logoalt Hacker News

tptacektoday at 12:39 AM4 repliesview on HN

If the vulnerability is already being exploited in the wild --- as in, it's a vector people already know about and are tracking --- it's possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with "maintenance payments") based on whether they're patched.

Further: a vulnerability is probably not worth that much either, even if it's a hypercapable vulnerability, because the grey market buys full enablement kits, not vulnerability information. People making 6 figures on vulnerabilities are selling fully enabled full chain exploit systems, not just intelligence about a sandbox escape.


Replies

rileymat2today at 5:18 AM

I was under the impression that the three letter agencies and contractors bought vulnerabilities?

nixon_why69today at 2:42 AM

That's really informative but maybe a little overly capitalist-brained.

We shouldn't look to the black market as cost discovery for these vulnerabilities, most non-criminal researchers are not putting up an ask order and letting the black market compete with Google.

show 1 reply
0xbadcafebeetoday at 2:09 AM

How much money is lost by consumers/businesses for every hour the vulnerability is exploited in the wild with no patch?

show 2 replies
fr2029today at 3:24 AM

[flagged]

show 3 replies