13 ms·
Researcher Who Stopped WannaCry Ransomware Detained in US After Def Con
- deleted 9y ago[deleted]
- cnkk 9y agoyeaaah let us arrest the good guys...
- suyash 9y agoIn the eyes of the court, there is no good or bad, only law if followed based on evidence.
- tanderson92 9y agoIn fact the court is concerned with justice, which absolutely depends on good and bad as opposed to the strictures of the law.
- coldtea 9y agoIn the magical fairyland, yes.
- hota_mazi 9y agoJust because you did one good thing doesn't make you a good guy if you've done bad things too. The indictment shows he broke six US cyber laws in 2014 in connection to the Kronos malware, which he created.
- holtalanm 9y agoI'm curious what charges are being brought against him. For all we know, this detention is completely unrelated to WannaCry. We shall see.
- christina_b 9y agoI may be totally off base here but IIRC, before he ran MalwareTech and was a whitehat, he participated (and was an op) in fairly "shady" IRC channels, with his oldest nick I can recall being `Ntoskrnl`, dedicated to malware and malware development which even had a person (Edit3: As pointed out in this thread, that person was `BetaMonkey/TouchMe`) who was selling a variant of a botnet drone client builder. Edit2: From one of the comments below in this thread, the network on which he was present (and was an IRC operator of) was `irc.voidptr.cz` or a variation of that, I could not recall the name of the network at first but when someone mentioned it, I instantly recognized it. If he's who I think he is, I doubt his early background is that clean, despite him being a whitehat now. It is very much possible he is being held because of something related to that and not because of anything related to WannaCry. This was all before he even started running the MalwareTech blog, it's very much possible the FBI decided to look into his background or were already familiar with it prior to him arriving in or leaving the US. That being said, it's possible that I'm mistaking him for someone else in which case I do apologize. I edited the post a bit, to clarify, the first paragraph to the best of my knowledge is certainly true, second one is based on my own speculation so take it with a grain of salt.
- sbarre 9y agoInstead of apologizing for potentially spreading FUD and falsehoods, maybe you should refrain from posting until you have actual facts in hand?
- plopz 9y agoLike the article itself?
- strictnein 9y ago> maybe you should refrain from posting until you have actual facts in hand? Yeah, like the rest of the people commenting here, right? They have all the facts.
- webkike 9y ago
- mholt 9y agoBitcoin wallets associated with WannaCry have been emptied: https://arstechnica.com/gadgets/2017/08/wannacry-operator-empties-bitcoin-wallets-connected-to-ransomware/ https://arstechnica.com/gadgets/2017/08/wannacry-operator-em...
- adad95 9y agoStrange coincidence
- jstanley 9y ago> "I've spoken to the US Marshals again and they say they have no record of Marcus being in the system. At this point we've been trying to get in contact with Marcus for 18 hours and nobody knows where he's been taken," the person added. "We still don't know why Marcus has been arrested and now we have no idea where in the US he's been taken to and we're extremely concerned for his welfare." What the hell? How does something like this even happen? Surely they can't just take somebody away and keep it a secret?
- mholt 9y agoThe next paragraph says it was an FBI arrest.
- jstanley 9y agoSo where is he? It surely can't be secret, regardless of who arrested him?
- rndmwlk 9y agoThey would need to ask the FBI, not the Marshals.
- jstanley 9y agoAnd if the FBI won't say either? https://twitter.com/MabbsSec/status/893146424753500163 https://twitter.com/MabbsSec/status/893146424753500163
- rndmwlk 9y agoI consider that a huge issue. No justifiable reason for that.
- charred_toast 9y agoThe license to for such illegal actions became legal after 9/11. This is nothing new. Police abductions happen in the pretty USA too.
- elorm 9y agoAs much as this article contains very little information,this sounds very much like something the US will do. Whenever someone has to be the butt of some global joke .....somehow the US has to be the one to step up. Taking someone into custody for 18 hours without giving the family or press any information. How different is this from Iran or North Korea? Two things could've happened here IMO. They asked for the domain to turned over to them and were politely refused, or they're about to punish an accidental hero for white hat work/previous black hat work not related to WannaCry
- abhi3 9y agoIn Iran and NK detention without rights is an institutionalized practice. In US if you deny them a phone call immediately, you just threw away your own case.
- astronautjones 9y ago... unless "national security" is cited
- deleted 9y ago[deleted]
- placeybordeaux 9y agoThe patriot act (amazing name) invalidated that statement. Not sure if it applies in this specific case.
