Should The FBI Have Arrested 'The Hacker Who Hacked No One'? (thedailybeast.com) 227
Last week The Daily Beast ran an article about the FBI's arrest of "the hacker who hacked no one." In December they'd arrested 26-year-old Taylor Huddleston, "the author of a remote administration tool, or RAT, called NanoCore that happens to be popular with hackers." It's been "linked to intrusions in at least 10 countries," reported Kevin Poulsen, but "as Huddleston sees it, he's a victim himself -- hackers have been pirating his program for years and using it to commit crimes."
The article quotes Huddleston's lawyer, as well as a Cornell law professor who warns of the "chilling effect" of its implications on programmers. But it also says security experts who examined the software are "inherently skeptical" of Huddleston's claim that the software was intended for legal use, since that's "a common claim amongst RAT authors." Security researcher Brian Krebs also sees "a more complex and nuanced picture" after "a closer look at the government's side of the story -- as well as public postings left behind by the accused and his alleged accomplices."
Click through for the rest of the story.
Mark Rumold, senior staff attorney at the EFF, tells Krebs "I don't read the government's complaint as making the case that selling some type of RAT is illegal, and if that were the case I think we would be very interested in this." Also skeptical is Allison Nixon, director of security research for New York City-based security firm Flashpoint. "Huddleston can claim the DRM is to prevent cybercrime, but realistically speaking the DRM is part of the payment system -- to prevent people from pirating the software or initiating a Paypal chargeback." Krebs writes:The article quotes Huddleston's lawyer, as well as a Cornell law professor who warns of the "chilling effect" of its implications on programmers. But it also says security experts who examined the software are "inherently skeptical" of Huddleston's claim that the software was intended for legal use, since that's "a common claim amongst RAT authors." Security researcher Brian Krebs also sees "a more complex and nuanced picture" after "a closer look at the government's side of the story -- as well as public postings left behind by the accused and his alleged accomplices."
Click through for the rest of the story.
Nixon, a researcher who has spent countless hours profiling hackers and activities on Hackforums, said selling the NanoCore RAT on Hackforums and simultaneously scolding people for using it to illegally spy on people "could at best be seen as the actions of the most naive software developer on the Earth. In the greater context of his role as the money man for Limitless Keylogger, it does raise questions about how sincere his anti-cybercrime stance really is."
And of course, the FBI's complaint also notes that the software was promoted on HackForums.net. The Daily Beast says Huddleston eventually realized "it was a terrible place to launch a legitimate remote administration tool. There aren't a lot of corporate procurement officers on HackForums," adding that at first Huddleston handed off the business, "while continuing to develop the code as an 'advisor' in exchange for 60 percent of every sale."
Slashdot reader Highdude702 believes Huddleston's arrest "is an outrage, and is a push too far, also in the wrong direction," calling it "the story of a script kiddie gone big time...arrested for being an accomplice to a crime committed by people he had never met, let alone knew well enough to commit crimes with."
What do Slashdot's readers think?
commonly used claim? (Score:5, Insightful)
"I didn't murder someone" is a very commonly used claim among those who don't murder people. Would that "raise skepticism" and make one a target for a murder investigation? I don't think so. This is a chilling-effect arrest. They know this guy didn't hack someone, they're just trying to make the tool-makers lives harder because the tools can be used for no good.
Bullshit logic. (Score:2, Insightful)
Time to arrest the manufacturers of trucks that are used to plow into civilians, hey?
Almost every "hacking tool" has a beneficial use.
Re: (Score:2)
Exactly. It exposes known vulnerabilities (at least to the author). Shutting these people down is just another form of security through obscurity.
Re: (Score:2)
Bullshit logic? Here's some budget logic.
The FBI arrest three people.
The FBI arrest 79 million people.
In which case do they get the most money?
Re: (Score:2)
"It also functions as a laser pointer for presentations and universal off switch"
Re: commonly used claim? (Score:2)
Do you arrest Glock cause someone was murdered with one of the pistols they made? What about Louisville Slugger cause someone was beaten with one of their baseball bats? How about Ford cause one of their cars was used to run someone down? Arresting the creator of a tool because of how it is being misused by others is highly questionable in any circumstance. I think most of the civilised world would agree that the responsibility for the use of such a tool in all the listed cases is on the person who used it
Re: (Score:1)
Do you arrest Glock cause someone was murdered with one of the pistols they made?
