3 ms·
Why shouldn’t there be bidding wars to determine the value of an exploit? These large software companies have zero issue with exploiting capitalism when it bene
by saltyspaghetti 3y ago
Why shouldn’t there be bidding wars to determine the value of an exploit? These large software companies have zero issue with exploiting capitalism when it benefits their bottom line, and yet it’s suddenly unethical for a researcher to demand to be paid market value for their work? Look at Google, a 1.6 trillion dollar company. They have virtually limitless resources when it comes to paying for secure software, and yet they offer less than half the $ for an Android zero click when compared to Zerodium. Pay people the fair market value for their work and all of this becomes a non-issue. They can afford to do it.
- piva00 3y agoThe ethical issue is when this capitalist fight between market prices for exploits have very real damaging consequences for unwitting users that have nothing to do with the bullshit. Why should they pay the ultimate price because a company is trying to fleece security researchers? Is that the only way to make them pay, to cause damage to what amount to "civilians" in this war? That's my point, these people, very real people, have nothing to do with the whole bullshit, they trusted in a 3rd party to use their product, they can't audit every single 3rd party they use for security holes, even less research themselves ways to exploit them before using their products, you are saying that it's ok for these people to suffer because Google didn't want to pay for an exploit that was discovered. It boils down to the same question: why are the researchers doing this job? If it's because they believe they are helping make software more secure then ethically they shouldn't be putting unwitting end users into harm. If they are just looking for a paycheck then it's just morally corrupt to use users as hostages to get a ransom. I repeat what I said: this is the ethical discussion I'd like to see happening, not this immature "they didn't pay me, so fuck all the users, I will blow it all!", that just sounds like children throwing tantrums. Again: why do researchers do this job? Underneath that you can judge if it's ethical to just sell to the highest bidder, capitalism is amoral, we as humans imbue some sense of morality into it... This approach of "pay what the market is paying or else I will fuck your users" is, in my opinion, ethically wrong, if a researcher is serious about the job they are performing to make the world a less shit place then they need to have some moral guideline to follow, if not it's all bullshit and they are just mercenaries, and I don't support mercenaries.
- pierat 3y agoPerfect example of the guilt-tripping crap seen in infosec. Where I come from, when you say if you do X, I'll pay you Y, it's unethical and a tort NOT to pay Y if you do X. You can do whatever contortions around 3rd parties (users). As long as the exploit vendor doesn't say they're doing anything illegal, I'm in the clear. I've had 1 vendor say that they were engaging in illegal activities, and refused to sell. Again, some may want to auction to highest bidder. Whereas I just like to eat. The companies are the ultimate unethical entities here, that summarily made everyone else look bad, all the while they're hitting users and saying "quit making us hit users!"
- piva00 3y ago> Where I come from, when you say if you do X, I'll pay you Y, it's unethical and a tort NOT to pay Y if you do X. Two wrongs don't make a right. I did agree that companies are being unethical if they don't pay, that does not give the leeway to then act unethically because of them. Again, ultimately who pays the price if an exploit that was sold is then used in the wild by bad actors are real life users. Also, the case being discussed is not about companies not paying X, the comment I replied was talking about not paying what the highest bidder would pay, that is not the agreement for a lot of zero-day programs offered by companies trying to secure their software, they give ranges of payments depending on severity of the exploit, not a "we will pay whatever is the highest bid you can get for your exploit". Is it guilt tripping to ask about ethical questions around infosec? That sounds to me like a thought-terminating cliche, attempting to terminate a discussion for what I believe is very clearly an ethical issue. It does have ethical ramifications, I will not stand on the side of "I will just auction to the highest bidder a potentially harmful exploit", that does not sit right with my moral code. > As long as the exploit vendor doesn't say they're doing anything illegal, I'm in the clear. I've had 1 vendor say that they were engaging in illegal activities, and refused to sell. What stops an exploit vendor from lying to you?
- pierat 3y agoTheses less of an ethical issue than what's argued. I have been screwed by 2 different companies over "proper" reporting. They came back and said I didn't qualify for bug bounties. Then they turned around and PATCHED said bugs that didn't qualify for stated bug bounties. The issue isn't "who's the highest bidder" but instead "who will actually pay what they say". And frankly, the whole of infosec is full of holier-thsn-thou's and corporate scamming. I'll sell to who will pay. (NOTE: what I type only applies to closed source and corporate websites. FLOSS gets free and discrete reports. No 0days for FLOSS. I'm just done being screwed by corporate interests who claim to pay and then screw you over.)