Arrest of WannaCry researcher sends chill through security community
301–310 of 353 posts
Re: Arrest of WannaCry researcher sends chill through security community
#302Re: Arrest of WannaCry researcher sends chill through security community
#303Earlier quoted context omitted.
> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…
"White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. People on this thread have a lot of strange ideas about what infosec people do in their jobs.
The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it.
And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.
Re: Arrest of WannaCry researcher sends chill through security community
#304Earlier quoted context omitted.
There is a due process to catch an ally's civilian, that's called an extradition, that process is important.
The parties involved probably judged correctly that if they attempted to extradite him, he would be the subject of a prolonged media campaign against the government in the UK to keep him here. What I don't understand is why the FBI didn't just hand the evidence to the NCA in the UK and have them arrest him.
Re: Arrest of WannaCry researcher sends chill through security community
#305Earlier quoted context omitted.
>The court case should be public, so we'll be able to judge the evidence ourselves. Well this is still the United States, so by law it will be. People are blowing this way out of proportion as if he were disappeared by the secret police or something.
I think the worry here is that he now has no way of returning to the U.K. where he earns his income. He is stuck in jail in the US without reasonable access to a good lawyer (an appointed lawyer won't understand this case). His outcome looks bleak, guilty or innocent.
Though I am not sure even if on bail if has access to his computers?
Re: Arrest of WannaCry researcher sends chill through security community
#306Earlier quoted context omitted.
> There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. There is only the thinnest of lines between the two. White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be neces…
White hats have to traffic in I feel like you're changing the terminology here in order to confuse the pretty clear lines. Obtaining and analysing != creating and selling.
Re: Arrest of WannaCry researcher sends chill through security community
#307I've read a few articles but I feel like I'm missing something. What's with the sensational quotes like "I had folks afraid that their own involvement in investigating WannaCry would get them arrested."? Everything I've read points that he created banking Malware "Kronos" which was sold on various "underground forums" (whatever that means). What's with the WannaCry conspiracies? He wasn't arrested for being a securit…
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware. People think that an innocent white hat hacker could get swep…
Re: Arrest of WannaCry researcher sends chill through security community
#308Earlier quoted context omitted.
I don't know what these terms even mean. "White hat hacker"? Is that what we call "everyone who does anything in infosec but doesn't sell stolen financial information obtained from botnets"? The attempt to divide the whole world into "people irrationally attacking 'hackers' and 'the good kind of hackers'" isn't doing anyone any favors. If Hutchins has nothing to do with a criminal conspiracy to profit from a truly aw…
>People love to talk about how the FBI has a history of framing people --- and in other fields they might. But there is no track record I'm aware of for the FBI to make up a story like this out of whole cloth. No? It is fairly common in Terrorism cases. I fail to see why they could not do it for Cyber Crime as well https://www.techdirt.com/articles/20120917/05193620404/fbi-c... https://www.nytimes.com/2016/06/08/us/f…
Well, yes, since none of those are actually examples of the FBI framing anyone. Stings are not the same thing as framing, no matter how much sarcasm techdirt uses to describe them.
A sting is law enforcement creating a situation where someone can demonstrate clear evidence of their intent to break the law. Framing is law enforcement MANUFACTURING evidence that someone broke or intended to break the law.
In the terrorism cases, a sting would be the FBI giving someone a fake bomb and that person trying to blow people up. Framing would be the FBI arresting someone and falsely claiming they found a bomb and plans for the local stadium in the persons's house. It's an important distinction. In the former case, the person clearly tried to kill people while in the latter case they did not.
Re: Arrest of WannaCry researcher sends chill through security community
#309Earlier quoted context omitted.
> The point the poster was making is that the US happily arrests foreigners who set foot in the US and regardless of your guilt or innocence you get trapped in the US justice system which is essentially a system to tie you up in court and legal processes that you cannot afford so that you accept a plea deal, possibly for something you have not done, because otherwise you face never seeing the outside world again. Any…
Good to see he definitely violated US law. If I had created “Kronos” I sure as fuck would not head to defcon, but then I’m too paranoid to even download Tor, let alone put myself on the radar of the FBI. His arrest proves my thoughts for a while; the US is not a safe place to travel to - the legal system will destroy you should you be accused of any crime, and as a foreign person you have even fewer rights than a US…
I'm honestly surprised by this reaction to his arrest. He may turn out to be innocent, but it's not like US authorities are grabbing random foreigners off the streets and applying arbitrary charges here. They (per the reporting so far) have evidence connecting him to Kronos in a criminal way (not as a researcher). He's in the US. They have enough to believe they can charge him and prove their case. Why would they not arrest him? Your country would almost certainly do the same to any foreigner who they believed violated their laws and still entered your country.
Re: Arrest of WannaCry researcher sends chill through security community
#310Earlier quoted context omitted.
Given his life style at Vegas and that he didn't even attend the conference, just went there for partying and meetups, the "chills" are different to the "chills" one would assume from reading the headline. http://www.dailymail.co.uk/news/article-4762608/Marcus-Hutch... They just caught another criminal hacker who was stupid and earned a lot of money from his Kronos hacks. The one chill is how stupid was he? Lamborghi…
If you're not from the UK, just take everything the Daily Mail prints with a gain ( well, a handful ) of salt.