4 ms·
A bunch of friends just look for and then sell vulnerabilities (the good ones to bug boundary programs the less ethical ones to governments or companies). The
by inglor 5y ago
A bunch of friends just look for and then sell vulnerabilities (the good ones to bug boundary programs the less ethical ones to governments or companies).
The price of a zero day exploit is quite high (for both sides) and I have friends who make much more money than I do doing this.
That said they mostly work alone or in small groups in their basement rather than at a large security company.
I would hire (or at least interview you) with a prior conviction though I am not hiring for a security role.
I don't think the conviction is a serious impediment for employment in this particular field (since it's for a non-violent crime) though it might warrant supervision on your employer's side and I can definitely see the larger companies not wanting to take the risk.
- texasbigdata 5y agoJust out of curiosity what's "high"'
- FastEatSlow 5y agoVery high, zerodium [1] offers from $10k to $1mil depending on the exploit. [1] https://zerodium.com/program.html https://zerodium.com/program.html
- inglor 5y ago500k-2m depending on severity is a good ballpark figure for numbers I’ve heard of
- bink 5y agoAs someone in the security field, please don't sell exploits to brokers. Aside from the moral and ethical implications it's also doing a disservice to the industry in general.
- jnwatson 5y agoCompare that to the ethical implications of megacorporations expecting private individuals to work for free or peanuts. A rational individual should look at bug bounties and exploit brokers and use the highest bidder. I'm a security professional, and I think brokers are a net positive to the industry. The more that market makers expose the real price/cost of security flaws, the more investment will be made in defensive measures.