- SomeStupidPoint 9y agoThe full name of the "USA PATRIOT" act: > Uniting and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism
- deleted 9y ago[deleted]
- QUFB 9y agoThis sends a clear message to the global whitehat security community: travel to the US at your own peril.
- owlninja 9y agoThere are zero details on this story...calm down..
- pavel_lishin 9y agoThere are absolutely details: > Motherboard verified that a detainee called Marcus Hutchins, 23, was being held at the Henderson Detention Center in Nevada early on Thursday. So at least we know he was detained. This one relies on a friend, so presumably it's "less verified" as far as these things go: > A few hours after, Hutchins was moved to another facility, according to a close personal friend. I don't know if Motherboard has tried to contact Hutchins, though.
- unethical_ban 9y agoDetained for what? You don't know. I mean, I agree, detainment isn't usually the way to make friends, but those are not specific details of the incident.
- tajen 9y agoWe should have overwhelming confidence that people are detained for good reasons. Given US's track record, it is entirely reasonable to think that it's not the case, until demonstrated otherwise by proof brought forward by the agressor.
- deleted 9y ago[deleted]
- pavel_lishin 9y ago> Detained for what? You don't know. That's rather my concern.
- AndrewKemendo 9y ago--
- jessaustin 9y agoAt this point we can certainly hope he hasn't just been disappeared forever.
- sbarre 9y agoSeems like a bad way to go about it.
- awesomepantsm 9y agoYou watch too many movies. FBI doesn't recruit people by kidnapping them.
- deleted 9y ago[deleted]
- kbenson 9y agoOnly if recruited is a euphemism for the LEO version of "given an offer he can't refuse".
- jessaustin 9y agoThey're surprisingly clever, to arrest after DefCon. Typical stupid USA LEOs would arrest ASAP, so the unjust detention could be a cause célèbre hyped up by half the talks.
- 21 9y agoOr maybe they wanted to see what he presents, who he meets there. Could be useful for prosecution.
- fweespeech 9y agoThey may be trying to identify the real identity of the redacted co-conspirator and were cross checking suspects against who he met at DefCon.
- rphlx 9y agoObviously I won't condone everything they do, and internal corruption remains an issue (as we've seen with Bitcoin..), but US LE - at least at the federal level - is certainly not stupid. They have a level of strategic, tactical and technical intelligence that is objectively pretty impressive especially compared to where they were at, say, 20 years ago WRT computer security. That said, it certainly doesn't hurt that some of the highest-profile criminal "masterminds" of the past 3-5 years have had fairly sloppy opsec.
- moomin 9y agoMaybe he violated WannaCry's terms of service. The DoJ are pretty down on that kind of thing.
- occultist_throw 9y agoIndeed. If he didnt get permission to stop WanaCry, then he violated the CFAA. No, a "crime" is not good justification of a different crime. I wish I was making this stuff up, but thank overly-broad '80s laws regarding "access", "permission", and that sort of language which weaponizes EULAs.
- noir_lord 9y agoUK is no better. http://www.legislation.gov.uk/ukpga/1990/18 http://www.legislation.gov.uk/ukpga/1990/18 That thing is 27 years old. Massively over broad. > Section 37 (Making, supplying or obtaining articles for use in computer misuse offences) inserts a new section 3A into the 1990 Act and has drawn considerable criticism from IT professionals, as many of their tools can be used by criminals in addition to their legitimate purposes, and thus fall under section 3A. Basically supplying a disassembler to someone who then uses it for a crime is itself possibly covered for example. It's the possibly that's the problem, when you can't tell if an offence has actually been committed you leave it open for abuse.
- abhi3 9y agoWhy are people in this thread so outraged without knowing any of the facts? For all we know there might be a legitimate charge on which he was arrested. As per him being untraceable, if he was not read his rights then the FBI just jeopardized their own case. If no one knows where he is, it's more likely that it's what Marcus wants at the moment rather than what the FBI wants.
- awesomepantsm 9y ago>If no one knows where he is, it's more likely that it's what Marcus wants at the moment rather than what the FBI wants. Oh come on...
- abhi3 9y agoHe could call his attorney have him release a statement right? Are you saying he is being denied access to a lawyer? Because that's a very serious charge and it would very silly of the FBI. IDK if I were arrested I would pray that the police abuse their power and deny me access to an attorney.
- webkike 9y agoWould you? Would you like them to detain you unjustly for your entire life for example? Personally, I'd prefer the state to act within the bounds of Justice.
