Malware researcher Marcus Hutchins, known as ’MalwareTech’, pleads guilty
techcrunch.com
techcrunch.com
Consider this fictionary tale: you fly to Budapest for a fun trip. You are jailed for posting the Soviet hammer and sickle on your Facebook two years ago -- it's a crime under Hungarian law to use that symbol. Do you think this is right?
Here's the law:
Any person who: a) distributes, b) uses before the public at large, or c) publicly exhibits, the swastika, the insignia of the SS, the arrow cross, the sickle and hammer, the five-pointed red star or any symbol depicting the above so as to breach public peace - especially in a way to offend the dignity of victims of totalitarian regimes and their right to sanctity - is guilty of a misdemeanor punishable by custodial arrest, insofar as the did not result in a more serious criminal offense.
He was arrested in the US for his impact to people and companies inside the US.
Assange was using Ecuador’s protection and resources for free. At that point you’re at the whim of the Ecuadorian people and their elections. Nothing is forever.
Kinda stupid to commit crimes against people in a country and then travel to that country before the statute of limitations has expired.
I might have a different opinion for victimless crimes, but it's irrelevant to this discussion.
There's not necessarily anything wrong with prosecuting him in the US, but presumably the US authorities could've just as well spared themselves the work and referred this to the UK authorities in whose jurisdiction the crimes were committed.
Now that I'm thinking about it more, I'd be upset if they didn't arrest him while he were here.
In fact, the DOJ press release specifically names a bunch of countries that aren't the US https://www.justice.gov/usao-edwi/pr/man-charged-his-role-cr...
>According to publically available information, since it was created, Kronos has been configured to exfiltrate user credentials associated with banking systems located in Canada, Germany, Poland, France, and the United Kingdom, among others countries.
Of course, given the nature of the malware it's very likely that at least someone in the US was affected.
How is this a problem? if you cause material damages to Americans and you then go to the US the country is going to come after you.
Why would the US not protect its citizens to the best of its ability and prosecute people who harmed them, even if they harmed them from a place that wasn't the US. We're talking about global financial crimes, they don't know any borders to begin with.
If you kill someone outside of the US, and then you travel to the US, I'd be concerned if you wouldn't get arrested
I could be wrong, but I don't think the federal government has ever claimed that any Americans were infected with Kronos.
It's a stretch.
World police strikes again.
Taken to the extreme with this logic he should be extradited across the globe for decades for any public prosecutor to go to town on, though I guess that type of fear is exactly the intended effect of witch trial justice.
The situation in reverse with a US citizen charged in a foreign country despite causing no harm to them is unlikely to garner the same response. American exceptionalism at it's finest.
I mean, for many of us that’s already a problem, and has been for a long time. Ever mentioned your same-sex partner somewhere a Government might be able to find it? There’s now a whole bunch of countries you can’t visit or pass through without being at risk of imprisonment or worse, yay.
A more apt hypothetical would be if you were tricking people into distributing hate symbols from abroad. I think you could make a cogent argument for arrest in that case.
The victims of the malware were on American soil. If someone remotely takes control of your smart oven and burns your house down, you have standing to charge them with a crime. The difference is he violated a US law, against a US citizen, while that citizen was in the United States. If you do that and are currently in the US you should expect to be arrested.
Maybe not the whole world but the US has the hegemony over countries where the US military bases reside. All of those countries have signed their sovereignty away through various extradition and trade treaties which give the US DoJ a massive reach over the citizens of those countries.
In 2019, if you were to try to escape the long arm of US law, your options are extremely limited. I can't think of a country that would not hand you over to the US because of a massive pressure that the US State Department would put on the host country. Just look at Ecuador which sold Assange for billions in aid.
Nobody cares that he wasn’t in the US when he caused harm in the US.
Lets be honest with ourselves - banks have a very specific role in the world economy, and have largely quit lending to businesses small enough to actually upset the market.
Sure VCs do what they do. But unless you're in something sexy or trendy? Good luck courting them.
I strongly feel that a malware researcher who stopped WannaCry and spends his free time making reverse engineering tutorials shouldn't go to prison because of a trojan he wrote as a teenager (assuming he really did write it).
After a few episodes I had to take a break. It is so upsetting. Justice is not a reality.
https://serialpodcast.org/season-three/about
““Charge stacking” is a process by which police and prosecutors create a case with numerous charges or numerous instances of the same charge to convince the defendant that the risk of not pleading guilty is intolerable. The defendant may be convinced to plead guilty to a few of the charges in return for not being prosecuted for the remaining charges.“ https://en.m.wikipedia.org/wiki/Courtroom_Workgroup
It sounds like a sentencing date has not been announced: "According to a copy of Hutchins’ plea agreement, both charges each carry a maximum of up to five years in prison, and up to a $250,000 fine, and up to one year of supervised release. However, those charges are likely to be substantially tempered by federal sentencing guidelines, and may take into account time already served in detention. It remains unclear when he will be sentenced." https://krebsonsecurity.com/2019/04/marcus-malwaretech-hutch...
