13 ms·
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannac
by NateyJay 9y ago
The concern is that a lot of behaviour that a security researcher would do in the course of their research, taking over C&C server addresses such as with Wannacry, soliciting for samples of malware, such as Hutchins did with the Kronos trojan, and having contacts with black-hat hackers, might look to the DOJ as if he is the culprit who created the malware.
People think that an innocent white hat hacker could get swept up in this kind of arrest, and there has been so little evidence released, nobody knows what actually happened.
- tptacek 9y agoHutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
- cargo8 9y agoIf I write open source code for research, share it with the community, and someone wants to license it for "further research" and pays me – am I responsible if their adapted software is then used / stolen / re-applied to kill people or hack a bank? In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to require direct knowledge of malicious intent of the software in the sale.
- tptacek 9y agoIf you know the person licensing it from you is going to use it to steal financial information, and the clear purpose of the tool you've built is to steal financial information, then I would say you should definitely make sure you have a criminal defense lawyer you trust and can afford.
- uyhso8 9y agoI don't think anyone would disagree with what you just said, but given the way prosecutors deal with "intent" sometimes, I think it would be easy for them to cross a line. If you haven't already, listen to this podcast about Doug Williams and polygraphs: https://www.thisamericanlife.org/radio-archives/episode/618/mr-lie-detector https://www.thisamericanlife.org/radio-archives/episode/618/... There's a lot of parallels and how issues of intent can get very grey.
- tptacek 9y agoThey're required to prove intent at trial.
- travmatt 9y agoAs I understand it this is the crux of the case - that the creation of such software isn't illegal, but sale with the intent to be used in the commission of a crime is. I understand the indictment is pretty barebones, so I wonder what exactly they are basing their allegations of intent on.
- deleted 9y ago[deleted]
- hmahncke 9y agohonest question: if your code is open source, why would someone pay you for further research? why would you charge for that?
- cargo8 9y agoI was being a bit of a devil's advocate, altho didn't quite get the responses I hoped for. I suppose I didn't phrase it quite right since I don't have significant knowledge about this case other than the article. It seems like the arrest is a bit aggressive, but so is the response – clearly out of fear and uncertainty of the govt and general time we live in. Hopefully more transparency will bring light to the allegations and reassure the innocent of their safety
- natch 9y agoIt bears mentioning that accused does not mean convicted. The DOJ record as far as accusations turning out to be grounded in reality is not unblemished. >Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright. You say that as though you are contradicting NateJay. But the fear NateJay is highlighting is exactly that a white hat is being accused. And that (whether ultimately borne out in this case, or not) this kind of thing could happen to people who are conducting innocent security research.
- notatoad 9y agoA white hat is being accused of black hat behaviour. There is no indication that the government is seeking to charge him with any activities related to behaviour that could be interpreted as "white hat" in any way. He's accused of creating and distributing malware. He may be found innocent of that, but the crimes he is accused of are very definitely crimes, and he shouldn't get a pass just because he's been publicly acting as a white hat. If the government has evidence, he should be charged and tried. And that appears to be what's happening here.
- tptacek 9y agoWell. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.
- AlexCoventry 9y agoYou're kidding, right? Looks like slam dunk aiding and abetting wire fraud.
- tptacek 9y agoI am not kidding, but rather parroting Orin Kerr, an expert on this subject, who does not think this case is a slam dunk. (Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)
- loeg 9y agoYes, that's what they're saying. Consider the source.
- tptacek 9y agoI'm not convicting him, and if you put a gun to my head and forced me to render a verdict based on what's public now, I'd say "not guilty". What do you want from me? Cases like this unfold over time. We don't get to know everything we want to know the moment we want to know it.
- ggggtez 9y agoThe parent post thread is about why researchers were afraid as a result of the arrest. While it might unfold and get a not guilty, in the mean time he's in jail. If you were a malware researcher with good intentions, you might rightly think it's a mistake and one that could get you in the same kind of trouble.
- tptacek 9y agoMy point isn't that I have a huge of trust and goodwill in the criminal justice system, but rather that almost nobody in the security community does the stuff that this person is accused of doing. Do you build banking trojans and then arrange for them to be sold to anonymous strangers on Darknet forums? If not: what does this case have to do with your security work?
