4 ms·
There are others who would know more about this than I do, but a few reasons come to mind: 1. NSO almost certainly has more than one exploit chain at a time. W
by jonpalmisc 4y ago
There are others who would know more about this than I do, but a few reasons come to mind:
1. NSO almost certainly has more than one exploit chain at a time. While this would burn one of their exploits, it wouldn’t put them out of business or eliminate the ability for them to get RCE on phones in general.
2. Vendors already have bug bounty programs with established award ceilings. These exploits are almost always far more valuable than the vendor is willing to pay via their bug bounty program. Why would the vendor pay more in this instance?
3. Given (1), how long would this go on for? NSO—who is aware of how many exploit chains they have—likely wouldn’t sell all of their exploits to a single buyer and risk them all getting burned.
TL;DR: It wouldn’t be practical.
- hsbauauvhabzb 4y agoVendors may be more incentivised to intentionally kill the Pegasus business model, which would have immeasurable PR value if executed well.
- alfalfasprout 4y agoThen another one pops up. Fact is, the market is there. It's not too dissimilar how after the silk road was taken down 10 others came up in its place. Markets for exploits are unfortunately here to stay.
- hsbauauvhabzb 4y agoThe models are different. Silk Road has millions of sellers and millions of buyers; Pegasus has a very small set of both, who would be more difficult to connect with. It probably won’t kill it, but will create a harder to leverage profit model