Hacker Newsnew | past | comments | ask | show | jobs | submit | asdfaoeu's commentslogin

Blackhat markets will always be able to pay better. Selling to Google though you aren't chancing jail time.

> Blackhat markets will always be able to pay better.

... than Google?

> Selling to Google though you aren't chancing jail time.

Why would you go to jail for selling a vulnerability? It's free speech.


"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.

Has anyone actually been convicted of abetting a crime by selling a vulnerability, by itself, not conspiring with the buyer to commit a crime using said vulnerability? Not as far as I can see. It would be absurd to jail someone for accurately describing a bug.

It would be absurd to jail someone for accurately describing a bug on their blog or whatever.

Not so much for taking money from someone who the buyer should know has no reason to be interested in buying the information. And either you know who your counterparty is, in which case you know that they are using it nefariously, or you don't know who your counterparty is, in which case you know that they are using it nefariously. Any court and any jury should see straight through this.

Similarly if you figure out how to get the ATM down the street to give you free money, and you "accurately describe the bug" to people who pay you, and they use it to steal money from the ATM, expect to be charged for participating in, and in fact being an instrumental enabler of their crime. Because it is beyond all reasonable doubt that you could've believed they could have been interested enough to pay you for any other reason.


Has anyone actually been charged and convicted for disclosing knowledge of a vulnerability in exchange for money with no further collusion to commit a crime?

Jeremy Jethro seems to be an example. His lawyer claimed he had no knowledge of what the exploit would be used for, and that it didn't even work, but he ultimately pled guilty to criminal conspiracy.

Hmm. Are you aware of any publicly identifiable security researchers that openly talk about selling their exploits on the black market?

Since it's all so legal and risk-free, you'd think selling an exploit for a million bucks would be quite the feather in their cap!

It may also be helpful to visualize being interviewed by the FBI and being asked "Did you sell this exploit? To whom? How much did you receive? For what purpose did you think it would be used?". And to remember they already know the answers to these questions, and lying to the FBI is also a crime.


My question stands.

"this vulnerability is being sold for research purposes only and must never be used outside of a tightly controlled research sandbox"

courts are very good at reasoning about things like this and figuring out its bullshit. Zerodium is probably the closest you could get to some reasonable denial about this. Selling an exploit on crime.com for "research puposes only" will get you laughed at on the way to the cell.

Telling someone the steps to rob a bank world probably catch you some charges, I'm assuming.

Are true crime authors going to jail? Or even authors of heist fiction?

No, it wouldn't.

I don't think they are saying it's trivial but compare say for example switching an organisation from Office or Windows the example that started this. They are not even in the same ballpark.


> one confidential, trusted place to coordinate discovery, remediation, and disclosure

I read this they would build the patches privately (or with maintainers if confidential) and then share amongst their supporters before public release.


> No one looks at Debian and is saying "well maybe we should do what they do"...

Arch does exactly what Debian for the official repos. It was only the AUR that was compromised. Possibly the issue is that Arch is a bit to strict for the official repos which has forced too many people on to the AUR ones.


Ubuntu has personal PPAs that are easy to setup - but Ubuntu has a good system to get everything into mainline (mostly because Debian has nearly everything and they ship Debian) and so they are rarely used. Arch has vastly less official packages and so there are a lot of niches where you have to use a AUR.

I don't think the issue is Arch is to strict though. I think the issue is Arch isn't good at helping people getting things that should be official to official. Publishing a AUR is easy, getting something from an AUR to official is hard and most people give up - often without trying.


The AI can't actually tell if you are trying to patch your own system or exploit others.


It seems like ... it's not illegal to find exploits, it's illegal to use them. Enforcement should start there, not the nanny state approach that you might do something bad with information. It breaks down a little bit because it means there will be a period of disruption while the bad guys use exploits - but that's already illegal, and the good guys have had time to use the tool & fix things before it went public, right?


Sounds like something they should work on before any potential future releases. I can, and this thing's explicit stated purpose is to do my job.


It seems to use DHT under the hood whether directly or through a relay. https://pkdns.net/ .


That is a pluggable/possible, but non-default, configuration.


You would have a lot of security issues right? Whether or not it's useful Wayland does prevent to isolate clients from each other.


They’re right on this one, shared memory isn’t some scary dangerous thing. Both processes will just have some region of their respective virtual address space which are mapped to the same physical memory, which they can use to share data. Wayland already uses this for pixel data.


Not really, you can have one command buffer per client or process, and map each one in the virtual space of the process that's supposed to write to it.


This ruling was about search clearly, however, there's definitely ways implications for chatbots too.


Google does remove defamatory results I believe at least partially in response to being sued. However there is a distinction if they have been informed it is defamatory.


In this case it looks like they were notified and didn't do anything.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: