6 ms·
Security researchers do the work and MS wants the information for free. If MS really wants to fix the problem, let them pay. I don't see the problem with this
by Antiks72 14y ago
Security researchers do the work and MS wants the information for free. If MS really wants to fix the problem, let them pay. I don't see the problem with this.
- nezza-_- 14y agoThe problem is that they do not sell vulnerabilities. They sell weaponized exploits. This is not the Zero Day Initiative.
- cdh 14y agoImagine if someone researched and sold exploits to anyone (“terrorists”, foreign governments, etc.) internationally which allowed illegal access to say, real-world bank vaults, nuclear military technology, or high security prisons. Theoretically, your same logic would be valid, but I'm fairly sure selling that kind of information on any one of those would be illegal. If not, than it should be! It's an exaggerated example, but it seems to me that sometimes what is in the best interest of everyone as a whole outweighs the desire of some individuals to exploit the weaknesses of others for personal gain.
- m0nastic 14y agoI have a hard time supporting any position that argues that the dissemination of information should be illegal. The U.S. government tried a variation of that through export restrictions of cryptography. I'm not a particularly big fan of firms that sell vulnerabilities (full disclosure: I've never sold any vulnerabilities I've discovered), but I would be incredibly uncomfortable with the idea that there should be a litmus test for what information is safe to trade, and what isn't.
- yuhong 14y agoThis would only apply to selling information on zero days.