Live data from Hacker News

Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

wired.com

31–40 of 69 posts

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#31
post #28

Title was intentionally misleading before mods updated it. This is a very one-sided article meant to make Hutchins look good. The valuable bit of the article is a a reminder of why it's important not to start being criminal/evil, because it traps you in a postive-feedvack loop of criminality as you feel a need to commit ever-greater criminal acts to cover up past acts. The only escape from this is to create a culture…

I carefully read the entire article and I don't think it made Hutchins look good. But it does describe, accurately in my view, the kind of rationalizations people apply to cross line after line until they see no way out.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#32
post #28

Title was intentionally misleading before mods updated it. This is a very one-sided article meant to make Hutchins look good. The valuable bit of the article is a a reminder of why it's important not to start being criminal/evil, because it traps you in a postive-feedvack loop of criminality as you feel a need to commit ever-greater criminal acts to cover up past acts. The only escape from this is to create a culture…

[deleted]

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#33
post #11

Earlier quoted context omitted.

>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.

His goal was to kill the malware. Registering the (unclaimed) domain in the binary was supposed to be step 0 to this. Such a domain would almost certainly act as a control center of some sort. You can claim it while it's still available and analyze the malware or even just the traffic reaching your domain to try and neuter it. Even if there's no killswitch, maybe sending invalid data will cause the malware to malfunc…

Also, I think the key point to reflect on here, Marcus had the domain knowledge and intuition to know where to start hacking literally within minutes/hours of plugging back in and getting the source.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#34
post #11

Earlier quoted context omitted.

>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.

isn't the first thing anyone would do when coming across such a domain in a malware binary to check it is claimed (and if not then who here wouldn't register it (even just if to see what happens)?) I mean we can argue over the semantics of accidental, but imo you can't accidentally register a domain?

[deleted]

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#35

This is a bit over the top. He is not a master hacker who "saved the Internet"; He accidentally neutered WannaCry by registering a domain he found in the binary, which as it turned out, acted as a kill switch.

> He is not a master hacker

Those who have watched his reverse engineering malware live streams would beg to differ.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#36
post #15

Earlier quoted context omitted.

That logic doesn't make sense. Everyone has the potential to do something bad. If you have a concealed carry firearm with you, should you get rewarded for not shooting someone on a particular day?

the analogy is more like you had a concealed firearm with you and you shot a terrorist. although personally I think time served and probation seems about right.

The proper analog is more like you carry a concealed firearm which you used to shoot an innocent person but then later used it to shoot a terrorist.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#37
post #27

Earlier quoted context omitted.

the analogy is more like you had a concealed firearm with you and you shot a terrorist. although personally I think time served and probation seems about right.

In the UK we stop terrorists with Narwhal tusks https://www.theguardian.com/uk-news/2019/nov/30/narwhal-tusk... What's more interesting on the "good deed - bad deed" ometer is > Among those who pinned down the attacker was James Ford, 42, who is also thought to have tried to save the life of a woman who had been stabbed. Ford was jailed for life in 2004 for the murder of 21-year-old Amanda Champion.

One good deed is not enough to absolve, but one bad deed is enough to condemn.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#38
post #28

Title was intentionally misleading before mods updated it. This is a very one-sided article meant to make Hutchins look good. The valuable bit of the article is a a reminder of why it's important not to start being criminal/evil, because it traps you in a postive-feedvack loop of criminality as you feel a need to commit ever-greater criminal acts to cover up past acts. The only escape from this is to create a culture…

A statute of limitations on hacking laws would also help. There's no reason people should be fearful decades later for stuff they did as (relative if not literal) kids.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#39
post #5
post #2

Hutchins was busted for committing bank fraud. Him doing one good thing does not absolve him of having committed another crime...he's still a criminal. Rather than protest him being arrested we should advocate for him getting a reduced sentence for having at least done some good.

> getting a reduced sentence for having at least done some good. It seems like this is exactly what happened: > On 26 July, 2019, Hutchins was sentenced to time served and one year of supervised release.

Judges comments are included in this short documentary https://youtu.be/vveLaA-z3-o (from 21:26)
Post reply on HN