Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

331–340 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#331
post #261

Earlier quoted context omitted.

This is complete nonsense. Maybe there is a case that buying malware is a reasonable thing to do in some circumstances. Selling your own malware is a different thing. That seems a pretty clear boundary.

"The indictment does not say Hutchins designed Kronos to be sold, knew about the sale or was at all aware his work was being used maliciously. " A person he knew, or he was in touch with sold the said trojan. The indictment also doesn't say if he did gain financially from the sale or not. So, he developed a trojan possibly for research, someone he knew sold it and he got arrested.

This is not the kind of thing you develop for "research". It's extremely boring code that is essentially just a user interface for seeding HTML trojans across a botnet.

This thread gives the impression that people not in the field see some sort of mystique to malware research and development. Malware isn't vulnerability research or exploit development. Most of the malware deployed in the real world is code that virtually anyone on HN could develop, from first principles without any additional research.

That's not true of exploit development, which can be extraordinarily difficult and almost always depends on specialized insider knowledge. There's lots of research reasons to work on exploit code. But that's just not true for the kind of malware we're talking about in this case.

This is important to understand, because the premise of the story is that prosecution over banking trojan malware is having a chilling effect in the industry. It is not. Very few people in the industry build stupid-looking PHP interfaces to HTML injection on botnet victims, not because it's illegal but because it's pointless and dumb and you wouldn't learn anything from doing it.

Re: Arrest of WannaCry researcher sends chill through security community

#332

Earlier quoted context omitted.

> It bears mentioning that accused does not mean convicted. That means it should be even less likely to be "send a chill through the security community"

Accused may not mean convicted, but it probably does mean a year in jail awaiting trial, and at trial, and paying for a lawyer that costs tens of thousands of dollars, maybe hundreds of thousands. They don't give you back your lawyer money if you're found innocent. They don't give you back any job that you may have lost, and they certainly don't give you back the money you would have earned during that time.

He got $30k in bail, the equivalent of a $3k bond if he doesn't just pay it directly himself. The $30k is returned whether or not he's found guilty: it ensures only his appearance in court.

Re: Arrest of WannaCry researcher sends chill through security community

#333

Earlier quoted context omitted.

The "chill" comes from legal activities potentially getting you detained and brought up on charges. That's a real cost, even assuming a perfect justice system that can tell they made a mistake. For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops could…

>the cops couldn't tell the difference is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?

> the FBI isn't a bunch of complete incompetents

It isn't a bunch of complete competents either, forensic hair analysis kerfuffle shows that much.

Re: Arrest of WannaCry researcher sends chill through security community

#334

Earlier quoted context omitted.

He makes great points, but I intuitively feel like certain acts of creating and selling malware should be illegal, even if only by the spirit and not the letter of the law. If someone manufactures guns, doesn't register them, and knowingly sells them to street gangs, it kind of seems like they're aiding and abetting illegal activities for profit. Of course there are instances of selling malware you created to parties…

Some malware uses libcurl. Does that make its creator a criminal?

You're comparing apples and orangutans.

Re: Arrest of WannaCry researcher sends chill through security community

#335

Earlier quoted context omitted.

Yes, the seller would legally be an accessory to the murder, having had knowledge that the crime would be committed and having helped the murderer commit it. https://en.wikipedia.org/wiki/Accessory_(legal_term)

Then shouldn't Hutchins legally be an accessory to uses of the malware to steal money, surveil unsuspecting victims, etc. if it is true that he knowingly sold it to people who do such things?

He might be able to get out of it by arguing that he didn't know about any particular crime they would commit, or that he thought they had good faith reasons to buy the software despite being criminals in general. I think this hinges on exactly what he knew.

Re: Arrest of WannaCry researcher sends chill through security community

#336
post #140

Earlier quoted context omitted.

Again, no contradiction here. There is a fear that a white hat is being accused of black hat behavior. Not a claim. A fear. And a reality that a person (maybe white hat, maybe black hat, we don't know) is being accused of black hat behavior. Nothing surprising here. He may, or may not, be a black hat. The fear of unjust accusation is still valid. We will have to see if the DOJ will share the evidence, and what that e…

>The fear of unjust accusation is still valid. Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.

You're not quite making the right analogous scenario. It's more like if a neighbor you know who has some strong vocal opinions agaist the current regime suddenly gets arrested on some charges like conspiracy to incite revolt. I would be rightful to be afraid of being charged similarly if I had similar beliefs and had knew I'd had similar conversations as my neighbor.

Re: Arrest of WannaCry researcher sends chill through security community

#337

Earlier quoted context omitted.

Then shouldn't Hutchins legally be an accessory to uses of the malware to steal money, surveil unsuspecting victims, etc. if it is true that he knowingly sold it to people who do such things?

He might be able to get out of it by arguing that he didn't know about any particular crime they would commit, or that he thought they had good faith reasons to buy the software despite being criminals in general. I think this hinges on exactly what he knew.

Yes, absolutely. The burden is on the government to prove he knew who he was selling it to and that he knew what they were very likely going to use it for.

Re: Arrest of WannaCry researcher sends chill through security community

#339
post #319

Earlier quoted context omitted.

For the Nth time in this thread: watch the video of the software we're talking about. "White hats" do not build things like that all the time.

So, to make an analogy representing your position: Watch the video of this horrendous deadly baseball bat attack. Baseball players do not bludgeon people to death with bats all the time. Therefore, baseball players should never worry that they might be falsely accused of an attack. Oh, and the crime was horrible, so that means the evidence must be pretty good. Q.E.D.

That's not analogous as the Bat was not developed for Bludgeoning. This was software designed to steal money / cause issues regardless of whom sold it. I don't know anyone in infosec that regularly creates fully functional and marketable platforms. It's also different than exploit proof of concepts, as again, this is designed to steal.

Re: Arrest of WannaCry researcher sends chill through security community

#340

I feel like no one here remembers when Dmitry Sklyarov was arrested under similar circumstances. The US government has no obligation to seek out every potential arrestee no matter where they are in the world for every single crime that the US has laws for. But if the target of an investigation (whether they know it or not) sets foot in the US, then we shouldn't be surprised when they are arrested. And this is just an…

Iceland would be great place if you want freedom, but I doubt the willingness from the current majority of attendees.
Post reply on HN