Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

21–30 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#21
post #10

Sad to see it confirmed that it's not worth the risk going to America to visit DEFCON. I hope they'll host it in Europe someday.. To see no statement by DEFCON on this whole thing is almost equally sad.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

Re: Arrest of WannaCry researcher sends chill through security community

#22
post #7

> It is unclear from the indictment if Hutchins would have been aware his work was being used maliciously The indictment specifically states he sold the malware. Unless he was completely convinced the buyers of Kronos were using it for research into browser malware, it's pretty damned obvious. I'd be interested to talk to malware researchers that are genuinely scared about this.

We dont know what was actually sold, or what was paid for, or who paid for it.

Of course the government in a government indictment will states "he sold malware" but the government is known to lie, exaggerate, and use terms incorrectly or out of context when talking about technology.

Taking the indictment at face value is IMO extremely naive

Re: Arrest of WannaCry researcher sends chill through security community

#23
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

[deleted]

Re: Arrest of WannaCry researcher sends chill through security community

#24
post #9
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

I was just at this past DEF CON. The good majority of attendees were from the United States. It doesn't make sense to move it to the Caribbean. That would cause attendance to drop by a lot, and some other organization would just start another conference in the US, and most people would go to that one.

If our justice system behaves dishonorably, then the world's information security industry should certainly abandon the U.S. We can have our solo conferences, but we can't ask foreigners to risk incarceration for our convenience.

The Bahamas might also be a reasonable choice, as they only declared independence from Britain in 1973.

Re: Arrest of WannaCry researcher sends chill through security community

#25

Is it me or the DOJ so the flight manifest and then went to a grand jury to indict? He did what he did in 2014-2015 and the charges were filed in July 2017, a couple of weeks before Defcon...

The timing does not shock me, it is most likely they flipped someone when they took down Alpha Bay which was recently

Re: Arrest of WannaCry researcher sends chill through security community

#26
post #21
post #10

Sad to see it confirmed that it's not worth the risk going to America to visit DEFCON. I hope they'll host it in Europe someday.. To see no statement by DEFCON on this whole thing is almost equally sad.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

No I haven't created or sold malware.

But i have this; A middle-eastern last name, I use Tor, I use Linux, and I use Telegram, I am active in the field of IT and especially enjoy IT security.

I know that I can be held indefinitely if I visit the USA. In the USA you're guilty until proven innocent, unlike the rest of the western world. Simply going to the USA is more risk than it is for practically every other country. Well, for me, and a lot of people like me.

That's what my comment was about.

EDIT: How is it relevant to the article? Well, he is an IT security specialist who wanted to visit DEFCON. Yes, I understand what he did was wrong, it was his own risk.

Re: Arrest of WannaCry researcher sends chill through security community

#27
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

I think people who write malware to steal banking info should be prosecuted when possible. It will be interesting to see whether this goes to trial and if so how solid any evidence against him is.

However, I do not doubt that a mix of fear & incompetence could have resulted in his arrest as much as any concrete evidence of his involvement in Kronos. I think there's (perhaps rightfully) a culture of distrust and paranoia around law enforcement's interaction with ethical hacking. It's difficult to detach from that when legitimate prosecution happens.

Re: Arrest of WannaCry researcher sends chill through security community

#28
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware.

People think that an innocent white hat hacker could get swept up in this kind of arrest, and there has been so little evidence released, nobody knows what actually happened.

Re: Arrest of WannaCry researcher sends chill through security community

#29
post #21
post #10

Sad to see it confirmed that it's not worth the risk going to America to visit DEFCON. I hope they'll host it in Europe someday.. To see no statement by DEFCON on this whole thing is almost equally sad.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

Was Marcus Hutchins arrested for selling malware online?

Re: Arrest of WannaCry researcher sends chill through security community

#30
post #24
post #9

Earlier quoted context omitted.

I was just at this past DEF CON. The good majority of attendees were from the United States. It doesn't make sense to move it to the Caribbean. That would cause attendance to drop by a lot, and some other organization would just start another conference in the US, and most people would go to that one.

If our justice system behaves dishonorably, then the world's information security industry should certainly abandon the U.S. We can have our solo conferences, but we can't ask foreigners to risk incarceration for our convenience. The Bahamas might also be a reasonable choice, as they only declared independence from Britain in 1973.

I might be misunderstanding your point but I don't understand what they did that was so dishonorable? I thought that this guy produced malware
Post reply on HN