Hacker News new | ask | show | jobs
by loloquwowndueo 7 days ago
Depending on those vaunted “security researchers” to take point and find all vulnerabilities in all packages is also fairly naive. That process costs money and produces a fairly valuable result - why would they give it away for free? So this will inevitably evolve into targeting only the high-value most popular packages and the exploiters will retreat to the long tail of less-popular ones. Lower payoff? Sure, but beats zero payoff.
1 comments

Finding vulns in popular OSS and disclosing is probably good for your reputation as a security researcher, even if it's not immediately profitable.
How is that sustainable?

Are security researchers going to be doing free labor for you indefinitely for exposure?

They sell their products using the credentials they gained.

I’d never heard of socket until they found and reported shai hulud hiding in pytorch lightning. It pays off.

What happens after a couple of players have obtained marketshare and the market has consolidated?

I think there are diminishing returns to be had.

This is essentially Snyk's business model. Sure, they do upsells, but it seems fully sustainable to me.