4 ms·
I'm not an american, but I'm a spare-time security researcher, hoping to make a career out of this in the future. The last few cases reported here on HN give me
by reginaldo 14y ago
I'm not an american, but I'm a spare-time security researcher, hoping to make a career out of this in the future. The last few cases reported here on HN give me the impression that if you stumble upon a vulnerability (which, by the looks of it, seems similar to the one involved in the AT&T case), it's best to keep it to yourself. You have nothing to win by reporting it, and possibly a lot to lose if you do.
- saym 14y agoI think a good solution would be a generally accepted security flaw reward contract. If most corporations with an online presence adopted some uniform agreement, we'd have a standardized method of report and reward.
- reginaldo 14y agoIt would be nice if they did so, but I don't think companies should be obligated to pay for bug reports from researchers that have no association whatsoever with them. Those that pay seem to get more reports, both in numbers and in quality, at least that's what Google says. Also, I think that a consumer should have the right to speak up when personal data is at risk, but that's a whole other story. In this case, I'm more worried about the "lots to lose" part than about the "nothing to win" one. For some reason I'm even fine with doing charity work for the benefit of billion-dollar corporations from time to time [1]. But not if there's the risk of them coming after me in the future... [1] http://technet.microsoft.com/en-us/security/cc308589.aspx http://technet.microsoft.com/en-us/security/cc308589.aspx
- wyager 14y agoOr you can sell it. There are a number of middlemen who purchase vulnerabilities (in ways that protect the seller) and re-sell them to security firms.
- beedogs 14y agoThis probably would work well until you sold one to an FBI agent.
- jdotjdot 14y agoWhy? Is researching and selling vulnerabilities actually illegal if you don't use them for illegal activities?
- shiftpgdn 14y agoVery much so. http://news.cnet.com/8301-13578_3-57574905-38/at-t-hacker-and-internet-troll-sentenced-to-over-three-years/ http://news.cnet.com/8301-13578_3-57574905-38/at-t-hacker-an...
- jdotjdot 14y agoThat guy actually accessed, downloaded, and leaked the confidential information--which is using the vulnerability, as opposed to simply doing theoretical research, which is what I was asking.
- wyager 14y agoWhich is why you sell it through established anonymous channels to well-known and well-reputed middlemen.
- lawnchair_larry 14y agoSelling this information is not illegal and is common practice. The US government also happens to be the largest buyer, through "unofficial" channels.