Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ideally, an auction and the vendor or a government can bid against malicious actors (which can also be a government). hard to set up though.


What kind of auction would you like to run?

Remember that you can sell the same vulnerability to multiple people: it's software you can copy.


Maybe needs a Good-Guy-Buy-It-Now w/instant delivery at a fair price. (OK that’s kind of a threat—you’re running an auction and you have the price the corp has to pay to avoid the auction ending.)

$1k is so dumb and the fact we’re discussing auctions is proof (hello, Sundar, what you doing over there?).

Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.


> Guess this will change after the next e.g. nationwide hospital ransomware by a hacker who publicly laments bounty rates, if the news cycle accommodates the story long enough.

Negotiating with terrorists or black mailers is a bad idea.


Agreed. Paying security researchers fair rates is a good idea though right? Keeps future researchers honest?


Maybe. But as soon as they threaten to sell it to the baddies or use it for ransomware themselves, I would cease all communication and negotiation.

The legitimate threat the researcher has is to disclose to the general public. (And to disclose the next bug to the general public, if there's no good payment.)


it seems unlikely google's lawyers would go for this


Maybe some code is so important and heavily trafficked it becomes a public works project, and various legs can bid for pieces of the project, line how all infrastructure works.


well that's why setting it up is hard, because you would want to do it in a way that what they want doesn't matter.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: