← Back to context

Comment by ofjcihen

7 hours ago

They can be and they can not be depending on what you’re selling.

But that’s besides the point. You straight up argued that one isn’t real in the most asinine way you could.

Even if you were right that would be ridiculous. The fact that you’re wrong and have multiple people telling you you are makes it even worse.

I’ve seen you replying in snide comments whenever someone disagrees with you before. Your status as…whatever you are doesn’t give you carte to treat randoms like they’re beneath you.

I'm noticing you didn't answer my question.

  • I did explicitly answer your question, yes.

    This is how all of these sites work. You would not get 500k for every exploit obviously. You would get that (or more) for great exploits.

    I’m noticing you haven’t addressed anything I mentioned at all. Is that just acceptance that it’s the truth or are you just having a bad day?

    Edit: Actually, let me add that for a 0click exploit on mobile devices that leads to root level permissions you’re very likely sitting on millions of dollars.

    • This is 2 years old, but goes deep into the details of how the "0 click" market works, roughly what kind of money you'd be sitting on, and what it takes to actually get that money:

      https://securitycryptographywhatever.com/2024/06/24/mdowd/

      It sounds like you're telling me you believe you might get six figures for a "great" WordPress core RCE. I believe that's false, and I believe that for reasons that probably indicate our premises are much too far apart to hash this out here.

      I have open contempt for online price list "brokers" like Zerodium. I do not have contempt for other commenters here. I think it's important that you understand the distinction before coming at me the way you've been in this thread. Disagreeing with me, rebutting or refuting me, sharply or ungenerously: totally fine. Your weird psychoanalysis of me: not fine.

      3 replies →