People think that an innocent white hat hacker could get swept up in this kind of arrest, and there has been so little evidence released, nobody knows what actually happened.
People think that an innocent white hat hacker could get swept up in this kind of arrest, and there has been so little evidence released, nobody knows what actually happened.
In this scenario I both wrote and explicitly sold the software with no idea of what the later applied tech would do. The computer laws referenced in the article seem to require direct knowledge of malicious intent of the software in the sale.
If you haven't already, listen to this podcast about Doug Williams and polygraphs: https://www.thisamericanlife.org/radio-archives/episode/618/...
There's a lot of parallels and how issues of intent can get very grey.
It seems like the arrest is a bit aggressive, but so is the response – clearly out of fear and uncertainty of the govt and general time we live in. Hopefully more transparency will bring light to the allegations and reassure the innocent of their safety
>Hutchins is accused of creating the Kronos trojan, and of working closely with someone who sold the trojan. The lines the DOJ is saying were crossed are pretty bright.
You say that as though you are contradicting NateJay.
But the fear NateJay is highlighting is exactly that a white hat is being accused. And that (whether ultimately borne out in this case, or not) this kind of thing could happen to people who are conducting innocent security research.
If the government has evidence, he should be charged and tried. And that appears to be what's happening here.
(Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)
Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.
If someone manufactures guns, doesn't register them, and knowingly sells them to street gangs, it kind of seems like they're aiding and abetting illegal activities for profit.
Of course there are instances of selling malware you created to parties who generally won't use it illegally, but that's not what's alleged here.
Whether Hutchins truly violated the law, I don't know, but if the allegations are true then he did something very unethical and something I feel should be illegal.
Then why isn't there a chill sent every time anyone is arrested on accusations of black hat crimes? If a cop is arrested under accusation of dealing drugs on the side, it doesn't suddenly send a chill through the law enforcement community that works to take down drug dealers.
How do you know that it doesn't? White hats are counterintel agents effectively. If a counterintel agent is arrested for doing something that could be deemed as part of his job, why wouldn't it 'send a chill' through the community?
For an analogy, suppose you wanted to rehabilitate some drug addicts in a bad part of town, and as a result, frequented that part of town, and bought books on drug dosages. If that could get you arrested because the cops couldn't tell the difference between you wanting to help drug addicts and being a drug dealer, and arrested you based on frequently being in the wrong part of town and showing an interest in drug literature, then it would send a clear message to go no where near these people in need. And that would be a shame.
is there any indication that's the case here? the FBI isn't a bunch of complete incompetents. He could be found innocent, but what makes this case different than the presumption of innocence that every person charged with a crime is supposed to be given?
The attempt to divide the whole world into "people irrationally attacking 'hackers' and 'the good kind of hackers'" isn't doing anyone any favors.
If Hutchins has nothing to do with a criminal conspiracy to profit from a truly awful banking trojan, then his arrest and indictment is a travesty. But if he does have something to do with it, then his status as any kind of "hacker" should have nothing to do with anybody's take on the situation. I'm not sure how much lower you can go than deliberately making money by stealing bank logins from ordinary people, which is what he's accused of doing.
People love to talk about how the FBI has a history of framing people --- and in other fields they might. But there is no track record I'm aware of for the FBI to make up a story like this out of whole cloth. In every case like it, from NanoCore to Albert Gonzales and Stephen Watt, there's been a basis for the charges.
But as you say maybe that's another field. But still skepticism is not without basis imho.
No? It is fairly common in Terrorism cases. I fail to see why they could not do it for Cyber Crime as well
https://www.techdirt.com/articles/20120917/05193620404/fbi-c...
https://www.nytimes.com/2016/06/08/us/fbi-isis-terrorism-sti...
https://www.techdirt.com/articles/20150316/17433230331/fbi-p...
https://www.techdirt.com/articles/20140722/14463127971/repor...
Want more?
Well, yes, since none of those are actually examples of the FBI framing anyone. Stings are not the same thing as framing, no matter how much sarcasm techdirt uses to describe them.
A sting is law enforcement creating a situation where someone can demonstrate clear evidence of their intent to break the law. Framing is law enforcement MANUFACTURING evidence that someone broke or intended to break the law.
In the terrorism cases, a sting would be the FBI giving someone a fake bomb and that person trying to blow people up. Framing would be the FBI arresting someone and falsely claiming they found a bomb and plans for the local stadium in the persons's house. It's an important distinction. In the former case, the person clearly tried to kill people while in the latter case they did not.