Yes, if Glock ran commercial ads stating their products were most and solely useful for murder and no other uses, they would likely be arrested or at least charged with crimes.
What about Louisville Slugger cause someone was beaten with one of their baseball bats?
Yes, again if Louisville Slugger specifically advertised their bats were most useful for assault and battery and less useful for baseball, they too would likely be in legal trouble for doing that.
How about Ford cause one of their cars was used to run someone down?
Once more, yes, if Ford advertized their cars as primarily useful in running over humans and were less useful as a form of transportation, t
Re: (Score:3, Informative)
Re: commonly used claim? (Score:4, Insightful)
Handguns are mostly worthless as a means of hunting either for food or sport. The simple fact is that handguns are made to kill.
Some thoughts on the above:
1. Apparently "hunting" is not "killing" in your lexicon?
2. Some handguns (though none I can think of made by Glock) are indeed used for hunting. This is what cartridges like .500S&W and .454Casull are for. I have friends who take deer or boar with them.
3. There are other shooting sports beside hunting. Glocks appear quite frequently in some of them.
4. Some handguns are made specifically for the purpose of punching holes in paper or knocking over steel plates, rather than for killing things. While they're capable of the latter, it would be akin to using a screwdriver as a hammer.
Just saying.
Re: (Score:3)
2. Some handguns (though none I can think of made by Glock) are indeed used for hunting. This is what cartridges like .500S&W and .454Casull are for. I have friends who take deer or boar with them.
I thought I'd get into deer hunting after talking to some of my friends that hunt. Along with their exciting tales of deer hunting I heard horror stories of hunting during what we call "shotgun season". You see around here it is legal to hunt with a shotgun that fires "slugs", which is a shotgun shell loaded with a single projectile. In this case the "shotgun" is really just a rifle with a big slow bullet, or what I call a "slug gun". Anyway, since just about anyone can hit a deer with a $300 "slug gun"
Re: (Score:2)
"Anyway, since just about anyone can hit a deer with a $300 "slug gun" all the good hunting spots fill up real quick with inexperienced hunters on the few days when "slug gun" hunting is allowed."
You can say the same thing about any rifle (well, .270 and higher...not sure I'd use a .22 for deer). A 12-gauge slug is what, three quarters of an inch wide? If you're a good marksman, you can group your shots at minute-of-angle, or 1 inch at 100 yards. Going from a one quarter inch wide bullet (.30) to 3/4 inc
Re: (Score:2)
Arizonan reporting in: Hikers carry handguns in bear country because hunting rifles are too heavy in the pack.
Re: (Score:2)
Re: (Score:2)
Sport and practice are the primary use of guns. I have many guns, and not one of the thousands of bullets I've shot have killed anything.
And yet some guns in common sport use today were definitely designed for killing humans (including most pistols) and many if not most popular non-shotgun calibers were also intended for this purpose, including .45 ACP, 9mm, .30-06 and .30 carbine, obviously NATO rounds...
Re: (Score:2)
I didn't buy a commander-style 1911 because it was pretty (it isn't particularly) or because it puts holes in paper nicely (which it does) but because .45 ACP is just a whisker better than 9mm in the force delivery department, and California will only let me have ten rounds anyway.
Re: (Score:2)
Re: (Score:2)
The standard freedom argument: If people want to do something incredibly stupid and hazardous to their own health, that's their decision.
It doesn't work very well for cigarettes though, as the rest of society eventually ends up footing the bill for their lung cancer, either through taxes or higher insurance premiums.
Re: commonly used claim? (Score:2)
to fund poor children's healthcare [heritage.org]
Re: (Score:2)
Historical reasons. If Walter Raleigh had visited Central Asia instead of the Americas, cannabis would be a legal health problem and tobacco would be a banned substance.
Re: (Score:2)
Making gun manufacturers liable for crime is exactly what admin carts spent the last eight years trying to do. Now that Repubkicans are in control, the jackboot is on the other foot.
Re: (Score:2)
EDIT: ...exactly what the Democrats spent...
Re: (Score:2)
How about as a recruitment tool ie either work for us for free or spend the next ten years in jail. That is closer to the reality of what is going on.
Re: (Score:2)
Re: (Score:2)
"I didn't murder someone" is a very commonly used claim among those who don't murder people. Would that "raise skepticism" and make one a target for a murder investigation? I don't think so. This is a chilling-effect arrest. They know this guy didn't hack someone, they're just trying to make the tool-makers lives harder because the tools can be used for no good.
If I was a gun manufacturer and someone used a gun I manufactured and sold to commit murder, am I an accomplice or guilty in the use of the gun?
The guy made a hacking tool. It became available and hackers used it. Should the guy be found guilty of being an accomplice or even being charged as a hacker?
Trafficking in circumvention measures is illegal (Score:5, Interesting)
Well.. as outrageous as the OP makes it sounds, you actually don't need to "hack" someone to break the law.
There are lots of laws out there. For starters, trafficking in software or devices which circumvent security measures is often illegal. "Using" said device isn't necessary to run afoul of the law.
The DMCA has strong anti-circumvention language for example. Other countries have similar laws.
Re:Trafficking in circumvention measures is illega (Score:5, Insightful)
That doesn't make it immoral. This is a case of opportunists making use of bad laws they likely lobbied for.
BS - This is thoughtcrime (Score:5, Insightful)
If this person is guilty of developing a remote admin tool, then so are the developers of SSH, Citrix Desktop developers, Microsoft Remote Desktop developers, VMware developers, VNC developers, Oracle SGD developers, Apple remote control services, and any other remote admin tool or tool that could be used for remote admin. All of those tools are developed to avoid people seeing what you are doing, all are configurable ports to avoid detection, etc.. Ask any developer or security expert if those tools can be used for hacking, and the answer is "YES" across the board.
The EFF should have stopped when they said it would have a chilling effect. It does, because this would make "not hacking" but developing a certain type of tool a crime.
Now had the guy actually used the tools to commit a crime, he should be charged with a crime.
This is no different than charging a gun manufacturer with murder because a gang member killed someone with a gun made by the manufacturer. This is tyrannical authoritarianism, plain and simple.
Re: (Score:2)
not that i necessarily agree with the following reasoning either, but i feel it's important to represent the case accurately.
his offense was not developing a remote admin tool. i'm pretty sure that, were he to have just developed it and put it on github or a personal page or even offered it for sale with neutral language, that he would be fine. i believe this in part because a lot of people have released RATs and not been prosecuted.
his offense, more specifically, was selling and promoting the tool as, basi
Re: (Score:2, Interesting)
Re: (Score:2)
Re: (Score:3)
Bullshit (Score:2)
The reason is that Law can not be arbitrary. Baseball bat manufacturers _KNOW_ that what they produce is used for crime. Hammer manufacturers _KNOW_ that tools they produce are used for crime. Knife manufacturers _KNOW_ that the instruments they produced are used for crime.
Singling out one of those manufacturers because criminals think they are cooler than the other manufacturers is an arbitrary act and has no basis in law.
Try really really hard to use logic and reason instead of the run of the mill bull
Re: (Score:2)
Re: (Score:2)
There was no 'hack forum', it was a site or sites in an online community which allowed sales of software. Functionally, it was free advertising and pretty-normal ecommerce.
One can CALL IT a 'hack forum', but that has no significance. Name-calling!
Don't talk about 'serious' if your main point is name-calling. You post on Slashdot, after all, and under an assumed identity.
Glass houses, stones... you know.
Re: (Score:2)
Re: (Score:2)
How come the two Steve's (aka Jobs and Woz) where never arrested then? They sold devices with the express intention of breaking the law. Or does the fact they used the money to start Apple give them a free pass?
Re: (Score:2)
I don't know, but lots of likely reasons:
The laws around phreaking tools may have been inadequate at the time.
They were not caught before the statute of limitations expired.
There may never have been evidence of a specific crime.
Re: (Score:2)
So if we prove gun makers true intentions they get to go to prison for murder?
Probably as an 'accessory to a crime' or 'aiding and abetting.' The legal system has been able to deal with this problem for a long time. If the bullet manufacturers intentions can be proven, they will likely go to jail, too.
Of course that's an unlikely scenario.
