logoalt Hacker News

tptacektoday at 12:39 AM3 repliesview on HN

If the vulnerability is already being exploited in the wild --- as in, it's a vector people already know about and are tracking --- it's possibly not worth much at all. Vulnerability valuations depend heavily on the lifespan of the vulnerability; payments on black market are tranched (explicitly or less explicitly, as with "maintenance payments") based on whether they're patched.

Further: a vulnerability is probably not worth that much either, even if it's a hypercapable vulnerability, because the grey market buys full enablement kits, not vulnerability information. People making 6 figures on vulnerabilities are selling fully enabled full chain exploit systems, not just intelligence about a sandbox escape.


Replies

nixon_why69today at 2:42 AM

That's really informative but maybe a little overly capitalist-brained.

We shouldn't look to the black market as cost discovery for these vulnerabilities, most non-criminal researchers are not putting up an ask order and letting the black market compete with Google.

show 1 reply
0xbadcafebeetoday at 2:09 AM

How much money is lost by consumers/businesses for every hour the vulnerability is exploited in the wild with no patch?

show 2 replies
fr2029today at 3:24 AM

[flagged]

show 3 replies