← Back to context

Comment by tptacek

7 hours ago

If the vulnerability is already being exploited in the wild --- as in, it's a vector people already know about and are tracking --- it's possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with "maintenance payments") based on whether they're patched.

Further: a vulnerability is probably not worth that much either, even if it's a hypercapable vulnerability, because the grey market buys full enablement kits, not vulnerability information. People making 6 figures on vulnerabilities are selling fully enabled full chain exploit systems, not just intelligence about a sandbox escape.

I was under the impression that the three letter agencies and contractors bought vulnerabilities?

[flagged]

  • Mate, it’s a style thing that depends on which style guide you’re following

    AP recommends spaces around them, whereas Chicago doesn’t

    besides if we’re critiquing incorrect following of English orthography

    —Sentences should be capitalized

    —The word “don’t” requires an apostrophe

    —End sentences with a period

    —That’s incorrect usage of an em-dash at the end there — but what does it matter anyways ;)

  • Books I've read would disagree. Are you the emdash police?

  • [flagged]

    • Before the LLMs made the emdash the tool of the electronic oppressor I used it often enough and other people did too.

      I hate that it's basically become the little hitler moustache of punctuation. There was at least one guy who was really enjoying his tiny little moustache until he couldn't anymore. That is the emdash for me.

      1 reply →

How much money is lost by consumers/businesses for every hour the vulnerability is exploited in the wild with no patch?

  • The value of the report is dependent on the scarcity of the knowledge. If anybody can report it, the bid goes down.

    • The value of future reports should also be a component though. By paying a low amount you discourage ethical bug bounty hackers from bothering to look for more exploits. If I think I'm only getting $1000 for a Chrome issue versus $100,000 for an Acme Co issue, I'll be spending my time looking for Acme Co issues.

      Bug bounties are as much a way of attracting talent to even try to exploit your system as they are about the exploits themselves. If you lowball the bounties the talent goes elsewhere.

    • There is a theta decay component. The zero day is highly valuable until known; once known, its value rapidly declines to zero.

That's really informative but maybe a little overly capitalist-brained.

We shouldn't look to the black market as cost discovery for these vulnerabilities, most non-criminal researchers are not putting up an ask order and letting the black market compete with Google.

  • > We shouldn't look to the black market as cost discovery for these vulnerabilities

    We absolutely should. One of the points of bug bounties is to discourage people from selling to the black market.

    • That's one of the points, yes, but the black market doesn't dictate the value of the exploit to Google.

      A hardline bargaining position with Google would be more like "pay me what I want, or else I'll give it to all takers on the black market for maximum damage". That would be unethical and probably illegal to boot but it's a better definition of value than "1$ greater than max bid".

      1 reply →