Re: (Score:2)
Sadly, as the song goes, "first they came for the murders, but I didn't say anything because I wasn't a murderer...",
Um, no actually, I actively cheer them on for catching murderers because I strongly believe murderers shouldn't be allowed free in society. I don't know what weird ideology you have that believes otherwise.
Re: (Score:2)
Um, no actually, I actively cheer them on for catching murderers because I strongly believe murderers shouldn't be allowed free in society. I don't know what weird ideology you have that believes otherwise.
Actually, Niemöller's poem [wikipedia.org] never talked about murderers, but merely about Socialists, Trade Unionists and Jews. Well, some variants listed communists, incurable patients, Jehova's witnesses, civilians of occupied countries, but none listed murderers.
Like tax preparation software. (Score:1)
Re: (Score:2)
Hacking tools do not hack, it is people that hack. (Score:1)
I would be happy if he went to jail ONLY IF executives of arms manufacturing also went to jail for killing people. Otherwise hacking tools do not hack, it is people that hack.
It's an outrage... (Score:3, Informative)
...everytime the media kneejerkingly supports the bad guys!
.On or about November 21,2013, HUDDLESTON caused an activation email to be sent to a customer who had purchased the Limitless key logger, knowing that individual intended to use the Limitless key logger for the purpose of committing unlawful and unauthorized computer intrusions. 'The email contained the license serial code and instructions for how to download and activate the keylogger.
Guy is toast and rightly so.
Re:It's an outrage... (Score:5, Insightful)
Good post - insightful and informative.
Note that this is a different scenario than the hypothetical question asked in the article/summary. The key is "knowing that individual intended to use the Limitless key logger for the purpose of committing unlawful and unauthorized computer intrusions". This is the standard FBI quasi-entrapment operation.
In my opinion, no tool should be illegal to make or sell as long as some legal use is possible, however improbable. Selling it to someone after you know that they intend to use it illegally, however, I'm willing to let law enforcement do their thing. (But I'd like to see some more public scrutiny of their methods, which smell like bullshit a bit more often than I'd like.)
Re: (Score:2)
When you get done shaking, go read up on how the FBI busts "terrorists". The legal mechanism is exactly the same, and it often smells like entrapment. The details, of course, are different, which probably comes as a big surprise to people who aren't aware that the people and situations are totally different.
What are they charging him with? (Score:1)
Re: (Score:2)
“During the course of the conspiracy, Huddleston received over 25,000 payments via PayPal from Net Seal customers. As part of the conspiracy, Huddleston provided Shames with access to his Net Seal licensing software in order to assist Shames in the distribution of his Limitless keylogger. In exchange, Shames made at least one thousand payments via PayPal to Huddleston.”
Conspiring to commit a crime is not free speech..
I don't see that as conspiring (Score:2)
Re: (Score:2)
simple answer (Score:4, Insightful)
Are gun manufacturers held responsible for deaths caused by their products ? I guess you know the answer now
Re: (Score:2)
Gun manufacturers are not guilty of the same crime as this person: the crime of not being wealthy.
Re:simple answer (Score:4, Insightful)
Do gun manufacturers hang out on "home invaders" forums touting their wares...?
Re: (Score:2)
Do gun manufacturers hang out on "home invaders" forums touting their wares...?
Are the major of people killed by handguns killed in justifiable self-defense?
Re: (Score:2)
Are the major of people killed by handguns killed in justifiable self-defense?
Are most defensive gun uses reported, or even result in a gun being fired?
That's honestly the hardest part with this debate. We simply have no idea when the mere brandishing of a gun caused a potential victim to move on unharmed while the attacker left.
I'd love to actually see some method of reporting an tracking DGU, just do know the answer, whatever it is.
Other countries do have police statistics (Score:2)
Note. In other countries where guns aren't pervasive the mere act of drawing your gun, signaling that you have one, or flashing it, is consider use for force and must be reported (like any other act of violence).
As an interesting statistics from Danish police 2015:
Use of gun: 148 instances (a police officer drawing or signaling that he has a gun)
Number of shots: 11 (of which 8 were warning shots)
That's from ~10k police of
Re: (Score:2)
Those forums have a significant non-criminal audience.
[citation needed]
It's not having "hack" in the name, necessarily. It could be obd hacking, or something like. But I don't think we're talking about a forum like that here.
