3 ms·
> Why tolerate that, and the people making zero-days? They should be treated like bioterrorists making enhanced ebola virus. That is the silliest thing I've he
by coderzach 12y ago
> Why tolerate that, and the people making zero-days? They should be treated like bioterrorists making enhanced ebola virus.
That is the silliest thing I've heard on hackernews in a while. Criminalizing disclosure of security flaws would make everything MUCH less secure. Security flaws would still be found by unscrupulous individuals, it's just that the users and creators of the flawed software wouldn't know about them.
- Malachai2227 12y agoIt seems to me that Zigurd is referring to people who keep exploits secret and sell them for financial gain to criminals and government agencies.
- ihsw 12y agoFull, anonymous, and public disclosure is fine, however selling exploits is not. The problem is when you sell exploits to software maintainers whom have no interest in fixing the bug, but instead are interested in purchasing the silence of the exploit developer.
- Zigurd 12y ago> Criminalizing disclosure of security flaws I made no such suggestion, much less proposal. The problem is commercial, militarized development of zero-day exploits and selling to the highest bidder. UNLIKE responsible disclosure by legitimate security researchers, weaponized exploits are very analogous to the freelance development of bioweapons and then auctioning them off to the highest bidder. It is a cancer on computing, and deserves to be stamped out, as such a bioweapons development would get wiped out quickly and conclusively.