Hacker News new | ask | show | jobs
by tptacek 3243 days ago
Well. They're probably crimes. The law behind building and selling banking trojans is pretty hazy.
2 comments

You're kidding, right? Looks like slam dunk aiding and abetting wire fraud.
I am not kidding, but rather parroting Orin Kerr, an expert on this subject, who does not think this case is a slam dunk.

(Not because the evidence for Hutchins' involvement is thin, but because the law here is hazy.)

Link to the Orin Kerr article: https://www.washingtonpost.com/news/volokh-conspiracy/wp/201...

Orin Kerr's analysis is excellent and made me consider the accused party's intent and the difference between selling code versus using code.

He makes great points, but I intuitively feel like certain acts of creating and selling malware should be illegal, even if only by the spirit and not the letter of the law.

If someone manufactures guns, doesn't register them, and knowingly sells them to street gangs, it kind of seems like they're aiding and abetting illegal activities for profit.

Of course there are instances of selling malware you created to parties who generally won't use it illegally, but that's not what's alleged here.

Whether Hutchins truly violated the law, I don't know, but if the allegations are true then he did something very unethical and something I feel should be illegal.

Some malware uses libcurl. Does that make its creator a criminal?
Obviously not.
You're comparing apples and orangutans.
Thanks for the cite. Interesting.
Do you think there should be a market for building/selling malware? I feel like it would aid in zero day disclosures. But it could also incentivize black hats.
Fuck no. Malware and exploits are not the same thing. Anyone can write malware; you just have to have the stones and a broken enough moral compass to make money by immiserating strangers. There is an infinite amount of malware; we don't benefit from its "disclosure".
There is a market already, the only diff. from this case is who is the end buyer. If you are building a rootkit for Sony Entertainment to use on it's customers none minds much.