Re: (Score:2)
Re: (Score:2)
If you advertise your gun as being particularly good at stickups, if you sell the gun to someone you know will use it unlawfully, yes. Yes they are
If this guy can be proven to have knowingly sold tools to an individual stated his illicit intent. If he ever made any claims to its potential use illegally, he will likely be convicted. I me likely will not be if it was just some pirates who used his software to hack.
Re: (Score:2)
Re: (Score:2)
Are gun manufacturers held responsible for deaths caused by their products ?
No, but they're also not advertising their wares on sites dedicated to exchanging tips for committing murder, nor are they providing customer support to people who are apparently engaged in murdering others.
From the sounds of things, this guy was advertising on forums commonly used by hackers to sell their wares to each other, and was offering support to people who made it abundantly clear that they intended to use his software for illegal purposes.
Overreaction... (Score:2)
Question of intent for the Jury (Score:3, Insightful)
Re: (Score:2)
Its also more of a tricky case than what you might imagine at first glance.
All these people know what their customers are doing with their products. I am sure their are gun sellers who know with 100% certainly that when a certain type of person comes into his store that one of his guns is going to end up at a crime scene sooner rather than latter. And yet you cannot discriminate even if you know the guy is part of a gang. There are gun sellers who know 90% of their sales go on to commit crimes. What is the
Why is his RAT necessary? (Score:2)
ssh/putty and RDP handle linux/unix/bsd and Windows remote administration perfectly well. The major difference is that you can't set up an sshd/putty/RDP server on your machine by clicking on an email attachment. Question... what legitimate use-cases are there which ssh/putty/RDP don't handle?
Re: Why is his RAT necessary? (Score:2)
Pen testing is a legitimate use. If it's possible to create such a tool then it's necessary for security operatives to use such tools to treat the effects they would have when penetrating a particular network's security.
Ramp up the Volume (Score:1)
Ikaruga? (Score:2)
That game looks a bit like a retextured Ikaruga [youtube.com].
If that's true: May $deity have mercy on your files!
What do Slashdot's readers think? (Score:4, Insightful)
> What do Slashdot's readers think?
I think the FBI should fuck the hell off, along with the rest of the federal government. Their purpose isn't law enforcement, it's to violate our civil rights, instil fear, and keep the populace under the thumb of the elitists who run the government (for their own benefit).
Seriously, we need to disband the FBI, the DHS (as Ron Paul said, "we fought World War II without a DHS"), ATF, TSA (a bunch of dumb-fucks who couldn't hack it at McDonalds), DEA, NSA, and pretty much the rest of the federal agencies. We don't need some massive, sprawling, byzantine, corrupt bureaucracy... we just need self-government.
Re: (Score:2)
Re: (Score:2)
During WWII, the US government (a) interred Japanese-Americans (b) rationed all manner of goods (c) had official propaganda departments aimed at US citizens and an official Office of Censorship (d) Diverted 40%+ of the economy to the military, etc. etc. etc. Whether an agency called the DHS existed, certainly far more reaching government intervention occurred. (Plus the military did homeland security; you know, at war and all).
This is the Swartz case all over again (Score:2)
“It’s a dual-use technology case,” says Grimmelman. “And you typically don’t get criminal liability in dual-use technology cases unless there’s a pretty clear intent to promote the criminal use instead of the legitimate ones.”
The gummint is fully aware that it can't prove criminal intent, but it has the deep bench of lawyers while Huddleston has whatever late-night TV lawyer he can afford. .
There is historical precedent here (Score:3)
was his an action of unmitigated evil for personal gain which ruined countless lives? YES
Was it technically illegal when he did it? NO
Is it reasonable to assume that anything not deemed actually specifically illegal should be accepted by society no matter how damaging it is? That appears to be the question. IMHO the answer is a resounding NO, but i am one man.
nirsoft_net (Score:2)
www.nirsoft.net have produced and given out a lot of useful software and many have found their way into hacking tools. I'd hate to see it stopped.
Re: (Score:2)
People like you are the reason big government inevitably becomes tyrannical.
Re: (Score:1)
I will put it upon you to read this [wikipedia.org] before reacting so hastily.
Re: (Score:2)
I'm not sure it matters. Such arguments are made quite a bit these days and deserve critical responses, if not for the benefit of the troll who likely knows better, then for those who read his comments.