- EthanHeilman 9y agoWe don't know the facts of the case yet and the government has released no evidence. This could all just be a massive FBI whoops as the FBI does from time to time. Or he could be completely innocent and the FBI is just using the threat of criminal prosecution to exert pressure to get him to inform on friends or contacts. We can't judge until more evidence is made available. A general question not directly related to the case: Where exactly is the line between criminal conspiracy and writing software tools? Certainly TOR is used by people to do bad things (and also good things), but almost everyone agrees that no criminal act has been committed by the creation of TOR. Plenty of legitimate businesses sell Remote Access Trojans (RATs) and go unarrested. On the other hand some developers that sell RATs have been arrested. If someone pays you 2,000 grand to find an exploit have you committed a crime? What if then they use that exploit you sold them to commit a crime? What if you knew beyond all doubt that was their purpose but then the exploit isn't used? Does it matter if they bought an exploit from you or if you are a salaried employee of their company? What if instead of selling them an exploit you configured an email server for them?
- piiie 9y agoWhy is there a tone that he's already found guilty without a trial?
- andylei 9y ago> Hutchins is accused... i thought it was pretty clear
- natch 9y agoConsider the context. From the context, it looks like that particular snippet was posted as a counter to the notion that researchers should be concerned about false accusations happening due to the possibility of their work being misconstrued as the activities of a black hat hacker. To post that as if to dismiss those concerns, is definitely tending toward the tone that piiie is talking about. While you are right to point out the word "accusation" is used, not guilt, the tone still comes through when you consider the context.
- BrainInAJar 9y agoit's unclear what "creating" entails. If I write a crypto library that a piece of ransomware uses did I create the ransomware?
- andylei 9y agono you didn't
- problems 9y agoIt seems like he may not have created the trojan, but simply created a bootkit that it utilized. A fairly common thing for security researchers to do.
- gjjrfcbugxbhf 9y agoAccusations can be based on bad extrapolation of facts.
- deleted 9y ago[deleted]
- pasbesoin 9y agoFrom my limited perspective, the U.S. is continuing to transition more fully to "rubber hose" policing, for lack of a better term. If they decide you are a problem for any reason or decide to put you in their sites, perhaps for their own political agenda, you will face an overwhelming range of charges and immediate legal expenses. The goal isn't truth; the goal is to break you and so further their agenda. I'm not saying there isn't legitimate law enforcement occurring within the mix. But, in terms of the overall picture as opposed to court etiquette itself, "benefit of the doubt" seems to have long since gone out the window. Now imagine being a foreigner, away from family and local support networks, and not knowing whether you've landed on some very political person's list (and prosecutors in the U.S. are very political creatures). Imagine you work in an area engendering much controversy, such as computer systems security. And finally, take it a step further, even sitting home or traveling in e.g. Europe: Just how far and pervasive are the FBI et al. willing to reach with politically aided extradition requests? Political forces in the U.S. want to "stop" "cybercrime" by physically insisting that people they don't like "stop" doing those things. Not a technical solution. Not improving systems and systems management. Nope, get out the rubber hose. And wield it based upon political calculation, more so than actual, (legally) substantiated fact.
- rurban 9y agoGiven his life style at Vegas and that he didn't even attend the conference, just went there for partying and meetups, the "chills" are different to the "chills" one would assume from reading the headline. http://www.dailymail.co.uk/news/article-4762608/Marcus-Hutchins-admits-malware-code-Las-Vegas.html http://www.dailymail.co.uk/news/article-4762608/Marcus-Hutch... They just caught another criminal hacker who was stupid and earned a lot of money from his Kronos hacks. The one chill is how stupid was he? Lamborghini? The second chill is how naive have I been when reading about the lone hacker fixing WannaCry and saving the world from his mom's house bedroom?
- petepete 9y agoIf you're not from the UK, just take everything the Daily Mail prints with a gain (well, a handful) of salt.
- rurban 9y agoYes, I know the reputation of the Daily Mail. But there are too many facts in there. The mansion, the admittance, the lamborghini.
- snowwrestler 9y agoYou've got to make sure you have all the facts though. Renting a $1,900 per night mansion looks a lot less extravagant when that cost is being split by 7 people. And renting a fancy car for a few days might not be that much money. I recently used Turo to rent a gold Cadillac for a trip up to Marin County. Pretty nice, huh? It cost less than renting a Nissan Altima from Budget. (I checked.)
- dclowd9901 9y agoOk, so to this point (and I'm not a security researcher, so forgive my ignorance) couldn't a legit malware creator call their work "research"? I feel like a malware creator could throw this smoke screen whenever they wanted. It's not a free pass...
- megamindbrian 9y agoThis makes me hope hackers go back to selling vulns online.