5 ms·
What is that about? - 2018-04-03 - Verified existing and sent to iDefense’s VCP - 2018-04-04 - Validated and acquired by iDefense Is there a company t
by anyzen 8y ago
What is that about?
- 2018-04-03 - Verified existing and sent to iDefense’s VCP
- 2018-04-04 - Validated and acquired by iDefense
Is there a company that buys information about bugs ahead of time so they can protect their clients?
(a cursory Internet search didn't answer my question)
- rhplus 8y agoIs there a company that buys information about bugs ahead of time so they can protect their clients? Companies like Zerodium act as brokers for 0-day exploits, but they tend to sell only to government agencies and the like. https://zerodium.com/about.html https://zerodium.com/about.html
- anyzen 8y agoAnd iDefense is doing something similar?
- dewey 8y agoThey are more "security alerts as a service": https://searchsecurity.techtarget.com/feature/VeriSign-iDefense-Threat-intelligence-services-overview https://searchsecurity.techtarget.com/feature/VeriSign-iDefe...
- wyldfire 8y agoGee. Is that really ethical? Presumably their customers don't intend to patch the bugs without help from the vendor. They likely intend to exploit the bugs (in the name of state surveillance). Many/most global governments (all?) aren't trustworthy in this regard. If you disclose a bug to Zerodium, can you trust them not to have "bad" governments as customers? Also, consider a Sybil attack: Zerodium is an untrustworthy government front. > ZERODIUM customers are mainly government organizations in need of specific and tailored cybersecurity capabilities, as well as major corporations from defense, technology, and financial sectors, in need of protective solutions to defend against zero-day attacks. shrug, okay, I hope that's the case.