Re: (Score:2)
I'm not sure it matters. Such arguments are made quite a bit these days and deserve critical responses, if not for the benefit of the troll who likely knows better, then for those who read his comments.
Be honest now - did you really think AC was trolling, rather than simply using sarcasm to make his point? Or did you just type so fast that your comment outpaced that whooshing sound?
Re: (Score:2)
Around here? I give it 50/50.
Re: (Score:2)
Re: (Score:2)
This 'blame chain game' inevitably leads to unchecked witch hunting. Do we blame Toyota for bank robberies when one of their cars are used? No. Do we blame Intel when one of their cpus is used in a 'hacking' crime? No. This is no different.
It's a sad day when this kind of thing has to be explained to someone who reads a site like slashdot.
Re: (Score:2)
Re: (Score:2)
Stop embarrassing yourself and read the comment I replied to. RAT is not a bomb.
Re: (Score:2)
Re: (Score:2)
He even marketed his sofware to them directly, knowing for what purpose they intended to use it.
That's the central question, right? If the government can prove he knew, then he'll go to jail. If they can't, he'll probably go free.
Re: (Score:2)
Re: (Score:2)
So? Was he caught spearfishing with it? Someone still has to decide to and then use his tool unlawfully. Arrest those people. I'd rather these easy-to-use tools are made and distributed because they highlight the vulnerabilities (software and policy) required to get them installed. Software vendors and governments don't want them highlighted, the former because of image and the latter because they hoard them as munitions. Neither attitude is beneficial.
The last thing society should do is depend on law and
Re: (Score:1)
Wrong, it's a tool to remotely administer your own computers.
Re: So what did he think would happen? (Score:1)
Re: (Score:2)
And if your keylog session lasts for more than four hours seek immediate help from a legal professional?
Re: (Score:2)
I've been told that, during Prohibition, some folks sold sets of pipes and other apparatus. The sets came with warnings: Do not do these things (described in detail), for then you would have created an alcoholic beverage and broken the law.
Re: (Score:2)
Everyone?
Re: (Score:2)
Everyone?
If you're making a reference to playing card games in the wee hours, I got off work at midnight from a restaurant job and it took several hours to unwind. My college roommates and I didn't have classes until noon. These days I can't stay up late because I get up at 4:30AM to start work at 7:00AM in government IT.
Re: (Score:2)
Cool story, troll. Keep trolling, you're hilarious.
I'm not a troll. I'm just someone who loves to troll the trolls on Slashdot. Being doing that for years.
Re: (Score:2)
I'm not a troll. I'm just someone who loves to troll
On your permanent record now, troll.
Not yet. I'm working on a Python script to scrape my ~8,000 comments from Slashdot. When I publicly release the script on GitHub, everyone can have access my comments — or their own.
Re: (Score:2)
Flaming narcissist downloads his posting history onto a pen drive and masturbates with it. So appropriate.
Reference materials for my Silicon Valley memoir.
Re: (Score:2)
Published in three volumes!
#1 I am Not a Troll
l #2 I am a Troll
#3 My Life as a Liar
Not quite. One essay will be about my software testing internship in 1997 at Fujitsu's WorldsAway virtual world [pcworld.com]. Several essays on being a video game tester and lead video game tester at Acclode/Infogrames/Atari (same, different owner, multiple personality disorders). A longer essay on testing the Sony Reader [kickingthebitbucket.com] in 2005. Of course, an essay on the Great Recession when I was out of work for two years (2009-10), unemployed for six months (working 20 hours per month), and filing for Chapter Seven bankruptcy. And,
Re: (Score:2)
You forgot to include the chapters on
350#, 1500 calories a day
Laid off two years
Gov't it job
No plans to write about my weight in the near future. Being laid off for two years will in the essay about the Great Recession. My current job is off limits until such time I'm no longer working there and a few years have passed.
They are all self published books by the way.
Self-published ebooks that make me money. Surprisingly, my original essays sell better than my previously published short stories in anthologies and magazines.
Re: (Score:2)
Re: (Score:2)
What is more important? Intent or effect? How much if any care was taken to prevent misuse of the application in the way it was misused?
In the 80's Regan and thatcher closed the national mental health hospitals nation wide in their countries