No that should be entrapment
A Sting is where they get a tip that criminal action might be happening and they are there to catch the criminals in the act
Not where the FBI creates the plan, induces people into the plan, provides support for the plan, provide materials for the plan, then arrests everyone.
That is or should be considered entrapment, which I also consider framing someone
If the FBI put cocaine in my car and then pulled me over, that’s framing.
I’m not entirely sure what either of these things have to do with getting arrested for creating and selling exploits.
The definition of "wouldn't normally" looks like some hairy case law, but it isn't as simple as you are saying. If they are offered a bomb for sale after a lengthy conversation about how great terrorism is and how important it would be for them to take the bomb, you could possibly have an entrapment case for example.
I.e. not relevant.
The FBI is human and therefor make mistakes, and they are a large organization and therefor have an structural inertia that occasionally directs a lot of power and effort at the wrong target.
Also, the price of democracy is eternal vigilance. Citizens have a duty to check the government's use of power. We should be worrying every time the government acts against a citizen until we also see proper due process including any necessary evidence.
> He could be found innocent
He is innocent until proven otherwise.
> what makes this case different
The government hasn't yet shown that they can handle this kind of case properly. That is partly due to the novel nature of situations involving new technology, but it is also from the government's own history of bad behavior. Their reputation means they do not get the benefit of the doubt, and until we see actual evidence that this case (regardless of the outcome) is being handled properly, it's prudent to worry that this might be an overreaching prosecutor (or worse).
It isn't a bunch of complete competents either, forensic hair analysis kerfuffle shows that much.
> is there any indication that's the case here? the FBI isn't a bunch of complete incompetents.
if they arrested someone selling the malware (which they did), and to get free that person say they can deliver the author (which they did), but instead point to any random security researcher he found working on that malware (we dont know). now, this plus the person whitehat research, the circle is closed and it would take one lifetime and imense legal fees to prove otherwise.
There is only the thinnest of lines between the two.
White hats have to traffic in malware and exploits because it's necessary to understand a threat in order to defend against it, and in order to test that your defenses are effective. In may even be necessary to infiltrate black hat collectives.
The clearest way to tell the difference is that a real black hat will be breaking some other law. Committing credit card fraud or misappropriation of trade secrets or something like that.
But that doesn't appear to be the case here. And the fear is that because the law around this is so uncertain, if the government is going to use it in cases like this without any independent bad acts then nobody knows where the line is supposed to be.
People on this thread have a lot of strange ideas about what infosec people do in their jobs.
The indictment doesn't allege that the defendant sold it, only that he wrote it and someone else sold it.
And as you know, white hats create proof of concept code all the time. And give it to various people (including, in the end, anyone) for various meritorious reasons.
Watch the video of this horrendous deadly baseball bat attack. Baseball players do not bludgeon people to death with bats all the time. Therefore, baseball players should never worry that they might be falsely accused of an attack. Oh, and the crime was horrible, so that means the evidence must be pretty good. Q.E.D.
And as a malware researcher when he became aware that his proof of concept was indeed being used to conduct fraud, he turned a blind eye?
The least plausible part of this chain of events is that Kronos, from what I can see, is not a very interesting piece of software - more a tedious exercise in plumbing than an interesting proof-of-concept.
There is a MASSIVE difference between researching security holes... and then selling the exploits for those security holes or tools that use said security holes.
Again... if the chatter here is accurate, he's not being "arrested" for research... he's being arrested for tools created and sold with the knowledge gained by said research.
There's a difference between discovering a hole in a banks security... and robbing a bank using that hole.
Massive difference.
Writing malware should not, in and of itself, be a crime. Security researchers need to create proof of concept programs in order to do their jobs. I don't think that he should get off scott free because someone else handled the actual marketing, sales, etc but if he didn't gain anything from those sales, or fraud perpetrated in connection with the malware, then - having been arrested and indicted and such - he is just as much a victim as those who were infected.
To use your bank analogy, he found a hole in the bank's security. Someone took knowledge of that hole and sold it to some bank robbers who went on to rob the bank. The seller of that information says that he got it from Hutchins. Unless Hutchins got a cut of the sale, did he do anything illegal? Is there anything really connecting him to the robbery other than evidence that he knew about the hole first and the word of the hole seller?
I feel like you're changing the terminology here in order to confuse the pretty clear lines.
