Earlier quoted context omitted.
I think people who write malware to steal banking info should be prosecuted when possible. It will be interesting to see whether this goes to trial and if so how solid any evidence against him is. However, I do not doubt that a mix of fear & incompetence could have resulted in his arrest as much as any concrete evidence of his involvement in Kronos. I think there's (perhaps rightfully) a culture of distrust and paran…
> people who write malware to steal banking info should be prosecuted I really disagree with you on this. The problem is not the person who researches different exploits (ie who may /write/ the malware) but with the people who /use/ the malware to do bad things. When we keep preventing white hat researchers from doing their job, there's no defense against black hats. If he actually sold Kronos for the sole purpose of…
Arrest of WannaCry researcher sends chill through security community
211–220 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#212> It is unclear from the indictment if Hutchins would have been aware his work was being used maliciously The indictment specifically states he sold the malware. Unless he was completely convinced the buyers of Kronos were using it for research into browser malware, it's pretty damned obvious. I'd be interested to talk to malware researchers that are genuinely scared about this.
We dont know what was actually sold, or what was paid for, or who paid for it. Of course the government in a government indictment will states "he sold malware" but the government is known to lie, exaggerate, and use terms incorrectly or out of context when talking about technology. Taking the indictment at face value is IMO extremely naive
Re: Arrest of WannaCry researcher sends chill through security community
#213I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
Why is there a law against selling malware? Couldn't a comparison be made with regards to firearms? He created the malware but didn't deploy it live
Re: Arrest of WannaCry researcher sends chill through security community
#214Earlier quoted context omitted.
Regarding Weev, should planning on selling the data really affect the legality of his behavior? I mean, there are services that sell data they scrape from websites after all.
Yes? Of course it would?
1. Someone physically breaks into factory, steals a list of customers for the purpose of (selling to competitors/personal interest)
2. Someone drives around the country and records locations of $company infrastructure, in an industry where optimal placement provides a major competitive advantage, for the purpose of (selling to competitors/personal interest)
In both cases, the person now has information that the target would rather keep private, and in both I would assume that their plans for the data would be irrelevant to the legality of gathering that data. (I'd assume case 1 would be illegal either way, and 2 legal either way) So if Weev's actions are akin to breaking into/hacking a system, then case 1 would apply - but if it was closer to looking at publicly exposed information, then the situation would be like case 2. But either way, I don't think his reasons for taking the actions (or after the fact plans on what to do with the data) would affect the legality of what he did.
Of course, IANAL and US computer law seems to be completely screwed up so maybe it would matter. I just don't see how.
Re: Arrest of WannaCry researcher sends chill through security community
#215Earlier quoted context omitted.
Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.
The gambling doesn't do much for me, but I'm a drinker and a social smoker. It's hard to put my finger on what's so grating about the Vegas strip, but something about it puts my teeth on edge. It's a really fake and touristy place, and it's not fake and touristy in a pleasant way.
Plus the fact that it works on a plurality of tourists coming through makes it sad.
I leave Vegas with less faith in humanity than I had when I came. It's been a few years though.
Hunter S. Thompson had it right: try to cram as many drugs into your body as possible, seek out the ghosts of America's dead dreams and you may come out with some semblance of spirit intact.
Re: Arrest of WannaCry researcher sends chill through security community
#216Earlier quoted context omitted.
Is it because of the gambling, drinking, or what? I don't gamble but I usually have a decent time visiting good restaurants and maybe seeing a show when I go to DEFCON.
The gambling doesn't do much for me, but I'm a drinker and a social smoker. It's hard to put my finger on what's so grating about the Vegas strip, but something about it puts my teeth on edge. It's a really fake and touristy place, and it's not fake and touristy in a pleasant way.
Re: Arrest of WannaCry researcher sends chill through security community
#217Earlier quoted context omitted.
Yes, take this for an example, if someone were to deliberately sell firearms to someone that they knew would attempt to murder someone with their firearm, do you think they should be partially liable for the murder?
No.
The law usually agrees with me, if that helps.
Re: Arrest of WannaCry researcher sends chill through security community
#218https://twitter.com/ChristyNews3LV/status/893603855266492416
Re: Arrest of WannaCry researcher sends chill through security community
#219Earlier quoted context omitted.
You forgot to mention having the opportunities to electronically surveil his activities while he's physically located in the United States, to attempt to possibly catch him soliciting a plant, bragging to a stripper while drunk, or attempt to catch him in some other questionable activities that they could use as the basis of an arrest or further warrants without having to play their hand as to what they think he's ac…
"Basis of an arrest"? They had an arrest warrant. The complaint I'm addressing is "why did they not arrest him sooner???".
The point I was making RE: "basis of an arrest" is that if you wait for him to do something stupid, like get arrested by local LEO for drunk and disorderly, that gives you cover to approach him in an interrogation and threaten him with prosecution over the malware... unless he agrees to be a witness/informant. Because he's in with local LEO for something innocuous, there's cover.
In the end, they indict him for the malware, which pretty much ruins him from that perspective. Or, perhaps, they already figured he wasn't worth using and it's not above a US Attorney to go after someone well known in order to further their own career...
Re: Arrest of WannaCry researcher sends chill through security community
#220Earlier quoted context omitted.
No.
I'm a pretty big fan of firearms. I disagree. If you had knowledge before hand, of the crime, and a reasonable expectation, you are culpable, to some percentage. The law usually agrees with me, if that helps.
See I can not support the concept of 3rd party lability. I should only ever be responsible for my actions, not the actions of others, and I have no responsibility or obligation to stop any crime.