- deleted 9y ago[deleted]
- rbritton 9y agoHe is not a US citizen -- do those rights extend to him? (no snark, I don't know)
- QUFB 9y ago> He could call his attorney have him release a statement right? How many people traveling to the US from the UK, just to attend a conference, have an attorney they can call in the US?
- danesparza 9y agoThis reminds me of Kevin Mitnick: https://en.wikipedia.org/wiki/Kevin_Mitnick#Arrest.2C_conviction.2C_and_incarceration https://en.wikipedia.org/wiki/Kevin_Mitnick#Arrest.2C_convic... Do we need to create some "Free Marcus" bumper stickers?
- godzillabrennus 9y agoMet Mitnick in Chicago last year at a bank that was paying him to demonstrate hacks for the audience. His business cards are amazing. I got stopped by security once because it was in my wallet.
- CaptSpify 9y agohttps://www.mitnicksecurity.com/shopping/kevin-mitnick-lock-pick-business-card https://www.mitnicksecurity.com/shopping/kevin-mitnick-lock-... In case anyone else was wondering
- dsl 9y agoMitnick was actually a criminal. He was living off stolen credit cards.
- BenjiWiebe 9y agoDo you have a reference?
- dijit 9y agoI mean. He he wrote a book about it. About how he used the identities of children who died while living across state lines because no record of death goes back to the originating state. And how he used those identities and stole credit cards to survive being chased by the FBI.
- scrapbird 9y ago..do you not know who Mitnick is or something?
- mnm1 9y agoNo good deed goes unpunished. But why is DefCon still in the US? I think the creators of the conference might want to seriously think about holding it somewhere that isn't so hostile to pretty much everyone who attends.
- 893helios 9y agoYou mean like Defcon Beijing?
- mankash666 9y agoNo. Defcon Toronto
- avs733 9y agoDefcon Reykjavik? Bunch of hackers in hotsprings sounds like a party
- rapind 9y agoAt least then we don't have to worry about the FBI... just Bell and Rogers. https://news.ycombinator.com/item?id=14911330 https://news.ycombinator.com/item?id=14911330
- jdright 9y agoThis is surreal, no other words. Like NK.
- btbuildem 9y agoNo thanks, don't want Canada turning into the next US.
- sah2ed 9y agoMoving Defcon to Canada doesn't solve the issue if attendees have to get there via US airspace. Deplaning [0] is a real possibility. [0] https://news.vice.com/story/somali-canadian-forced-off-flight-from-toronto-to-paris-because-his-planes-route-was-through-u-s-airspace https://news.vice.com/story/somali-canadian-forced-off-fligh...
- sajal83 9y agoUK's National Cyber Security Centre on MalwareTech's arrest: "We are aware of the situation. This is a law enforcement matter and it would be inappropriate to comment further." https://twitter.com/josephfcox/status/893160214664445952 https://twitter.com/josephfcox/status/893160214664445952
- QUFB 9y agoWould the UK National Cyber Security Center respond differently if he were detained by law enforcement in Iran?
- tankenmate 9y agoThey'd probably refer you to the Foreign Office in that case.
- daedalbug 9y agothat'll be the 'rapid response' unit leaping into action right there
- deleted 9y ago[deleted]
- rocky1138 9y agoWhy in heaven's name did he travel to the US?
- saosebastiao 9y agoI'm sure he was thinking, "hey, what's the harm? It's a first world country!". Classic mistake.
- deft 9y agoDEFCON. I'm sure a lot of people wanted to see him there. What crime did he commit anyway? There was no reason for him to worry at all...
- sovietmudkipz 9y agoThere is an annual security focused convention going on this week called "Defcon" that many security focused engineers typically attend. Since wannacry was a big thing that happened between this year's con and last year's con, and because Hutchins is a security researcher, I'm sure he was invited to attend if not give a talk.
- hota_mazi 9y agoThat doesn't answer OP's question. Why travel to the US if just three years ago, he broke multiple US cyber laws? Answer: because he's not as smart as he thought.
- thieving_magpie 9y agoremoved, misunderstood parent.
- justboxing 9y ago> Since we're all speculating, No we are not. He was here for Black Hat and DEFCON > Shortly before his arrest, Hutchins was in Las Vegas during Black Hat and Def Con, two annual hacking conferences. Source: https://motherboard.vice.com/en_us/article/ywp8k5/researcher-who-stopped-wannacry-ransomware-detained-in-us-after-def-con https://motherboard.vice.com/en_us/article/ywp8k5/researcher...
- cjsuk 9y agoI'd like to know on what grounds?
- LyndsySimon 9y agoSame here. I reserve judgement until there's more information on the reason for his arrest.
- cjsuk 9y agoExactly. This may be entirely unrelated to wannacry.
- wudangmonk 9y agoI guess not everyone was happy that he stopped Wannacry. US agencies in particular.
- ryanlol 9y agoThis is utter nonsense. He didn't stop Wannacry. The Wannacry devs stopped Wannacry, if he didn't grab the domain it'd have been picked up by some other TI firm within minutes or hours.
- slurppurple 9y agoI mean he had to notice that it was contacting that website, might not have been an obvious thing to look for.
- ryanlol 9y agoNah, this was one of the first things you'd notice. No need to reverse the binary, you see the domain in pcaps when you run it. Registering unregistered domains the malware connects to is a very obvious thing to do, in this case he got "lucky".
- araneae 9y ago
- Traytorz 9y agoI like how this malware writer/researcher claims he "found" the address and "miraculously saved" everyone by grabbing the domain. Not sure why everyone says he isn't the malware writer. What proof do you have that he didn't write it? Maybe he left a trail that you missed.
- tankenmate 9y agoAn extraordinary claim requires an extraordinary proof.
- madez 9y agoYou don't need to proof anything to raise questions. The comment didn't claim anything, it was just a sceptical one. We should cheer those.
- celticninja 9y agoHe found the address in the source code of the ransomware, any researcher could have found it. He even said himself that when he found it in the source code and saw it was unregistered he registered it to see what would happen. As it turned out it stopped infections from occurring. Not to say that he isnt the malware writer but your use of quote marks makes me think you have no idea about what happened and havent looked into it, just made some "wild assumptions".
- Avery3R 9y agoPretty sure it was in disassembled machine code, not source code.
- jtl999 9y agoI have taken the liberty to download a sample of WannaCry and I can see the "killswitch" domain just running strings on the binary. $ strings Downloads/24d004a104d4d54034dbcffc2a4b19a11f39008a575aa614ea04703480b1022c.bin |grep .com __p__commode http://www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com
- samwillis 9y agoThe Guardian has more: https://www.theguardian.com/technology/2017/aug/03/researcher-who-stopped-wannacry-ransomware-detained-in-us https://www.theguardian.com/technology/2017/aug/03/researche... He may have a shady past: According to an indictment released by the US Department of Justice, Hutchins is accused of having helped to spread and maintain the banking trojan Kronos between 2014 and 2015"
- tptacek 9y agoSince he's only been in custody for less than 24 hours, and CNN already has the indictment, presumably the DOJ had his case before a grand jury awhile ago. Which implies that they did not do this on a whim. Since CNN has the indictment, we'll all have it soon enough, and we'll get a look at the basis for the DOJ's claims.
- duskwuff 9y agoDate on the indictment says July 12th. So this has been cooking for a while.
- maxerickson 9y agoIndictment: https://www.documentcloud.org/documents/3912520-Marcus-Hutchinson-Indictment.html https://www.documentcloud.org/documents/3912520-Marcus-Hutch...
- maxerickson 9y agoCNN got the indictment: On Wednesday, 22-year-old Marcus Hutchins -- also known as MalwareTech -- was arrested in Las Vegas for "his role in creating and distributing the Kronos banking Trojan," according to a spokesperson from the U.S. Department of Justice. The charges relate to alleged conduct occurring between July 2014 and July 2015. According to an indictment provided to CNN Tech, Hutchins created the malware and shared it online. http://money.cnn.com/2017/08/03/technology/culture/malwaretech-arrested-las-vegas-trojan/index.html http://money.cnn.com/2017/08/03/technology/culture/malwarete...
- BigChiefSmokem 9y agoTrump's Dept of Justice is out of control.
- downandout 9y agoFYI, if you've committed any form of cybercrime in the previous 3 years (edit: the statute of limitations is 5 years for most federal computer crimes, as pointed out below), you should avoid such conferences in the US for exactly this reason. You probably aren't as smart as you think, and there may be a sealed arrest warrant for you. The FBI waits for these kinds of conferences to do exactly what they did here. Another Las Vegas DEF CON victim was Dmitry Sklyarov [1]. They won't bother with all of the problems associated with international arrest warrants and extradition if they know you're coming to them. [1] https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd https://en.wikipedia.org/wiki/United_States_v._Elcom_Ltd.
