Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Perhaps more worrying, they may have sold them elsewhere first and informed the purchaser that they have until the competition date to use it. Better business if you have to come back after the disclosure date for more holes...

Nohig ethical at all going on here.



My understanding is that would violate the rules of the competition. Though of course if a competitor were to do that, odds are no one would find out.


Would someone willing to sell exploits on the black market really be concerned with "violating the rules of the competition"?


Well, presumably they'd want to keep the money from the competition. That's definitely an incentive.


I would imagine it'd be fairly hard to the competition to know and revoke the money. Bad guys are almost certainly exploiting various undisclosed vulnerabilities. The bigger issue, I'd assume, is that by doing this competition, you've now killed that bug you previously sold. So long that was disclosed to the buyer though, I imagine you're all set.


Odds are the black market guys find out. I don't know how the market works, but I'd be pretty pissed if I had bought a hole just for it to be patched soon after.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: