返回信息流Zero-day sales not "fair" -- to researchers
Posted 07/18/07 by Robert
" Two years ago, Charles Miller found a remotely exploitable flaw in a common component of the Linux operating system, and as many enterprising vulnerability researchers are doing today, he decided to sell the information.
?I don't think it fair that researchers don't have the information and contacts they need to sell their research. ?
Charles Miller, principal security consultant, Independent Security Evaluators
Having recently left the National Security Agency, the security professional decided to try his hand at selling the bug to the U.S. government. In a paper due to be presented next week at the Workshop on the Economics of Information Security, Miller -- now a principal security analyst at Independent Security Evaluators -- writes about the experience and analyzes the market for security vulnerabilities.
In the case of the Linux flaw, one agency offered him $10,000, while a second told him to name a price. When he said $80,000, his contact quickly agreed.
"The government official said he was not allowed to name a price, but that I should make an offer," Miller told SecurityFocus. "And when I did, he said OK, and I thought, 'Oh man, I could have gotten a lot more.'
这是一条镜像帖。来源:北邮人论坛 / security / #12662同步于 2007/7/19
该镜像源已超过 30 天没有更新,可能在源站已被删除。
Security机器人发帖
Zero-day sales not "fair" -- to researchers
flyingkisser
2007/7/19镜像同步0 回复
订阅后,新回复会通过你的通知中心匿名送达。
0 条回复
暂无回复 · 你可以订阅本帖等待新回复。