5 ms·
Sounds like part of my summary's issue was grammar/word choice. I definitely understand the problem now and will be more careful. New summary: The governments
by snlacks 12y ago
Sounds like part of my summary's issue was grammar/word choice. I definitely understand the problem now and will be more careful.
New summary: The governments (plural) hire these companies (as opposed to "guys") and may, but don't always, keep these software vulnerabilities secret in order to collect information on people/targets. This is sometimes done with a warrant and in other times is done without the need.
I don't see how the governments and these companies aren't keeping the vulnerabilities in the software we rely on secret, I need more convincing.
I really appreciate you taking the time to flesh it out with me, even though it's unlikely we'd end up agreeing (just from hints in the tone we're using), I'm glad it won't just be over poor writing on my part. Thanks!
- tedunangst 12y agoYes, the vulnerabilities are kept secret. The value of an exploit decreases significantly after the vulnerability is patched, and they are in the business of selling high value exploits. If they couldn't sell the exploits, they wouldn't be finding the vulnerabilities either. Banning exploit sales won't suddenly result in VUPEN turning into a vuln finding charity. For whatever it's worth, zeroday exploits are rare in practice. The vast majority of exploited systems are taken down with public vulns because they weren't patched in time. Very few organizations are interested in specific targets; carpet bombing the internet and searching for unpatched shellshock/drupal/etc installations will collect enough low hanging fruit.
- snlacks 12y agoIf the NSA buys an exploit in Windows, does the NSA's contract preclude VUPEN from selling that exploit to Microsoft?
- tedunangst 12y agoPresumably. If you're paying for an unpatched vuln, you don't want to get a patched vuln.