Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

281–290 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#281
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

There is a due process to catch an ally's civilian, that's called an extradition, that process is important.

The parties involved probably judged correctly that if they attempted to extradite him, he would be the subject of a prolonged media campaign against the government in the UK to keep him here.

What I don't understand is why the FBI didn't just hand the evidence to the NCA in the UK and have them arrest him.

Re: Arrest of WannaCry researcher sends chill through security community

#282
post #261

Earlier quoted context omitted.

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

This is complete nonsense. Maybe there is a case that buying malware is a reasonable thing to do in some circumstances. Selling your own malware is a different thing. That seems a pretty clear boundary.

"The indictment does not say Hutchins designed Kronos to be sold, knew about the sale or was at all aware his work was being used maliciously. "

A person he knew, or he was in touch with sold the said trojan. The indictment also doesn't say if he did gain financially from the sale or not.

So, he developed a trojan possibly for research, someone he knew sold it and he got arrested.

Re: Arrest of WannaCry researcher sends chill through security community

#283
post #274

Earlier quoted context omitted.

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

Wait, what? How does a person accused of development and direct distribution of malware qualify as a white hat? Because he pulled the plug on some ransomware and put his name in global households? There are a lot of logic jumps here that you have simply glossed over.

The same way someone accused of murder qualifies as not-a-murderer.

"Accused" just means someone said it, it doesn't make it true.

Re: Arrest of WannaCry researcher sends chill through security community

#284
post #220
post #217

Earlier quoted context omitted.

I'm a pretty big fan of firearms. I disagree. If you had knowledge before hand, of the crime, and a reasonable expectation, you are culpable, to some percentage. The law usually agrees with me, if that helps.

I does not, the vast majority of the law I disagree with See I can not support the concept of 3rd party lability. I should only ever be responsible for my actions, not the actions of others, and I have no responsibility or obligation to stop any crime.

> and I have no responsibility or obligation to stop any crime.

You don't have to ask someone if he wants to commit a crime, so that is not the problem. It is when someone explicitly asks for your help in commiting a crime and you think to yourself "yes I want to be complicit in this" that lands you in legal trouble.

If someone asks you for a handgun to kill someone you don't have to stop him, you just aren't allowed to aid him.

I really don't understand how you people seem to be under the impression that not going out of your way to help criminals takes more effort than not. I am more under the impression that you would pull the trigger on your on grandmother if it made you money, since it is not you but the blodloss that finally does her in - degrees of seperation and all that.

Re: Arrest of WannaCry researcher sends chill through security community

#285

Earlier quoted context omitted.

> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…

While the tools, methods and knowledge might be similar or the same... to say "the thinnest of lines between the two" exists is a bit disingenuous. There is a MASSIVE difference between researching security holes... and then selling the exploits for those security holes or tools that use said security holes. Again... if the chatter here is accurate, he's not being "arrested" for research... he's being arrested for to…

What if it turns out that his "co-conspirator" stole and sold his PoC malware? We're talking about thieves and fraudster after all so this doesn't seem like it is outside of the realm of possibility. The only proof to the contrary would be if Hutchins profited from the sale of the malware.

Writing malware should not, in and of itself, be a crime. Security researchers need to create proof of concept programs in order to do their jobs. I don't think that he should get off scott free because someone else handled the actual marketing, sales, etc but if he didn't gain anything from those sales, or fraud perpetrated in connection with the malware, then - having been arrested and indicted and such - he is just as much a victim as those who were infected.

To use your bank analogy, he found a hole in the bank's security. Someone took knowledge of that hole and sold it to some bank robbers who went on to rob the bank. The seller of that information says that he got it from Hutchins. Unless Hutchins got a cut of the sale, did he do anything illegal? Is there anything really connecting him to the robbery other than evidence that he knew about the hole first and the word of the hole seller?

Re: Arrest of WannaCry researcher sends chill through security community

#286

Earlier quoted context omitted.

>the cops couldn't tell the difference is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?

There is evidence that he was a white hat hacker now, and that is enough for current white hat hackers to be worried.

That's a bit like saying there is evidence he is a white male, and that is enough for all white males to be worried.

I.e. not relevant.

Re: Arrest of WannaCry researcher sends chill through security community

#287
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

Which is why he was arrested. He is accused of a crime, and will stand trial.

Unless charges are dropped, of course.

Re: Arrest of WannaCry researcher sends chill through security community

#288
post #41
post #17

I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…

There's a tweet dating back to 2014 [1] where he asks for a sample of Kronos. A number of people have pointed out that would be taking the extremely ridiculously long game for an alibi - why would the author ask for a copy of his own code? There's also little/no published information to back up the statement that he ever sold Kronos. [1] https://twitter.com/MalwareTechBlog/status/48837379416825446...

Anecdotal, but I did things that were a lot more paranoid than "tweeting myself" when I was doing questionably legal things on the internet as a 13 year old.

So to me, tweeting "I want a sample of Kronos" is indicative of nothing.

Re: Arrest of WannaCry researcher sends chill through security community

#289
post #64
post #30

Earlier quoted context omitted.

I might be misunderstanding your point but I don't understand what they did that was so dishonorable? I thought that this guy produced malware

We don't know whether he did or not. But if they have evidence to support arresting him, the US has an extradition treaty with Britain; they should have shared it and asked British authorities to make the arrest. And there very well may be evidence, especially if the timing is related to something new obtained from the Alpha Bay takedown and it happening when he happened to visit the US for DEFCON was a coincidence.…

In what universe does a country not arrest a criminal suspect when they set foot on that country's soil?

Sure, so he was a suspect in a criminal investigation before attending DEF CON. The US doesn't try to extradite literally everyone suspected of a crime from every other country we have an extradition treaty with. Extradition is a pain in the ass so the DOJ decided that it probably wasn't worth their time. Then he comes to the US, he's flagged at immigration, and the DOJ is like "OK, now it's worth our time".

Seems completely acceptable to me.

Re: Arrest of WannaCry researcher sends chill through security community

#290
post #3

Realistically, DEF CON should move to the Caribbean. Marcus Hutchins is a British citizen. Extradition before the event was feasible and would have been a far more honorable path than the snatch and grab that transpired. British security experts might insist on Grand Cayman for any further conferences in the Americas.

I'm pretty sure every year someone arrested because they attended DEF CON. Considering the US are one of the main countries seeking out and arresting cyber criminals why on earth is the main security conference in the world in what could be considered a hostile country. A case of smart people doing stupid things.

Because DEF CON is for whitehats / reformed blackhats so it shouldn't be an issue?
Post reply on HN