In federal sentencing, in general, and in particular with these charges, "like" counts group. In effect, you serve the time for the "worst" charge you're convicted of. You do not add the sentences for all the counts together to determine a sentencing.
As the article says, and as you'll find if you read the plea agreement and then consult the chart in the federal sentencing guidelines, he's not facing anything close to 5 years.
https://www.courtlistener.com/recap/gov.uscourts.wied.77855/...
In particular, there are CIs with online chat transcripts corroborating the accusations, and Hutchins offered a partial confession the day of his arrest.
Hutchins also had excellent representation, including Marcia Hofmann.
The please bargain system is nothing but institutionalized blackmail, and many innocent people have become its victims.
The please bargain system does neither of that.
To answer your question, not "we" would do that but that's what fair trials are intended for.
I was laying out reasons why the plea bargain system is principally unjust. There are many more problems with the US justice system, of course.
In reality, the guideline ranges stipulated in the plea bargain put him most likely under 2 years, and possibly as few as 6 months. Even with the maximum upward departure stipulated in the agreement, Hutchins would not be looking at 3 years.
The guilty get the benefit of reduced sentences. The innocent have to face the bullying behavior where prosecutors stack up charges to make the potential punishment more frightening in order to coerce a plea.
https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...
Lesson learned, I suppose.
Plea bargain here: https://www.documentcloud.org/documents/5972658-Marcus-Hutch...
From the deal: "The government agrees to make no recommendation regarding the ultimate sentence to be imposed; however, the government remains free to take a position with respect to any fact or factor pertinent to the sentencing decision consistent with this agreement and to advise the court that the government's failure to make a sentencing recommendation should not be construed as a recommendation for leniency or severity."
The guy got screwed.
This was definitely not that. It is the very opposite of precise.
The PSR will be generated, and the judge will decide on the sentence, ranging from deportation without incarceration to 5 years.
If your doctor told you you had 0-5 years left to live, inclusive, you wouldn’t call that detailed and precise, would you?
Most don’t or won’t.
White collar crimes are very expensive to investigate, prosecute, and keep the attention of the jury. High-profile clients and attorneys invite a lot of red tape, expensive to cut through, so they don't bother unless conviction is certain. Failure is embarrassing and makes the State look weak.
But Ken White is living in a bubble if he thinks the State won't spend the money to go after any low-hanging fruit it can reach.
don't trust testimonies, don't trust statements, or at LEAST recognize their infallibility
just understand the decision tree and how they change the options available during the legal process
in this case, we have:
- duress
- a short remorseful statement that is hoping to get his sentence reduced or even nullified
- no room for appeals court due to the plea agreement
the saying goes "remorse is for the courts", and unfortunately this will be used against me if I am ever indicted for something
People make mistakes, and people can change. Don't feel too bad for contributing to his defense. He fucked up and is trying to make up for the damage he caused by sincerely helping people.
Edit: The source code leaked at some point so its hard to tell when he stopped selling it based on available malware samples. New variants were detected at least as late as 2018. He was accused of selling it in 2014 and 2015 though, so there's a decent chance that he stopped a couple of years before his arrest.
From the contents of the "attachment A" it seems like the FBI (or whatever other US agency) "sat" on the code they indirectly purchased for 2-3 years (the UPAS) and for several months (the KRONOS), observing the behaviour of Hutchins and "Vinny" and collecting evidence against them.
Shouldn't they have somehow acted to prevent the spreading of the malwares?
Can someone elaborate what that conspiracy is?
Hutchins took a plea deal. It's well known that there is rampant abuse of the plea deal in the US justice system [1].
That's not to say he's totally innocent of everything but that him pleading guilty to this single count may not be as straight forward as the article would make it seem.
[1] https://www.theatlantic.com/magazine/archive/2017/09/innocen...
The plea agreement itself stipulates to the sentencing level. Assuming all charges group, the maximum proposed sentencing level is 13, with the caveat that the agreement allows prosecutors to argue for an adjustment of as many as 8 sentencing levels. With no previous criminal history, a level 13 offense is 12-18 months.
Late edit
I missed that he also loses 3 levels for accepting responsibility. At level 10, his guideline range would be 6-12 months.
For more detail on how this works, Google [popehat whale sushi].
(I also read Popehat.)
https://www.boston.com/uncategorized/noprimarytagmatch/2013/...