Live data from Hacker News

Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

wired.com

11–20 of 69 posts

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#11

This is a bit over the top. He is not a master hacker who "saved the Internet"; He accidentally neutered WannaCry by registering a domain he found in the binary, which as it turned out, acted as a kill switch.

> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…

>Nothing accidental about that.

He didn’t know it was the kill-switch domain, seems pretty accidental to me.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#12

This is a bit over the top. He is not a master hacker who "saved the Internet"; He accidentally neutered WannaCry by registering a domain he found in the binary, which as it turned out, acted as a kill switch.

> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…

He didn't know it was the kill-switch domain. He expected it would enable him to kill the malware, though, and was trying to figure out how to send the kill command before it turned out that simply sitting a server behind the domain was enough to kill it.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#13
post #11

Earlier quoted context omitted.

> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…

>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.

isn't the first thing anyone would do when coming across such a domain in a malware binary to check it is claimed (and if not then who here wouldn't register it (even just if to see what happens)?) I mean we can argue over the semantics of accidental, but imo you can't accidentally register a domain?

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#14
post #2

Hutchins was busted for committing bank fraud. Him doing one good thing does not absolve him of having committed another crime...he's still a criminal. Rather than protest him being arrested we should advocate for him getting a reduced sentence for having at least done some good.

Shouldn’t the system be set up to reward the good thing more than the bad thing when possible? If someone is in a position of power from doing bad things, how could you expect them to stop of their own volition?

One problem with rewarding an action is that humans are very good at gaming rules. For example, let's say I get X for donating to charity. I can for example setup my own charity, donate to it, pay myself all its income as salary and then just collect lot's of X.

The US tax system is a perfect example of this I'd say.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#15
post #2

Hutchins was busted for committing bank fraud. Him doing one good thing does not absolve him of having committed another crime...he's still a criminal. Rather than protest him being arrested we should advocate for him getting a reduced sentence for having at least done some good.

Shouldn’t the system be set up to reward the good thing more than the bad thing when possible? If someone is in a position of power from doing bad things, how could you expect them to stop of their own volition?

That logic doesn't make sense. Everyone has the potential to do something bad. If you have a concealed carry firearm with you, should you get rewarded for not shooting someone on a particular day?

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#17

Earlier quoted context omitted.

> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…

He didn't know it was the kill-switch domain. He expected it would enable him to kill the malware, though, and was trying to figure out how to send the kill command before it turned out that simply sitting a server behind the domain was enough to kill it.

Nobody ever knows something until they do it. I don't understand what are you trying to say.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#18

Earlier quoted context omitted.

> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…

He didn't know it was the kill-switch domain. He expected it would enable him to kill the malware, though, and was trying to figure out how to send the kill command before it turned out that simply sitting a server behind the domain was enough to kill it.

I mean, how does one solve a problem with unknowns? You try different things until you make some progress and work from there. Turns out he didn't have to do more than registering the domain but just because the problem turned out to be simple to resolve, doesn't make solving it an accident.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#19
post #11

Earlier quoted context omitted.

> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm…

>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.

His goal was to kill the malware. Registering the (unclaimed) domain in the binary was supposed to be step 0 to this. Such a domain would almost certainly act as a control center of some sort. You can claim it while it's still available and analyze the malware or even just the traffic reaching your domain to try and neuter it. Even if there's no killswitch, maybe sending invalid data will cause the malware to malfunction and effectively stop its spread for example.

The fact that just registering the domain killed WannaCry wasn't expected, but his intent was to kill the virus from the start, that's no accident.

Re: Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack

#20
post #11

Earlier quoted context omitted.

>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.

isn't the first thing anyone would do when coming across such a domain in a malware binary to check it is claimed (and if not then who here wouldn't register it (even just if to see what happens)?) I mean we can argue over the semantics of accidental, but imo you can't accidentally register a domain?

i totally agree. most of innovation is "i wonder if..." and then you do something and see what happens. him registering the domain was based on research, it killing wanacry was based on research and a bit of luck, just like most things
Post reply on HN