9 ms·
Confessions of Marcus Hutchins, the hacker who stopped the WannaCry attack
- rayuela 6y agoHutchins was busted for committing bank fraud. Him doing one good thing does not absolve him of having committed another crime...he's still a criminal. Rather than protest him being arrested we should advocate for him getting a reduced sentence for having at least done some good.
- willis936 6y agoShouldn’t the system be set up to reward the good thing more than the bad thing when possible? If someone is in a position of power from doing bad things, how could you expect them to stop of their own volition?
- jakelaboss 6y agoA system that rewards the morally 'right' behavior seems ripe for abuse. Should we not set the expectation that one should be 'good' as the base of our society contract?
- JustFinishedBSG 6y ago> how could you expect them to stop of their own volition? The threat of punishment ...? Your system encourage doing bad things when you are in a position of doing good things. If I discover a cure for cancer might as well rob a bank and kill my noisy neighbor just before publishing because I'll be pardoned
- naringas 6y ago> The threat of punishment ...? if this is the only reason not to harm others, then you'll probably look for (and likely find) a way to harm others and avoid punishment.
- nmeofthestate 6y agoPunishment is pointless because anyone who would be deterred by punishment would also be able to avoid punishment. Right.
- Chris2048 6y agoOr make it part of a plea deal
- CalChris 6y agoIn a sense, it did. That was taken into consideration at his sentencing. From his Wiki [1]: Hutchins was sentenced to time served and one year of supervised release. [1] https://en.wikipedia.org/wiki/Marcus_Hutchins https://en.wikipedia.org/wiki/Marcus_Hutchins
- marcinzm 6y agoOne problem with rewarding an action is that humans are very good at gaming rules. For example, let's say I get X for donating to charity. I can for example setup my own charity, donate to it, pay myself all its income as salary and then just collect lot's of X. The US tax system is a perfect example of this I'd say.
- koheripbal 6y agoTo be clear, that specific example doesn't work at all, because salaried income from a non-profit is still fully taxable.
- vmception 6y agoNot really any benefit from that But the charity you setup would shelter your assets better than any prenup or other asset planning (or lack thereof) when you divorce your spouse
- gvjddbnvdrbv 6y agoI am not a lawyer but I'm guessing a judge would look pretty badly on doing this too obviously.
- vmception 6y agoOne of the most useful monetary goals in life is being able to afford US federal appeal's court. It's the only part of the system where arbiters of the law actually begin to analyze the law. There is no dog and pony show for jurors there, no instructions that a prosecutor can tell the judges and sway them. So it wouldn't matter what a single judge thought in lower court, if you were compliant.
- yazan94 6y agoThat logic doesn't make sense. Everyone has the potential to do something bad. If you have a concealed carry firearm with you, should you get rewarded for not shooting someone on a particular day?
- bryanrasmussen 6y agothe analogy is more like you had a concealed firearm with you and you shot a terrorist. although personally I think time served and probation seems about right.
- iso1631 6y agoIn the UK we stop terrorists with Narwhal tusks https://www.theguardian.com/uk-news/2019/nov/30/narwhal-tusk-and-fire-extinguisher-used-to-tackle-london-bridge-attacker https://www.theguardian.com/uk-news/2019/nov/30/narwhal-tusk... What's more interesting on the "good deed - bad deed" ometer is > Among those who pinned down the attacker was James Ford, 42, who is also thought to have tried to save the life of a woman who had been stabbed. Ford was jailed for life in 2004 for the murder of 21-year-old Amanda Champion.
- Ntrails 6y agoOne good deed is not enough to absolve, but one bad deed is enough to condemn.
- chapium 6y agoCan I steal a purse if I read to children at the library?
- jstanley 6y ago> getting a reduced sentence for having at least done some good. It seems like this is exactly what happened: > On 26 July, 2019, Hutchins was sentenced to time served and one year of supervised release.
- JoeSmithson 6y agoJudges comments are included in this short documentary https://youtu.be/vveLaA-z3-o https://youtu.be/vveLaA-z3-o (from 21:26)
- koheripbal 6y agoSeems like the system works far more frequently than we generally give it credit for.
- anonyxyz 6y agoYou mean because it worked this one time?
