Dailydave mailing list archives
Re: Vulnerabilities Market
From: Steve Shockley <steve.shockley () shockley net>
Date: Mon, 24 May 2010 16:18:02 -0400
On 5/23/2010 7:20 PM, Shane wrote:
Crediting those who donate vuln/exploit information with tax deductible receipts. Maybe then we would see some real ROI for the research/work put into these things.
Who sets the value? Without a market with real money changing hands, it's all just speculative. If you're selling a vuln and nobody will give you at least 50% of what it's worth, perhaps you're asking for more than double its value. With this, if I find I need some tax deductions, I can write some crappy PHP CMS that nobody uses and post it on Sourceforge under an alias, then "find" some security holes and donate them for the write-off. _______________________________________________ Dailydave mailing list Dailydave () lists immunitysec com http://lists.immunitysec.com/mailman/listinfo/dailydave
Current thread:
- Vulnerabilities Market Jason Syversen (May 19)
- Re: Vulnerabilities Market Michal Zalewski (May 21)
- Re: Vulnerabilities Market Shane (May 24)
- Re: Vulnerabilities Market Steve Shockley (May 24)
- Re: Vulnerabilities Market Shane (May 25)
- Re: Vulnerabilities Market Shane (May 24)
- Re: Vulnerabilities Market Michal Zalewski (May 21)
- Re: Vulnerabilities Market rajat swarup (May 21)
- <Possible follow-ups>
- Re: Vulnerabilities Market Michal Zalewski (May 24)