NHS cyber-defender Marcus Hutchins to appear in US court
bbc.co.uk
bbc.co.uk
Or maybe they found out (or at least suspected) that he planned to attend DefCon and figured it would be easier if he came to them.
Some journos bought him dinner in Vegas - did they know something, were they really just there for BHDC?. He got all the way to airport and was moaning about the delay with his priority boarding but looking forward to getting back to a debugger.
The dude in question they really want is called TouchMe/TouchMyMalware. There are some old chat logs but no hard evidence in them even on TouchMe. If something as ephemeral as an IRC nick is then well then I'm bruceschneieier. They joke about putting Brian Krebs in it and I do recall this was a meme for a while. There is some stuff on hacker forum but kids stuff.
It is not illegal even in US/UK to write code.
He researches malware, maybe hung out with the creators in IRC. Actual evidence suggests that he did not create or distribute either Kronos or Wannacry.
Some people say he wrote and did a video for a RAT. So what - it is a RAT.
It is interesting to note the reaction of various hackers. Spot the fed. Used to be a game at BHDC now it is spot the hacker. I think that an alternate con - maybe in Estonia - would be a good idea? There must be many who won't travel to US now or even before.
Only last week some UK Police Squad were touting their hacker rehab for kids with some lulzsec dude. Recent UK legislation was brought in that means the government can force you to work for them. They want to make it easier for themselves to spy/hack and to lock up and/or press-gang everybody else. Do what we say not what we do.
What OPSEC lessons are we learning kids? Privacy? Getting involved? Helping out?
Whoever they also lifted has a SSN, any ideas?
Who on earth let this article go out with that in it?
> It is thought to be named after a mythological creature.
This article has some interesting framing issues. Aside from being simply incorrect in this case.
I'd call him a Hero for that.
Let us also not forget that these are allegations against him and until he is tried and found guilty, he is still an innocent person with only said good deeds to his name. If that changes, so be it, but let's not get ahead of ourselves until justice has ran its course.
'Beyond a reasonable doubt' doesn't have an agreed upon numerical probability AFAIK, but let's say it's 95%.
I can say, sure, don't put people in jail until it's 95% certain they're a bad guy, but if I think it's 75% likely they're a bad guy, I'm still gonna think they're probably not the most lawful person ever.
(I have zero evidence either way w.r.t to this case specifically, I'm not saying he's guilty, but I just don't think it's as black and white as you make it sound. If someone is accused of murdering children, and there is some evidence pointing to that, but not enough to reach 'beyond a reasonable doubt' so he is found not guilty, it's quite sane to refuse to hire him as a babysitter.)
> It's just poor writing. Either you paraphrase what people are saying, or you cite someone specific.
https://arstechnica.com/tech-policy/2017/08/researcher-who-s...
- companies selling 0-day malware/spyware to U.S. Government
- companies offering software to 'root' a device to extract information (cell phone data extraction), used by law enforcement.
Are we going to start pretending the identity of the customer or employer doesn't matter? It's accepted practice for the government to have a monopoly on certain goods & services.
If Mr. Hutchins was selling malware to the U.S. Government, then his thought would more likely be it was to be used for malicious purposes. i.e espionage. However, this is not illegal -- but the other is?
Should we start selling tanks anyone just because they could be taken apart for educational purposes?
No.