They were arrested for building and selling software used to harvest Amazon logins, bank account logins, and credit card numbers from botnets.
Your logic could just as easily be used to dismiss an indictment of any crime, from undersized lobsters to murdering someone with an undersized lobster.
What I took away from this is that Marcus probably shouldn't have come to the US if there really were trails on a computer system tying him to malware. And that Jacques believes it will eventually be a bad idea to come to the US if you have done anything the US disapproves of, even if such things are both acceptable and legal where you did them and when.
Me, I'm just trying to move my deck chair so that I can get a good look at the icebergs floating nearby away from all the screaming and panicing.
http://www.npr.org/2017/08/01/540903038/u-s-citizen-held-by-...
https://www.aclu.org/other/constitution-100-mile-border-zone
ICE and CBP do conduct arrests pertaining to border violations within that 100 mile zone, but they aren't shaking down random passers-by for their iCloud passwords. They do have to follow due process.
I don't have citations because I can't prove a negative.
"In any event, even if the FBI had somehow 'hacked' into the SR Server in order to identify its IP address, such an investigative measure would not have run afoul of the Fourth Amendment," Turner wrote. "Because the SR Server was located outside the United States, the Fourth Amendment would not have required a warrant to search the server, whether for its IP address or otherwise."
https://arstechnica.com/tech-policy/2014/10/us-says-it-can-h...
Too far, man.
Although I can see the line between that and this, I find it worringly thin. Throw in a leaked IRC log joking about using it for criminal purposes and an overzealous prosecutor, and you'd probably be done.
Not to mention, it's idiotic to spend resources on prosecuting this guy. His life is effectively over, as he can now only ever use his skills for illegitimate work. Nobody will hire him. Since he was no longer an active accessory to crime and had already spent several years focused on legitimate work, society was far better off allowing him to continue on that path. He probably even more than made up for it by enabling hospitals to treat patients with the wannacry thing.
Instead, we have thrown all that away so some prosecutor can put a notch on his belt and brag about taking down something insignificant because he couldn't get anybody that really mattered. Who, by the way, has a long line of other sellers and is still looting bank accounts.
But also, please don't corner me into defending the prosecution here. I get that it's easy to do that; just make absurd statements about how law enforcement works, as other people in this thread have done, and I'll probably take the bait.
But really, I have no idea who any of these people are. I don't work in the part of this field that gives a shit about "the Kronos banking malware", I didn't follow "MalwareTechBlog" on Twitter, I'm faintly allergic to the concept of any twitter account with "Malware" in the name, and more than anything else I think that anyone who would write PHP code to help plant HTML trojans across a botnet needs to set the bar a little higher for themselves.
I do not have a strong opinion about whether this person should be prosecuted.
Upd. Oh it was sarcasm. Joking, black hats are pain to deal with on payment side before bitcoin, so I havent got anywhere with that task.
You don't need that. Adding up all the torrents I have downloaded during my life would probably amount to gazillions of dollars (according to DCMA, of course) and land me in jail for several life times. Just a hyperbole of course, but it highlights the fact that I would be scared to enter USA, because who knows, I might have offended some local laws sometime in the past I wasn't even aware of.