Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Zero-day sales not "fair" -- to researchers
Robert Lemos, SecurityFocus 2007-06-01

Two years ago, Charles Miller found a remotely exploitable flaw in a common component of the Linux operating system, and as many enterprising vulnerability researchers are doing today, he decided to sell the information.

Comments Mode:
Cry me a river Mr Miller 2007-06-04
Anonymous
Zero-day sales not "fair" -- to researchers 2007-06-04
GDFuego
This isn't an issue of "fair" versus "unfair". It is a reality of any sale.

Next year I'll be trying to sell my house. How much is it worth? Well, its worth however much someone is willing to pay for it. If I put it on sale too high, I'll turn off potential buyers. If I put the price too low, I have the potential for screwing myself over. The more potential buyers I can get at once, the better the chance of competition driving the price up.

Why should vulnerability sales be any different?

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11468/34640#34640







 

Privacy Statement
Copyright 2008, SecurityFocus