- wonderwonder 9y agoIt's actually 5 years and potentially more depending on the specifics. Relevant information begins on the bottom of page 126/213 or 120 using the numbers printed on the pdf. https://www.justice.gov/sites/default/files/criminal-ccips/legacy/2015/01/14/ccmanual.pdf https://www.justice.gov/sites/default/files/criminal-ccips/l...
- downandout 9y agoI stand corrected. It is three years for many federal crimes, but since the CFAA has no specific statute of limitations, you are correct that crimes prosecuted under it use the default number, which is 5 years. On a side note, if you are an international person visiting the US, you do not want to be arrested for a federal crime in Las Vegas...if you think you may be arrested, visit somewhere else. There is no automatic right to bail in the federal system, and the District Court in Las Vegas is notorious for ruling that most non-US defendants are flight risks. That means, at a minimum, you will go through a month-long transfer process (that goes through Oklahoma, regardless of your destination) to get to wherever your federal warrant was actually issued before you are likely to be granted bail.
- vkou 9y agoThis is good advice, but if you think you may be arrested, you should not visit at all.
- openmosix 9y agoIndictment: https://www.documentcloud.org/documents/3912524-Kronos-Indictment-R.html https://www.documentcloud.org/documents/3912524-Kronos-Indic...
- c-slice 9y agoSo there's another individual who was involved as well. I wonder if they've been detained as well.
- featherverse 9y agoThis is some seriously shady shit. The smart bet is we're not getting the whole story. "Buy guns, lock your doors." - Bill Hicks
- c-slice 9y agoThe bitcoin ransom wallets for WannaCry were just emptied today as well. What was the time difference between these two events? It seems possible that Hutchins could have had control of the wallets and fed seized the coins.
- djvdorp 9y agoMaybe this is the reason he did not appreciate people revealing his identity online (basically DOXing him for fun, some journalist did it if I recall correctly). It really sucks when somebody that is trying to do well (stopping the WannaCry Ransomware as he did) is detained, even though we don't know more details at this points, this hits him rather personally and probably not for the good, I am very sorry for him and I hope he gets out soon and that all is well.
- mzs 9y agobetter summary: http://www.reuters.com/article/us-usa-cyber-arrest-idUSKBN1AJ2IC http://www.reuters.com/article/us-usa-cyber-arrest-idUSKBN1A... insightful thread also delving into wannacry: https://twitter.com/3L3V3NTH/status/893181445824446464 https://twitter.com/3L3V3NTH/status/893181445824446464 edit: there is a nice HN discussion already about the bitcoin: https://news.ycombinator.com/item?id=14918545 https://news.ycombinator.com/item?id=14918545
- cromwellian 9y agoReading the indictment, it seems like his partner ratted him out. Curious though, the indictment seems to list the redacted partner as doing most of the incriminating things (posting a video demonstration, advertising the sale on AlphaBay, etc), it merely accused Marcus as being the author and co-conspirator. I wonder if his partner/friend got caught, and plea bargained to turn state's evidence against Marcus.
- ivanbakel 9y agoMakes me wonder if he was involved with criminal intentions - maybe they produced it together as a research project, then the partner decided to sell it? It would explain why he wanted a sample of his own software, if it wasn't just a cover.
- Bartweiss 9y ago> I wonder if his partner/friend got caught, and plea bargained to turn state's evidence against Marcus. I always wonder a bit about how often these things end up like Rubin Carter, with the guilty party turning state's evidence against someone less guilty or entirely innocent. I mean... one presumes there's more evidence generated by being more involved with the crime, as in this case. If you catch whoever is most identifiable and turn them, there ought to be a lot of cases where you're starting with the worst player and cutting them a deal.
- ktta 9y agoI would love to have a game theorist break this down in an understandable way.
- notafurry 9y agoBased on the number of people who are absolutely certain he wouldn't be involved, the circumstantial evidence suggesting he wasn't, and the lack of any solid evidence that he is, I think the smart bet to place is on this being Swatting. In other words, AlphaBay goes down, FBI analyses information and determines Mr. Redacted was responsible for Kronos. They arrest him, and in interrogation, he decides to blame someone else for anything they can't actually prove is him directly.
- dang 9y agoSince https://news.ycombinator.com/item?id=14922563 https://news.ycombinator.com/item?id=14922563 adds significant new information (or at least I assume it does), the discussion can shift there now.
- pyman 9y agoI'm more than happy to discuss this issue here. In my opinion, Marcus Hutchins will spend the next 10 years of his life working for the NSA and reverse engineering malware built by the Chinese. Unless MI5 has other plans.