Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You might find these slides on the 0day market interesting

https://github.com/mdowd79/presentations/blob/main/bluehat20...

Unfortunately the talk wasn’t recorded but he did do a follow up interview on a podcast called Security, Cryptography, Whatever



That seems to be saying that currently there is no market for website vulnerabilities, but a market for them might develop in the future as memory corruption vulnerabilities disappear due to mitigations.

This Google/Alphabet VRP change I think is pretty much just about website vulnerabilities.

Disclosure: I work at Google but not on the VRP.


Skip to the end if you want to see the numbers.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: