Hacker News new | ask | show | jobs
by tptacek 2116 days ago
Can you support that statement about the black market with evidence?
2 comments

agreed on 5 figures. evidence? there’s even clearnet websites where you can buy vulns. most known would be: https://0day.today
What you see on that website is the cost, not the earnings though. If a private exploit costs $1.2k, you can get 5 digits by selling it 9 times. That isn't a huge number of sales, but I don't know if this exploit would sell that many times. Anyway, by disclosing on H1 you're "selling" at most once.
Zerodium won't buy a Slack exploit. I'm not debating whether there is a black market for exploits; there is. It just doesn't buy most of the things HN commenters think it does.