Skip to main content

Exploit Sales: The New Disclosure Debate

posted onMay 16, 2013
by l33tdawg

The security community is one that thrives on controversy, drama and debate. For years–decades, really–no topic satisfied this desire like vulnerability disclosure. Long after every possible argument had been forwarded and the horse was not just dead but buried and the grave covered by a strip mall, the debate has limped along, like Happy Days post-shark jump. Now comes the flood of bilious opinions regarding the commercial exploit market, a discussion that feels even more pointless than the disclosure debate because there’s absolutely nothing to debate.

In the beginning, the disclosure debate was just that, a debate. People with well-formed opinions based on their experiences with finding and publishing vulnerabilities, or, on the other end of the equation, dealing with those reports and fixing the bugs. Most researchers argued that they had the right to do what they wanted with the vulnerabilities they found. For a long time, researchers generally kept details private and dealt with the vendors in the background, only publishing the details when a fix was ready. There were exceptions, researchers who simply published what they found whenever they felt like it, either never notifying the vendor or doing so a day or two before they posted their advisories.

Source

Tags

Security Industry News

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Simplenews subscription

Stay informed - subscribe to our newsletter.
The subscriber's email address.
Keeping Knowledge Free for Over a Decade

Copyright © 2018 Hack In The Box. All rights reserved.

36th Floor, Menara Maxis, Kuala Lumpur City Centre 50088 Kuala Lumpur Malaysia
Tel: +603-2615-7299 Fax: +603-2615-0088