Dailydave mailing list archives

Re: Vulnerabilities Market


From: Michal Zalewski <lcamtuf () coredump cx>
Date: Fri, 21 May 2010 15:58:57 -0700

I agree, the multiple-decimal percentages aren't real useful.

No, my point is that the whole study is probably meaningless. With 26
data points, I am guessing they had about 10 participants, yet ask
incredibly granular bucketing questions. The results are going to be
just random.

Looking at the volume of vulnerabilities released by ZDI and the
likes, it's evident that hundreds of sales are taking place every
year, so it's not just that the market is very small.

/mz
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: