Thursday, July 12, 2007

Vulnerability Auction Services

Lately, it seems, Vulnerability auctions are capturing a lot of news. As a researcher, I'm not quite sure how I feel about them. There are a lot of items to consider. In the past I've been involved with ZDI, iDefense and others with regards to vulnerabilities being sold. Vendor based solutions generally handle the responsible disclosure aspect of the issue, including dealing with the vulnerable vendor. In an auction based scenario, the seller may not have the opportunity to understand who may be purchaing his or her vulnerability. For some researchers knowing the endpoint of the vulnerability may not be an issue. For others ethics may play a part. It's really an interesting area.. what are the thoughts of the crew out there?