, SecurityFocus 2005-12-15
The auction may have set a record price for a highlighter pen and an 8-by-11-inch sheet of paper.
Expand all |
Post comment
Researchers: Flaw auctions would improve security
2005-12-16
Sean (2 replies)
Sean (2 replies)
Researchers: Flaw auctions would improve security
2005-12-18
Anonymous (2 replies)
Anonymous (2 replies)

A secondary set of issues occur in any open sale of such information, e.g., how does the seller confirm that the buyer is who they claim to be and actually meets the buyer's restrictions? How does the buyer confirm the seriousness and accuracy of claims? What if the vulnerability only occurred in certain, specific, obscure configurations, which would certainly diminish its value to anybody?
Security Product Vendors have a history of offering bounties for finding flaws within their products (typically as a marketing ploy) going back 20+ years (e.g., I recall one small security company who offered the CEO's used Ferrari if anybody could break their security system). Another vendor offered tee-shirts for security related bugs. For example RSA's crypto breaking contests are a close cousin to this issue. I haven't heard any complaints about their contests and security researchers participate actively.
Disclosure: I used to work for several product vendors and have dealt directly with independent security researchers regarding undisclosed vulnerabilities of my employer's products.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/11364/32899#32899