3 ms·
I was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market. In the scenario you described, without any o
by gnl 8y ago
I was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market.
In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere.
My experience with the field is limited and considering yours, if you are suggesting that this particular exploit would not fetch a significantly higher price, I shall stand corrected.
- tptacek 8y agoWhat's an "exploit broker"? Where would you find them? What price would you ask for this vulnerability?
- gnl 8y agoI was referring to companies like Zerodium.
- tptacek 8y agoIf you look at Zerodium's FAQ, they explicitly say that they don't buy one-off vulnerabilities like this. Have you found a firm that does?
- gnl 8y agoI have not and I haven't been looking for one either. I'm not quite sure what you're getting at here. If you're trying to point out that I haven't done my homework on this and that I don't have a sufficiently specific/workable plan how to approach it - that is accurate. I don't have exploits to sell. In my previous comment I already stated the assumption that I made, if you feel it's incorrect, which clearly you do, feel free to correct/fill in whatever you think is missing. I'm not getting into a debate about something with which I don't have in-depth experience with someone who does.
- tptacek 8y agoSorry, I'm interested in anyone's response to this, since the HN community reaction to any price paid in a bug bounty by a big company always seems to be "people can make more money on the black market". Rather than recapitulating all the previous debates about why that's not true, I'm interested in seeing someone --- doesn't have to be you --- work their way to an educated guess at a black market price for a bug like this one. I think a lot of HN'ers believe that there's a market for high-severity bugs of any ilk, when, in reality, there's really only a liquid market for a pretty specific subset of those bugs.
- gowld 8y agoWhy to vendors pay bug bounties, if not to defend against financially motivated attackers? To defend against "digital vandals" who would damage systems but not profit from them? To defend against widespread grassroots attacks if an attack is published publicly?
- pvg 8y agoTo encourage people to report bugs they've found and to research bugs and then report them.
- gnl 8y agoI understand. I did in fact believe that this applies to any highest reward RCE vulnerability, thanks for pointing out that this may not be the case. As for the black market price - I don't consider my security background sufficient for my guess to be anywhere near educated enough, so I'm bowing out.
- tptacek 8y agoNo problem. You've been a good sport, thanks! (I'm still interested in seeing someone take a crack at this.)
- bitexploder 8y ago
- blattimwind 8y agoIt actually turns out to be not that simple to approach organized crime for an one-off transaction. If that would be simple for you, then it would be exceedingly easy for LEO to get to these players as well.
- gnl 8y agoClearly. As pointed out/clarified in another comment I was mostly thinking of the grey area companies who buy 0-days and sell them to governments, law enforcement and god knows who.