| > [1]: https://opzero.ru/en/prices/ Those are the prices that they are buying for, they do not indicate at all that these are common or how large the market is for RCE on any OS. > [2]: https://arstechnica.com/gadgets/2025/10/leaker-reveals-which... Those are (mostly) not RCE, and are for consumer devices configured in a default way. --- The parent stated that "Any government can get RCE on any OS with the change in their couch." That implies that Kiribati currently could easily buy RCE on for example hardened Linux or OpenBSD running the most sensitive infra in the world. I just don't buy that, since if it was true any current conflict would look much different. Of course there are security holes and major fuckups do happen, but not at the scale the parent implied. |
> Those are (mostly) not RCE, and are for consumer devices configured in a default way.
I'm more worried about activists and journalists in developing counties without the financial means to afford flagship phones. But even Google can't manage to keep out a pedestrian mid sized security outfit selling to the cops and the FBI.
When activists lobbying for a fucking sugar tax in Mexico get hacked, then the bar is too fucking low.
Let's not talk about the nightmare that is old networking equipment or IoT devices.