Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

201–210 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#201

Earlier quoted context omitted.

>the cops couldn't tell the difference is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?

There is evidence that he was a white hat hacker now, and that is enough for current white hat hackers to be worried.

I don't know what these terms even mean. "White hat hacker"? Is that what we call "everyone who does anything in infosec but doesn't sell stolen financial information obtained from botnets"?

The attempt to divide the whole world into "people irrationally attacking 'hackers' and 'the good kind of hackers'" isn't doing anyone any favors.

If Hutchins has nothing to do with a criminal conspiracy to profit from a truly awful banking trojan, then his arrest and indictment is a travesty. But if he does have something to do with it, then his status as any kind of "hacker" should have nothing to do with anybody's take on the situation. I'm not sure how much lower you can go than deliberately making money by stealing bank logins from ordinary people, which is what he's accused of doing.

People love to talk about how the FBI has a history of framing people --- and in other fields they might. But there is no track record I'm aware of for the FBI to make up a story like this out of whole cloth. In every case like it, from NanoCore to Albert Gonzales and Stephen Watt, there's been a basis for the charges.

Re: Arrest of WannaCry researcher sends chill through security community

#202

Earlier quoted context omitted.

Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.

Do you think there should be a market for building/selling malware? I feel like it would aid in zero day disclosures. But it could also incentivize black hats.

Fuck no. Malware and exploits are not the same thing. Anyone can write malware; you just have to have the stones and a broken enough moral compass to make money by immiserating strangers. There is an infinite amount of malware; we don't benefit from its "disclosure".

Re: Arrest of WannaCry researcher sends chill through security community

#203

Earlier quoted context omitted.

You're kidding, right? Looks like slam dunk aiding and abetting wire fraud.

I am not kidding, but rather parroting Orin Kerr, an expert on this subject, who does not think this case is a slam dunk. (Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)

Link to the Orin Kerr article: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.

Re: Arrest of WannaCry researcher sends chill through security community

#204
post #62

Earlier quoted context omitted.

You think the FBI is going to interdict a computer criminal before they spend a week in Las Vegas associating with computer security professionals, any of whom could be criminal co-conspirators?† That would be exceptionally nice of them, but also extremely poor investigative practice. I will say, though, as one of the many people in my field that is bone-tired of schlepping out to the worst place in the United States…

You forgot to mention having the opportunities to electronically surveil his activities while he's physically located in the United States, to attempt to possibly catch him soliciting a plant, bragging to a stripper while drunk, or attempt to catch him in some other questionable activities that they could use as the basis of an arrest or further warrants without having to play their hand as to what they think he's ac…

"Basis of an arrest"? They had an arrest warrant. The complaint I'm addressing is "why did they not arrest him sooner???".

Re: Arrest of WannaCry researcher sends chill through security community

#205
post #106

Earlier quoted context omitted.

So I take it you're not a fan of Vegas?

I have friends who live there and don't want to talk shit about the real city of Las Vegas where people actually live, but the part of Las Vegas that Black Hat and Defcon drag us to every year is probably the worst place in the country.

Whats wrong with Vegas for large conferences? Airport is close by and has daily flights to it from most major cities, hotel rooms are cheap and decent quality. Can you name a better city to have a conference for 20,000 people? Only thing i wish it had was tougher smoking laws. You aren't forced to gamble or drink or partake in whatever debauchery that goes down in vegas.

Re: Arrest of WannaCry researcher sends chill through security community

#206
post #47

Earlier quoted context omitted.

The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

Why is there a tone that he's already found guilty without a trial?

Re: Arrest of WannaCry researcher sends chill through security community

#207

Earlier quoted context omitted.

There is evidence that he was a white hat hacker now, and that is enough for current white hat hackers to be worried.

I don't know what these terms even mean. "White hat hacker"? Is that what we call "everyone who does anything in infosec but doesn't sell stolen financial information obtained from botnets"? The attempt to divide the whole world into "people irrationally attacking 'hackers' and 'the good kind of hackers'" isn't doing anyone any favors. If Hutchins has nothing to do with a criminal conspiracy to profit from a truly aw…

Wen-Ho Lee. Evidence showed that the leaked/stolen documents could only have come from a downstream contractor, not from Lee's lab. And yet the FBI latched on to him and wouldn't let go. Everything you think you know about the case is likely built on flawed reporting fueled by deliberate government leaks. Don't get me started... just know that what you think you know about that case is probably wrong. I was at most of his hearings and watched the judge apologize to him for the DOJ's behavior.

But as you say maybe that's another field. But still skepticism is not without basis imho.

Re: Arrest of WannaCry researcher sends chill through security community

#208
post #21

Earlier quoted context omitted.

Can you elaborate? Have you been creating malware (banking trojans) and selling it online?

Was Marcus Hutchins arrested for selling malware online?

Perhaps, but the possibility of a revenge from a few powerful people annoyed by him shouldn't be discarded at this moment.

The underlying message for the community is "if you stand out in the way and go noticed, your identity will be disclosed and then you got owned". Keeping your real identity safe and your activity low-key on the other hand, will increase the probabilities to pass unnoticed and preserve your actual life and freedom.

Is the wrong message. Nobody will dare to try to be a hero the next time.

Re: Arrest of WannaCry researcher sends chill through security community

#209
post #84
post #47

Earlier quoted context omitted.

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

Which is why he was arrested. He is accused of a crime, and will stand trial.

Re: Arrest of WannaCry researcher sends chill through security community

#210

Earlier quoted context omitted.

Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.

Do you think there should be a market for building/selling malware? I feel like it would aid in zero day disclosures. But it could also incentivize black hats.

There is a market already, the only diff. from this case is who is the end buyer. If you are building a rootkit for Sony Entertainment to use on it's customers none minds much.
Post reply on HN