Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> We shouldn't look to the black market as cost discovery for these vulnerabilities

We absolutely should. One of the points of bug bounties is to discourage people from selling to the black market.

 help



The black market also prices in a risk premium for ‘this is illegal and you could go to jail for selling me this’.

Google is only paying for the vulnerability; the exploit market is also paying for your mortal soul.


There's plenty of legal gray-hat companies that will buy a bug. Zerodium is a good example though it no longer exists. These companies in turn sell to NSA, etc. maybe even foreign governments for all I know. There's very little regulation of the space iirc.

I had a friend that worked in the space. He lived an exciting life; I hope he's still alive..


I'm surprised that selling knowledge is illegal? Is it really? Maybe it shouldn't be

Ah the classic programmer mistake when encountering the legal system of thinking ‘but surely this act, in and of itself, could not be considered illegal?’ When what the law criminalizes are not mere acts but actions carried out with intent and knowledge in a context.

‘Officer, you can’t arrest me for carrying a gold bar!’

‘I can if you are carrying it out of the Federal Reserve vault without permission’

Similarly:

‘Surely selling someone the knowledge that a piece of software can be hacked isn’t illegal?’

‘It is if you know or suspect that that person’s intention is to use that knowledge to commit crimes’

This would make you a ‘coconspirator’ or possibly an ‘accessory before the fact’ in any crimes they committed.


Ask Stephen Huntley Watt.

That's one of the points, yes, but the black market doesn't dictate the value of the exploit to Google.

A hardline bargaining position with Google would be more like "pay me what I want, or else I'll give it to all takers on the black market for maximum damage". That would be unethical and probably illegal to boot but it's a better definition of value than "1$ greater than max bid".


The value to Google - sure. But the market value of the exploit itself - the black market I think is a factor in that regardless of what Google offers.

The value of something is dictated by what _the market_ offers, and just because Google throws a lowball price because _they_ don't value it doesn't necessarily mean that the value of the exploit itself is as low as they dictate.

There will always be someone who would screw Google just for the love of the game, and if they got a better price from elsewhere, I don't see why _morality_ would really play that big of a role. It all comes down to incentives, and if Google doesn't incentivize doing the good thing enough, then someone _will_ incentivize them to do the bad thing just a bit more.


Your conflating capitalism with markets.

Markets are fundamental things and exist regardless of any kind of moral "should". Otherwise we wouldn't have people buying hard drugs or trafficing women.


If we abandon the moral "should", then the right move is to shake down Google along the lines I already said.

Google should, as a rational actor, pay out better for legitimate vulnerabilities that pose actual risk to them to avoid such a situation.

My beef here is that morality and ethics are only assigned to the researchers.


So what does that have to do with capitalism?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: