Dailydave mailing list archives

Re: Vulnerabilities Market


From: Steve Shockley <steve.shockley () shockley net>
Date: Mon, 24 May 2010 16:18:02 -0400

On 5/23/2010 7:20 PM, Shane wrote:
Crediting those who donate vuln/exploit information with tax deductible
receipts.  Maybe then we would see some real ROI for the research/work
put into these things.

Who sets the value?  Without a market with real money changing hands, 
it's all just speculative.  If you're selling a vuln and nobody will 
give you at least 50% of what it's worth, perhaps you're asking for more 
than double its value.

With this, if I find I need some tax deductions, I can write some crappy 
PHP CMS that nobody uses and post it on Sourceforge under an alias, then 
"find" some security holes and donate them for the write-off.
_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: