Earlier quoted context omitted.
Yes, that's what they're saying. Consider the source.
I'm not convicting him, and if you put a gun to my head and forced me to render a verdict based on what's public now, I'd say "not guilty". What do you want from me? Cases like this unfold over time. We don't get to know everything we want to know the moment we want to know it.
Arrest of WannaCry researcher sends chill through security community
111–120 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#112Earlier quoted context omitted.
"can we name anyone who has been prosecuted for what turned out to clearly be benevolent research work?" Randal Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz
Yeah, I think you'll find when you dig into the details that that case is not a great example for you.
Re: Arrest of WannaCry researcher sends chill through security community
#113Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.
> Seleznev, the identity thief who is the son of the Duma deputy, chose to vacation at a five-star resort in the Indian Ocean archipelago nation of the Maldives in 2014 precisely because it has no extradition treaty with the United States. U.S. officials got word and persuaded Maldives authorities to intercept Seleznev at the airport, where in a fast-paced operation he was bundled on a private plane to Guam
Personally - I think in this Hutchins case they just wanted a new hire.
http://hamodia.com/2017/04/02/u-s-sweeping-russian-hackers-b...
Re: Arrest of WannaCry researcher sends chill through security community
#114Earlier quoted context omitted.
Yeah, I think you'll find when you dig into the details that that case is not a great example for you.
Instead of doubt, can you give us concrete reasons?
It's not the crime of the century, but it's not a case of someone doing benevolent security research getting caught. Nobody practicing today would backdoor a client computer, use the backdoor after their engagement had ended, and expect anyone to find that action defensible.
Re: Arrest of WannaCry researcher sends chill through security community
#115Earlier quoted context omitted.
I'm not convicting him, and if you put a gun to my head and forced me to render a verdict based on what's public now, I'd say "not guilty". What do you want from me? Cases like this unfold over time. We don't get to know everything we want to know the moment we want to know it.
The parent post thread is about why researchers were afraid as a result of the arrest. While it might unfold and get a not guilty, in the mean time he's in jail. If you were a malware researcher with good intentions, you might rightly think it's a mistake and one that could get you in the same kind of trouble.
Re: Arrest of WannaCry researcher sends chill through security community
#116As someone who's not sure where I stand on this, I feel like Hutchins supporters are doing themselves a disservice by overly-conflating this with WannaCry. I think there's potentially a good argument to be made along the lines of "Hutchins good work w.r.t. WannaCry is the only reason that anyone (including law enforcement) is aware of semi-historical Kronos, so going after him for Kronos is equivalent to going after…
I don't think that's what these researchers are saying. I think they are saying more along the lines of: "Hutchins has shown that he is a security researcher through his work on wannacry. As a security researcher, he probably has researched other problems as well, possibly including Kronos. The fact that he was arrested with little to no evidence could be showing that the DOJ is willing to arrest people who have copi…
W.r.t. the latter, I'm not saying that the DOJ should have had him arrested if it lacks serious evidence of his guilt. I'm saying that his arrest has happened; it's too late to stop it. The question is whether it should have happened, and, since we're highly unlikely to be able to change anything within a few days, it seems like it makes sense to wait a few days before asserting that the DOJ lacked evidence to support the arrest if only to avoid poising the well. If it turns out that they didn't have any evidence, then the arrest was a problem which needs to have consequences. But I think being over-eager at this point greatly lowers the probability of there being any such consequences.
Re: Arrest of WannaCry researcher sends chill through security community
#117Earlier quoted context omitted.
> He's not a "hacker" who is doing security research, he's a malware creator selling malware. There's no reason he can't be both. We can both like him for stopping WannaCry, and dislike him for (if true) marketing/distributing malware based on Kronos. Although I agree with your general sentiment, I'm confused as to why the security community is chilled by this. The court case should be public, so we'll be able to jud…
>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.
Re: Arrest of WannaCry researcher sends chill through security community
#118Earlier quoted context omitted.
You think the FBI is going to interdict a computer criminal before they spend a week in Las Vegas associating with computer security professionals, any of whom could be criminal co-conspirators?† That would be exceptionally nice of them, but also extremely poor investigative practice. I will say, though, as one of the many people in my field that is bone-tired of schlepping out to the worst place in the United States…
So I take it you're not a fan of Vegas?
Re: Arrest of WannaCry researcher sends chill through security community
#119Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
If I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank? In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to re…
Re: Arrest of WannaCry researcher sends chill through security community
#120Earlier quoted context omitted.
Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…
If the government has evidence, he should be charged and tried. And that appears to be what's happening here.