« DHCP NAC enforcement done right - knock no more on NAC | Main | Some special stuff planned for RSA »

January 30, 2007

NY Times article on the market for vulnerabilities

Nytlogo_1 The technology section of the Times today has a good article on the vulnerability market by Brad Stone.  Not vulnerability management, but vulnerability research and the buying and selling of vulnerabilities and the motives of the people doing it. It starts out with the current quest for finding vulnerabilities in Vista. The public side, it points out is being financed by companies like iDefense/VeriSign. While no one is endorsing the iDefense program, the article points out that it pales to some of the underground markets for vulnerabilities.  Trend Micro claims there was a Vista flaw on sale for 50k.  From there the article tries to give the Times reader a glimpse into the seamier side of vulnerability research.

What I thought interesting is when they discuss responsible disclosure and the changing profile of vulnerability researchers.  What are the factors driving this?  First of all the increasing cost and complexity of finding new vulnerabilities. Also, while many vulnerability researchers would find vulnerabilities for the glory, now people say "show me the money".  Legitimate sources don't pay enough money for less scrupulous researchers and so they hawk their findings on the back channels of the net.  I don't think any of this is earth shattering to those in the security business, but I am always amused when I see this stuff go mainstream in a publication like the Times.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d834deb90753ef

Listed below are links to weblogs that reference NY Times article on the market for vulnerabilities:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005