Obtaining and analysing != creating and selling.
Maybe there is a case that buying malware is a reasonable thing to do in some circumstances.
Selling your own malware is a different thing. That seems a pretty clear boundary.
A person he knew, or he was in touch with sold the said trojan. The indictment also doesn't say if he did gain financially from the sale or not.
So, he developed a trojan possibly for research, someone he knew sold it and he got arrested.
This thread gives the impression that people not in the field see some sort of mystique to malware research and development. Malware isn't vulnerability research or exploit development. Most of the malware deployed in the real world is code that virtually anyone on HN could develop, from first principles without any additional research.
That's not true of exploit development, which can be extraordinarily difficult and almost always depends on specialized insider knowledge. There's lots of research reasons to work on exploit code. But that's just not true for the kind of malware we're talking about in this case.
This is important to understand, because the premise of the story is that prosecution over banking trojan malware is having a chilling effect in the industry. It is not. Very few people in the industry build stupid-looking PHP interfaces to HTML injection on botnet victims, not because it's illegal but because it's pointless and dumb and you wouldn't learn anything from doing it.
How does a person accused of development and direct distribution of malware qualify as a white hat? Because he pulled the plug on some ransomware and put his name in global households?
There are a lot of logic jumps here that you have simply glossed over.
"Accused" just means someone said it, it doesn't make it true.
If not, you're all being targeted so you should grab a new career before you get feds at the door.
You can put up $30,000 Cash or some other asset as BAIL then that is returned to you in full after the trail
Or you can pay a Bails Bondsmen 10% of that, as a fee, they will put up the court a 30K BOND then assure the court they will make you appear or pay the court the 30K if skip
You as the individual however lose that $3k.
That's bound to set off some alarm bells, somewhere some day, at some agency or bureau.
Now, Krebs keeps a relatively high profile pertaining to his work, so it's not improbable that they think twice when they read who he is, and see he's one of the "good guys" obviously.
But there's a lot of white hat researchers who aren't Internet-famous (in the tech world, not just security). Quite a few by choice, too.
So now they're worried if there's anything they might have done in the past that could get them into this kind of trouble. That is, being charged with something over having done (perhaps legally grey) security research. And yes they'll be given a fair trial, except that it seems that in the US proving one's innocence also depends on whether you have sufficient funds (I feel like I'm stereotyping here, but I see so many people casually mention these scenarios as if it's a given).
And then, being one of the "good guys"--by, say, single-handedly stopping the first wave of a global ransomware epidemic--doesn't seem to warrant a bit more considerate and less aggressive approach any more, either.
So now they're worried!
It seems to me that, if proven, the DOJ has a case here. They key point will be exactly what they can or cannot prove in court.
It's best not to get too riled up over preliminary things like this. We haven't heard most of what there is to hear until the closing arguments are given and I'd rather not make up my mind too far one way or another before I've heard everything there is to know. And I would be embarrassed to stake an opinion later proven ridiculous because I rushed to judgement.
There are good reasons to be cautious, but this particular case is far from decided either way.
"He admitted he was the author of the code of Kronos malware and indicated he sold it," said Mr Cowhig.
The lawyer claimed there was evidence of chat logs between Mr Hutchins and an unnamed co-defendant - who has yet to be arrested - where the security researcher complained of not receiving a fair share of the money.
That means it should be even less likely to be "send a chill through the security community"
They don't give you back your lawyer money if you're found innocent. They don't give you back any job that you may have lost, and they certainly don't give you back the money you would have earned during that time.
Only in the most exceptional cases is someone held without bail.
> They don't give you back your lawyer money if you're found innocent.
Federal courts can award legal costs "where the court finds that the position of the United States was 'vexatious, frivolous, or in bad faith.'" https://en.wikipedia.org/wiki/Hyde_Amendment_(1997)
---
But yes, your broader point is correct that it's certain to be a very bad experience.
FBI is known for arresting, and indicted people with crimes that carry LARGE sentences to use that a leverage to turn those people into informants.
Extortion is a power tool used by the US Government
What I don't understand is why the FBI didn't just hand the evidence to the NCA in the UK and have them arrest him.
In this case he was selling malware so I think this about a time when head gear was of a darker color...
There's a big disconnect because people seem to be associating this guy's arrest with his serendipitous Wannacry incident. But there's no correlation at all. He is alleged to have had a shady past (corroborated by many reputable HN commenters) and later turned white hat.
Of course it does. But the subject here is whether the indictment should cause a "chill" in the security community. Nothing he did in his legitimate research is related to the indictment.
This is like saying Hans Reiser's arrest would have had filesystem authors afraid of the government.
I think the "selling" part is the problem, not the writing. Don't sell trojans and you won't go to jail. Seems pretty clear.
A lot of AC software runs in ring0 and behaves a lot like a Trojan. I remember nProtect specifically injecting DLLs into explorer.exe among other nasty "black hat" techniques.
On the other hand, if you think that the DOJ, while subject to making mistakes, does not often knowingly and deliberately falsely accuse people, then you look at the alleged behavior, and realize that it is well outside the bounds of whitehat behavior.
I can't speak to any other aspect of federal prosecution. My thoughts about computer crime prosecution definitely can't be extrapolated to my thoughts about criminal justice in general.
Wanncry was a massive black eye of the US Government, I think everyone believing there is zero connection between his involvement in that and this indictment is also naive.
I also fail to understand why you believe "computer crimes" are handled differently than any other type of crime, why you believe the DOJ would frame people for "other types of crimes" but never computer crimes, like there is some prohibition on entrapment when it comes to computers...
They come down hard and they come down heavy on the wrong people, ruining lives. They also pile ridiculous charges even on those who are guilty of minor crimes, threatening to bury them in an avalanche of charges unless they settle. They also seem to be really ignorant of technology, and show a deep suspicion of anything that they don't understand.
Whether this bullying is because they are out of their depth, have a culture of recklessness, or some other reason doesn't matter to those who end up in their crosshairs. If you are a bank fixing Libor, or money laundering (UBS), or are involved in any number of frauds in the financial crisis, you are treated with kid gloves. But if software or encryption is involved, then the sirens wail, SWAT teams gather, and the fear campaign begins.
A general question not directly related to the case: Where exactly is the line between criminal conspiracy and writing software tools?
Certainly TOR is used by people to do bad things (and also good things), but almost everyone agrees that no criminal act has been committed by the creation of TOR. Plenty of legitimate businesses sell Remote Access Trojans (RATs) and go unarrested. On the other hand some developers that sell RATs have been arrested.
If someone pays you 2,000 grand to find an exploit have you committed a crime? What if then they use that exploit you sold them to commit a crime? What if you knew beyond all doubt that was their purpose but then the exploit isn't used? Does it matter if they bought an exploit from you or if you are a salaried employee of their company? What if instead of selling them an exploit you configured an email server for them?
i thought it was pretty clear
From the context, it looks like that particular snippet was posted as a counter to the notion that researchers should be concerned about false accusations happening due to the possibility of their work being misconstrued as the activities of a black hat hacker.
To post that as if to dismiss those concerns, is definitely tending toward the tone that piiie is talking about. While you are right to point out the word "accusation" is used, not guilt, the tone still comes through when you consider the context.
If they decide you are a problem for any reason or decide to put you in their sites, perhaps for their own political agenda, you will face an overwhelming range of charges and immediate legal expenses.
The goal isn't truth; the goal is to break you and so further their agenda.
I'm not saying there isn't legitimate law enforcement occurring within the mix.
But, in terms of the overall picture as opposed to court etiquette itself, "benefit of the doubt" seems to have long since gone out the window.
Now imagine being a foreigner, away from family and local support networks, and not knowing whether you've landed on some very political person's list (and prosecutors in the U.S. are very political creatures).
Imagine you work in an area engendering much controversy, such as computer systems security.
And finally, take it a step further, even sitting home or traveling in e.g. Europe: Just how far and pervasive are the FBI et al. willing to reach with politically aided extradition requests?
Political forces in the U.S. want to "stop" "cybercrime" by physically insisting that people they don't like "stop" doing those things. Not a technical solution. Not improving systems and systems management. Nope, get out the rubber hose.
And wield it based upon political calculation, more so than actual, (legally) substantiated fact.
They just caught another criminal hacker who was stupid and earned a lot of money from his Kronos hacks. The one chill is how stupid was he? Lamborghini? The second chill is how naive have I been when reading about the lone hacker fixing WannaCry and saving the world from his mom's house bedroom?
And renting a fancy car for a few days might not be that much money. I recently used Turo to rent a gold Cadillac for a trip up to Marin County. Pretty nice, huh? It cost less than renting a Nissan Altima from Budget. (I checked.)