Live data from Hacker News

Arrest of WannaCry researcher sends chill through security community

thehill.com

351–353 of 353 posts

Re: Arrest of WannaCry researcher sends chill through security community

#351
post #343

Earlier quoted context omitted.

> "White hats" do not in fact routinely sell software intended almost solely to harvest financial information from botnets. The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it. And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.

You are suggesting he spent time and energy to build a proof of concept whose explicit task was to demonstrate banking theft from browsers, and he chose to never release it but keep it secret, and a friend decided to sell it on the dark web? And as a malware researcher when he became aware that his proof of concept was indeed being used to conduct fraud, he turned a blind eye?

None of that sounds particularly implausible, to be honest. People build proof-of-concepts for their own amusement. If there's no unique vulnerability to be patched, there's no value to releasing it. People share things with their friends, who are sometimes unscrupulous. And if I found out that software I wrote was being used maliciously, I'm not so sure that my first email would be to the FBI either - especially after this.

The least plausible part of this chain of events is that Kronos, from what I can see, is not a very interesting piece of software - more a tedious exercise in plumbing than an interesting proof-of-concept.

Re: Arrest of WannaCry researcher sends chill through security community

#352

Earlier quoted context omitted.

lets take away the feelings by saying... if someone were to deliberately sell a pair of shoes to someone that they new would attempt to j-walk with their shoes, do you think they should be partially liable for the j-walking? > no.

sentencing is based around severity, change the severity of the situation and we are no longer talking about the same thing.

comment replied to raised the discussion to firearms and murder, which isn't the same as code that is designed to reveal flaws in software.

Re: Arrest of WannaCry researcher sends chill through security community

#353
post #84

Earlier quoted context omitted.

It bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exac…

A white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly…

What about, say, Brian Krebs? According to his blog posts, he hangs out a lot on blackhat/cybercrime forums, particularly Eastern European and Russian (?) ones. He has contact with people there, posing as another blackhat, to lure information from them. It's possible, perhaps, that he also leaves out certain interactions that might cross further into a legal grey area (I'm not saying that he has), benign to his research.

That's bound to set off some alarm bells, somewhere some day, at some agency or bureau.

Now, Krebs keeps a relatively high profile pertaining to his work, so it's not improbable that they think twice when they read who he is, and see he's one of the "good guys" obviously.

But there's a lot of white hat researchers who aren't Internet-famous (in the tech world, not just security). Quite a few by choice, too.

So now they're worried if there's anything they might have done in the past that could get them into this kind of trouble. That is, being charged with something over having done (perhaps legally grey) security research. And yes they'll be given a fair trial, except that it seems that in the US proving one's innocence also depends on whether you have sufficient funds (I feel like I'm stereotyping here, but I see so many people casually mention these scenarios as if it's a given).

And then, being one of the "good guys"--by, say, single-handedly stopping the first wave of a global ransomware epidemic--doesn't seem to warrant a bit more considerate and less aggressive approach any more, either.

So now they're worried!

Post reply on HN