|
|
|
|
|
by riferguson
6297 days ago
|
|
Miller says that the bugs have a market value beyond $5000 -- indeed, he claims that an IE8 exploit has a "market value" of over $50k. But that market value exists only if you're willing to sell the exploits to people who either (a) are planning to use them or (b) want to fix them. The former group are the ones setting the market value, since they're the ones who are going to monetize the exploits. The idea of announcing NO MORE FREE BUGS really amounts to saying to the world "I'm either going to sell my work to criminals, or am going to participate in an ongoing blackmail scheme to make myself rich." Nice. Good luck with that, Charlie. |
|
But I have two problems with where you're going.
First, finding a bug in your own time and not telling Apple about it unless they pay you isn't blackmail. Charlie Miller bills $300/hour. His work product is worth money. Apple has no right to confiscate it. If the dilemma was, "pay up or it's going to the Russian Mafia", it'd be blackmail. But if you think Charlie Miller is selling vulnerabilities to the Russian Mafia, you're a jackass.
Second, the reason you don't see me at CanSecWest --- well, one of them, another being that Nils and Charlie and Dino would crush me --- is that I spent all day reversing protocols, writing fuzzers, and finding flaws. For cash. Vendors pay us, and so do large companies that buy from those vendors. It's my day job; it's a job; money changes hands. How is Charlie's proposal different?
I think it is different. But it's way more subtle than you're making out to be. It's also a common industry practice, so making him the face of it isn't a great play.
(You can see where we stand on this: http://www.matasano.com/log/mtso/ethics/).