, Matasano 2007-11-06
WabiSabiLabi, formerly most famous for bringing to market the first public vulnerability market, has once again made the headlines. This time, one of their co-founders, Roberto Preatoni, has been folded into an ongoing Italian wiretapping scandal. This investagation has been going on for 10 plus months.
Prior to WabiSabiLabi, Roberto worked at Telecom Italia as part of their penetration testing team. Four members of this team have already been arrested back in January for using a Trojan Horse to compromise and monitor Vittorio Colao, the former CEO of the Rizzoli Corriere della Sera publishing group.
From Robert McMillan:
According to the reports, Preatoni helped staff a 10-member Tiger Team, ostensibly set up to test Telecom ItaliaÃ¢??s information security system. Members of this team are now charged with hacking and spying on Carla Cico, CEO of Brasil Telecom; the Kroll investigative agency; and journalists Fausto Carioti and David Giacalone of the newspaper Libero.
This might actually be one of the biggest challenges for vendors and vulnerability researchers. How far can you really trust that everyone is doing the right thing? If I were a vendor, I would not make the assumption that the vulnerability researcher is trustworthy. This isnt to say that you should be hostile towards vulnerability researchers. It is simply that you have absolutely no idea how many people a researcher has told about a vulnerability. Given that, I think it makes sense to treat vulnerability reports as if you just found out about your vulnerability through BUGTRAQ.
While obvious, this also speaks to why it is hard to implement a vulnerability market. It is all about trust. And if the buyers and sellers utilizing (or considering utilizing) WSL cant get past this, Id say its game-over.
As I think about it, probably the best way for vulnerability researchers and vendors to be bridged is through a vulnerability broker. This could be a trusted person or organization that can represent vulnerability researchers whose reputation is at stake when dealing with vendors.
Of course, I am personally not sold on the idea that the sale of vulnerabilities is a good idea.
Finally, from the Theres No Such Thing as Bad Press Dept: