Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

101–110 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#101
I think one factor not being accounted for is cybersecurity is a fairly big priority for law enforcement yet in a very large number of cases they are never able to find or prosecute people responsible. So they need to "make the numbers" to show that they are being effective and the easiest strategy is to go for easy targets.

Re: Arrest of WannaCry researcher sends chill through security community

#102
post #36
post #26

Earlier quoted context omitted.

No I haven't created or sold malware. But i have this; A middle-eastern last name, I use Tor, I use Linux, and I use Telegram, I am active in the field of IT and especially enjoy IT security. I know that I can be held indefinitely if I visit the USA. In the USA you're guilty until proven innocent, unlike the rest of the western world. Simply going to the USA is more risk than it is for practically every other country…

You're commenting on an article about how the FBI arrested someone for creating malware. If you haven't been creating malware, then I don't see how this article has anything to do with the issues you face as someone with a middle-eastern last who uses privacy tools like Tor. Hutchins wasn't targeted because of CBP's stance on things it associates with terrorism. He was targeted because the FBI believes he authored ma…

Believe it or not, it's possible to be suspected or even accused of something you didn't actually do, whether through a misunderstanding or otherwise. And factors such as ethnicity and personal associations can influence the chance of this occurring.

Re: Arrest of WannaCry researcher sends chill through security community

#103
post #93
post #83

Earlier quoted context omitted.

"can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?" Randal Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz

Yeah, I think you'll find when you dig into the details that that case is not a great example for you.

https://w2.eff.org/legal/cases/Intel_v_Schwartz/schwartz_cas...

Seems to be clear example to me

Re: Arrest of WannaCry researcher sends chill through security community

#104
I guess I get the concern but it seems clear the accusation are unrelated to WannaCry and his involvement in another event.

We've seen bumbling investigations and misguided legal threats before... that didn't stop people and this one doesn't seem to yet be either of those.

Re: Arrest of WannaCry researcher sends chill through security community

#105
post #27
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

I think people who write malware to steal banking info should be prosecuted when possible. It will be interesting to see whether this goes to trial and if so how solid any evidence against him is. However, I do not doubt that a mix of fear & incompetence could have resulted in his arrest as much as any concrete evidence of his involvement in Kronos. I think there's (perhaps rightfully) a culture of distrust and paran…

> people who write malware to steal banking info should be prosecuted

I really disagree with you on this. The problem is not the person who researches different exploits (ie who may /write/ the malware) but with the people who /use/ the malware to do bad things.

When we keep preventing white hat researchers from doing their job, there's no defense against black hats.

If he actually sold Kronos for the sole purpose of stealing, I agree that he should be prosecuted. If he only used it for research purposes, this is a complete witch hunt.

Re: Arrest of WannaCry researcher sends chill through security community

#106
post #62
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

You think the FBI is going to interdict a computer criminal before they spend a week in Las Vegas associating with computer security professionals, any of whom could be criminal co-conspirators?† That would be exceptionally nice of them, but also extremely poor investigative practice. I will say, though, as one of the many people in my field that is bone-tired of schlepping out to the worst place in the United States…

So I take it you're not a fan of Vegas?

Re: Arrest of WannaCry researcher sends chill through security community

#107
post #88
post #65

Earlier quoted context omitted.

The FBI claims he created malware, an unnamed co-conspirator is charged with selling it So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. I never take the government word for anything, and generally assume the government is lying at all times. History supports my position. I find it extremely alarming how quickly people just believ…

> So you generally believe people are guilty until proven innocent, and I always believe people are innocent until they are proven guilty. Is indicting people for crimes they are alleged to have committed consistent with your position? Because that's all that's happened so far. The FBI asserts that he created malware. He denies it. An indictment and a trial will figure out which of them is lying.

That's one thing that might happen.

Another is that he might plead guilty and we'll never know whether he was guilty or innocent (but threatened with consequences he didn't feel he could risk).

Re: Arrest of WannaCry researcher sends chill through security community

#108

Is it me or the DOJ so the flight manifest and then went to a grand jury to indict? He did what he did in 2014-2015 and the charges were filed in July 2017, a couple of weeks before Defcon...

If that is the case, it would not be remarkable. Prosecutors have a responsibility to only pursue cases that are likely to result in conviction. If extradition was considered impossible, then there would not be much point in pursing an indictment.

I honestly assume that there's a "list of foreigners we'd like to prosecute" that the US gov't checks visa applications against.

Re: Arrest of WannaCry researcher sends chill through security community

#109
post #20

If your code is used in an exploit and that is now a punishable crime, maybe next the NSA will be in the hot seat since the code that was used in wanacry was their own. Or perhaps Israel for their effort in Stuxnet. I hope he takes it to trial and we find out what is really happening here. Pretty suspicious that this happens years after the fact and only weeks after he helped prevent the further spread of wannaCry. W…

Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?

Yes, the seller would legally be an accessory to the murder, having had knowledge that the crime would be committed and having helped the murderer commit it.

https://en.wikipedia.org/wiki/Accessory_(legal_term)

Re: Arrest of WannaCry researcher sends chill through security community

#110
post #100
post #64

Earlier quoted context omitted.

We don't know whether he did or not. But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. And there very well may be evidence, especially if the timing is related to something new obtained from the Alpha Bay takedown and it happening when he happened to visit the US for DEFCON was a coincidence.…

> But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. Is this just for alleged computer crimes, or would you apply that to all alleged crimes? For example, suppose I run a fraudulent mail order business targeting people in, say, France, and this is a crime in France. Would you argue that if I vi…

I think that a Black Hat convention that attracts many federal employees who work in computer security should be especially sensitive to "snatch and grab" operations.

The pall which is descending over foreign attendees is a harbinger of either relocation or vastly reduced attendance.

Post reply on HN