Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Zero-day sales not "fair" -- to researchers
Robert Lemos, SecurityFocus 2007-06-01

Two years ago, Charles Miller found a remotely exploitable flaw in a common component of the Linux operating system, and as many enterprising vulnerability researchers are doing today, he decided to sell the information.

Comments Mode:
Cry me a river Mr Miller 2007-06-04
Anonymous
Zero-day sales not "fair" -- to researchers 2007-06-13
Anonymous
Its great that people are cluey enought to find these vulnerabilities but I have great difficulties it them selling the information for profit. I can accept that time is money and maybe there is a case for payment but it is my belief that it is strongly unethical to sell it .

The first approach must be to the company concerned and they should have a policy in place to reward people when they report a problem because it is in their bst interest to repair it to prevent exploitation of it thus potential great harm to users of the product.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11468/34673#34673







 

Privacy Statement
Copyright 2008, SecurityFocus