the issue here, the conspiracy to cause damage with the bits is.

Re: Arrest of WannaCry researcher sends chill through security community

#349

There's so much strange hand-wringing in a loud subset of the security community. The DoJ has a 93% conviction rate because they pursue strong cases that usually end in a plea-bargain. The FBI aren't spooks. The evidence will become public. If this guy profited off of banking trojans then I, for one, hope he ends up in the clink.

The DoJ has a 93% conviction rate because they pressure any target into a plea bargain so they don't have to pursue strong cases.

Re: Arrest of WannaCry researcher sends chill through security community

#350
Why didn't the FBI ask for an extradition to the UK? If the case was solid they should use the proper channel to deal with foreign (supposed) criminals.

When you use this strategy, you deprive the arrested of the right he would have in his country and you add the crazy cost to defend yourself in a US court. So it's possible that the case is not that solid or need some Parallel construction. It's pure speculation but it seems fishy to me.

I can understand the use of shenanigans to arrest previous dictators or very powerful crime lords as a last resort for Justice but here it seems very unfair.

I think we may see a drop of attendee to US conference and/or a drop in tourism.

Post reply on HN