- deleted 6y ago[deleted]
- pfundstein 6y agoThis is a bit over the top. He is not a master hacker who "saved the Internet"; He accidentally neutered WannaCry by registering a domain he found in the binary, which as it turned out, acted as a kill switch.
- DyslexicAtheist 6y ago> He accidentally neutered he did not "accidentally neuter WannaCry". He stopped WannaCry by registering the kill-switch domain. Nothing accidental about that. > He is not a master hacker he is a kid. what makes his experience interesting, and his story worth listening to is that he had first-hand experience with the legal system as a hacker that went too far (because he is/was a kid). that is worth more than the arm-chair analysis of law (by wannabe skript kiddies and theoretical security experts).
- ryanlol 6y ago>Nothing accidental about that. He didn’t know it was the kill-switch domain, seems pretty accidental to me.
- DyslexicAtheist 6y agoisn't the first thing anyone would do when coming across such a domain in a malware binary to check it is claimed (and if not then who here wouldn't register it (even just if to see what happens)?) I mean we can argue over the semantics of accidental, but imo you can't accidentally register a domain?
- flatiron 6y agoi totally agree. most of innovation is "i wonder if..." and then you do something and see what happens. him registering the domain was based on research, it killing wanacry was based on research and a bit of luck, just like most things
- deleted 6y ago[deleted]
- Aissen 6y agoIt's a long piece, and quite interesting. Thanks for sharing @Malwaretech.
- Twisell 6y agoYeah this piece is especially long, interesting and nuanced. If only people could take time to actually read it before reacting with simplistic and pre-existing opinions that would be awesome.
- thisisnico 6y agoOne of the first times I've read an article from start to finish entirely without skimming through. Incredible story.
- dylan604 6y agoIt is very similar to the one on Silkroad and Ross Ulbricht that Wired had previously done. I can easily see either/both/combined into a movie script.
- ausbah 6y agocybersecurity professionals are the closest things to superheroes we have
- koheripbal 6y agoThere are a lot more grey-hats than the industry is generally willing to admit.
- C1sc0cat 6y agoBatman's pretty grey hat as a Super Hero as is Oliver Queen
- gowld 6y agoTitle was intentionally misleading before mods updated it. This is a very one-sided article meant to make Hutchins look good. The valuable bit of the article is a a reminder of why it's important not to start being criminal/evil, because it traps you in a postive-feedvack loop of criminality as you feel a need to commit ever-greater criminal acts to cover up past acts. The only escape from this is to create a culture where criminals know that it safer to turn themselves in and turn informant on their co-conspirators, than to try to evade the authorities.
- gizmo 6y agoI carefully read the entire article and I don't think it made Hutchins look good. But it does describe, accurately in my view, the kind of rationalizations people apply to cross line after line until they see no way out.
- deleted 6y ago[deleted]
- sqldba 6y agoA statute of limitations on hacking laws would also help. There's no reason people should be fearful decades later for stuff they did as (relative if not literal) kids.
- thoughtstheseus 6y agoMarcus - thanks for stopping WannaCry. Be well.
- ngneer 6y agoSecurity is about control. Shame on the malware writers for having left a single point of failure.
- WrtCdEvrydy 6y agoIt's interesting to see how trusting another criminal with your address opens you up to serious blackmail... maybe I should set up a PO Box for Bitcoin business :)
- C1sc0cat 6y agoAh that explains his tweet this morning
- killswitched 6y agoWhy wouldn’t the wannacry malware writers register the domain first? Should be possible to simply update the name servers or dns records should the kill switch need to be engaged?
- derrikcurran 6y agoPerhaps it wasn't a kill switch but rather a way to exempt certain organizations or countries from the effects of the malware.
- seesawtron 6y agoThis was a long and yet one of the most interesting reads from WIRED I have seen in a long time.
- korethr 6y agoI cringed when it came to describing how he'd try to tell the FBI half truth. Even if they hadn't had enough evidence to get him for his involvement in the Kronos malware, they'd still throw the lying to a Fed charge at him.
- voska 6y agoIf you fellow HN'ers feel as compelled to thank Marcus as much as I did, I recommend supporting his Patreon: https://www.patreon.com/MalwareTech/ https://www.patreon.com/MalwareTech/