3 ms·
It would be a lot easier to agree that security researchers shouldn't be selling vulnerabilities to the highest bidder if, say, they were offered $250k to $1mm
by earl 14y ago
It would be a lot easier to agree that security researchers shouldn't be selling vulnerabilities to the highest bidder if, say, they were offered $250k to $1mm each from the vendors involved. Baring that, it's hard not to think this is mostly very wealthy companies bitching that researchers are declining to work for free to fix the companies' inability or lack of desire to write secure code.
It feels like the companies first tried to hold a bulwark and claim that vulnerabilities are worth nothing. Now that fb, google, and mozilla offer bug bounties, we're starting to establish a market price. Like the old joke apocryphally attributed to Churchill:
"Churchill: "Madam, would you sleep with me for five million pounds?"
Socialite: "My goodness, Mr. Churchill... Well, I suppose... we would
have to discuss terms, of course... "
Churchill: "Would you sleep with me for five pounds?"
Socialite: "Mr. Churchill, what kind of woman do you think I am?!"
Churchill: "Madam, we've already established that. Now we are haggling
about the price”