Live data from Hacker News

Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

motherboard.vice.com

241–250 of 268 posts

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#241
post #31

No good deed goes unpunished. But why is DefCon still in the US? I think the creators of the conference might want to seriously think about holding it somewhere that isn't so hostile to pretty much everyone who attends.

It's not about his good deed, it's about the fact that he may have been involved with a bank scam Trojan in 2015

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#242

They're surprisingly clever, to arrest after DefCon. Typical stupid USA LEOs would arrest ASAP, so the unjust detention could be a cause célèbre hyped up by half the talks.

Obviously I won't condone everything they do, and internal corruption remains an issue (as we've seen with Bitcoin..), but US LE - at least at the federal level - is certainly not stupid. They have a level of strategic, tactical and technical intelligence that is objectively pretty impressive especially compared to where they were at, say, 20 years ago WRT computer security. That said, it certainly doesn't hurt that some of the highest-profile criminal "masterminds" of the past 3-5 years have had fairly sloppy opsec.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#243

Earlier quoted context omitted.

If you tweet and stop using an account that is what happens and that was a shady group of people in 2013.

pfft. I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech. This is all easily verifiable with google and archive.org. And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592

That just looks like standard IRC bantz though. Do you know if he was actually trying to sell/weaponize the malware he was developing? (I assume he was, given the indictment, but can't hurt to ask.)

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#244

Earlier quoted context omitted.

pfft. I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech. This is all easily verifiable with google and archive.org. And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592

That just looks like standard IRC bantz though. Do you know if he was actually trying to sell/weaponize the malware he was developing? (I assume he was, given the indictment, but can't hurt to ask.)

I'd go with "no doubt" for both. Although I'd assume he'd have loved the $20k if it was actually on the table.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#245

Earlier quoted context omitted.

If you tweet and stop using an account that is what happens and that was a shady group of people in 2013.

pfft. I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech. This is all easily verifiable with google and archive.org. And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592

Sup ryan, remember me? i used to chill on voidptr sometimes too. I don't know why everyone is so surprised by this

"he's a fucking genius because he got us all" https://twitter.com/x0rz/status/893203106338680832

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#246

Earlier quoted context omitted.

There's almost zero chance that he was arrested for stopping Wannacry. I'd guess a 23-year old in that business has a history of "less-than-white-hat" activities...

Wouldn't be surprised if this gets a lot of other people in the field thinking.

That's an interesting position to be in. If you're legit now but you have some past event which might be uncovered, do you approach the DOJ (through a lawyer, of course) to turn yourself in and try to cut a deal, maybe probation and free consulting services for TLAs for a few years, or do you just hope it never comes to light?

Then again, any deal probably means informing on friends and acquaintances of that period and scene. You could try to contact some of them and see if you could go forward together, but then you're setting yourself up for a prisoner's dilemma situation.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#247

Earlier quoted context omitted.

Or you could not make and sell malware, no matter where you are in the world.

Has he been convicted?

Not at all. These are allegations. The indictment itself states this clearly.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#248
post #5

> "I've spoken to the US Marshals again and they say they have no record of Marcus being in the system. At this point we've been trying to get in contact with Marcus for 18 hours and nobody knows where he's been taken," the person added. "We still don't know why Marcus has been arrested and now we have no idea where in the US he's been taken to and we're extremely concerned for his welfare." What the hell? How does s…

>What the hell? How does something like this even happen? Surely they can't just take somebody away and keep it a secret? There's this little thing called the Patriot Act that Bush brought into law after 9/11 that allows the feds to do exactly this.

This. Welcome to the new America.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#249

Earlier quoted context omitted.

If you tweet and stop using an account that is what happens and that was a shady group of people in 2013.

pfft. I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech. This is all easily verifiable with google and archive.org. And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592

> This is all easily verifiable with google and archive.org.

Yes. And I've had a hostile fellow once upon a time put my RL info in the whois and post a bunch of shit on it. I generally give people the benefit of the doubt when its random online public stuff until they are convicted.

The internet "evidence" is way too flimsy to be considered reasonable standards of proof imho.

Re: Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con

#250

Earlier quoted context omitted.

pfft. I used to talk to this guy on a malware dev IRC on a daily basis, he started a blog "TouchMyMalware" which eventually evolved into Malwaretech. This is all easily verifiable with google and archive.org. And lol, apparently some twitter user dug up logs of him offering to sell me a rootkit for $20k https://twitter.com/jeremiahg/status/893207272154734592

> This is all easily verifiable with google and archive.org. Yes. And I've had a hostile fellow once upon a time put my RL info in the whois and post a bunch of shit on it. I generally give people the benefit of the doubt when its random online public stuff until they are convicted. The internet "evidence" is way too flimsy to be considered reasonable standards of proof imho.

Okay, never fear! In that case I will provide you with irrefutable proof.

Navigate to: https://web.archive.org/web/20131031200609/https://twitter.c...

Pick any of the tweets, copy the direct link to that tweet.

You'll end up with something like this: https://web.archive.org/web/20131031200609/https://twitter.c...

Now remove the archive.org part from the beginning: https://twitter.com/TouchMyMalware/status/395862786602827776

Click on the link and boom you're suddenly redirected to https://twitter.com/MalwareTechBlog/status/39586278660282777...

Here's also an archive.org link showing the account with the "TouchMe" name on it: https://web.archive.org/web/20130710045915/https://twitter.c...

Happy?

Post reply on HN