Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

311–320 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#311
post #224

Earlier quoted context omitted.

>People love to talk about how the FBI has a history of framing people --- and in other fields they might. But there is no track record I'm aware of for the FBI to make up a story like this out of whole cloth. No? It is fairly common in Terrorism cases. I fail to see why they could not do it for Cyber Crime as well https://www.techdirt.com/articles/20120917/05193620404/fbi-c... https://www.nytimes.com/2016/06/08/us/f…

> Want more? Well, yes, since none of those are actually examples of the FBI framing anyone. Stings are not the same thing as framing, no matter how much sarcasm techdirt uses to describe them. A sting is law enforcement creating a situation where someone can demonstrate clear evidence of their intent to break the law. Framing is law enforcement MANUFACTURING evidence that someone broke or intended to break the law.…

>In the terrorism cases, a sting would be the FBI giving someone a fake bomb

No that should be entrapment

A Sting is where they get a tip that criminal action might be happening and they are there to catch the criminals in the act

Not where the FBI creates the plan, induces people into the plan, provides support for the plan, provide materials for the plan, then arrests everyone.

That is or should be considered entrapment, which I also consider framing someone

Re: Arrest of WannaCry researcher sends chill through security community

#312

Earlier quoted context omitted.

>The fear of unjust accusation is still valid. Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.

> If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers. How do you know that it doesn't? White hats are counterintel agents effectively. If a counterintel agent is arrested for doing something that could be deemed as part of his job, why wouldn't it 'send a chill' through the community?

No they aren't.

Re: Arrest of WannaCry researcher sends chill through security community

#313

Earlier quoted context omitted.

"White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. People on this thread have a lot of strange ideas about what infosec people do in their jobs.

> "White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it. And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.

For the Nth time in this thread: watch the video of the software we're talking about. "White hats" do not build things like that all the time.

Re: Arrest of WannaCry researcher sends chill through security community

#314
post #285

Earlier quoted context omitted.

While the tools, methods and knowledge might be similar or the same... to say "the thinnest of lines between the two" exists is a bit disingenuous. There is a MASSIVE difference between researching security holes... and then selling the exploits for those security holes or tools that use said security holes. Again... if the chatter here is accurate, he's not being "arrested" for research... he's being arrested for to…

What if it turns out that his "co-conspirator" stole and sold his PoC malware? We're talking about thieves and fraudster after all so this doesn't seem like it is outside of the realm of possibility. The only proof to the contrary would be if Hutchins profited from the sale of the malware. Writing malware should not, in and of itself, be a crime. Security researchers need to create proof of concept programs in order…

Then he'll have an extremely strong defense at trial, and the DOJ will be wasting its time. Which is why it's a little bit unlikely that that's what happened.

Re: Arrest of WannaCry researcher sends chill through security community

#315

Earlier quoted context omitted.

He makes great points, but I intuitively feel like certain acts of creating and selling malware should be illegal, even if only by the spirit and not the letter of the law. If someone manufactures guns, doesn't register them, and knowingly sells them to street gangs, it kind of seems like they're aiding and abetting illegal activities for profit. Of course there are instances of selling malware you created to parties…

Some malware uses libcurl. Does that make its creator a criminal?

Obviously not.

Re: Arrest of WannaCry researcher sends chill through security community

#316

Earlier quoted context omitted.

Writing malware is not a crime. Using it is. What gets me about this case is that, if I understand it correctly, he is being punished for writing software. I've read the indictment but we'll have to wait and see how the government argues its case when this comes to trial.

If you read the indictment then you’d know he was arrested for selling the trojan and conspiracy, not for writing it.

If you read the indictment then you'd know he's arrested for writing the software as a step to conspiring, not for selling it.

Re: Arrest of WannaCry researcher sends chill through security community

#317
post #311

Earlier quoted context omitted.

> Want more? Well, yes, since none of those are actually examples of the FBI framing anyone. Stings are not the same thing as framing, no matter how much sarcasm techdirt uses to describe them. A sting is law enforcement creating a situation where someone can demonstrate clear evidence of their intent to break the law. Framing is law enforcement MANUFACTURING evidence that someone broke or intended to break the law.…

>In the terrorism cases, a sting would be the FBI giving someone a fake bomb No that should be entrapment A Sting is where they get a tip that criminal action might be happening and they are there to catch the criminals in the act Not where the FBI creates the plan, induces people into the plan, provides support for the plan, provide materials for the plan, then arrests everyone. That is or should be considered entra…

If I ask the FBI for a bomb and they give it to me and then arrest me that isn’t entrapment. That’s me being a jackass.

If the FBI put cocaine in my car and then pulled me over, that’s framing.

I’m not entirely sure what either of these things have to do with getting arrested for creating and selling exploits.

Re: Arrest of WannaCry researcher sends chill through security community

#318
post #206

Earlier quoted context omitted.

Why is there a tone that he's already found guilty without a trial?

> Hutchins is accused... i thought it was pretty clear

Consider the context.

From the context, it looks like that particular snippet was posted as a counter to the notion that researchers should be concerned about false accusations happening due to the possibility of their work being misconstrued as the activities of a black hat hacker.

To post that as if to dismiss those concerns, is definitely tending toward the tone that piiie is talking about. While you are right to point out the word "accusation" is used, not guilt, the tone still comes through when you consider the context.

Re: Arrest of WannaCry researcher sends chill through security community

#319

Earlier quoted context omitted.

> "White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it. And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.

For the Nth time in this thread: watch the video of the software we're talking about. "White hats" do not build things like that all the time.

So, to make an analogy representing your position:

Watch the video of this horrendous deadly baseball bat attack. Baseball players do not bludgeon people to death with bats all the time. Therefore, baseball players should never worry that they might be falsely accused of an attack. Oh, and the crime was horrible, so that means the evidence must be pretty good. Q.E.D.

Re: Arrest of WannaCry researcher sends chill through security community

#320
post #84
post #47

Earlier quoted context omitted.

Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

> It bears mentioning that accused does not mean convicted.

Of course it does. But the subject here is whether the indictment should cause a "chill" in the security community. Nothing he did in his legitimate research is related to the indictment.

This is like saying Hans Reiser's arrest would have had filesystem authors afraid of the government.

Post reply on HN