Poll: Do You Love Or Loathe Zero-Day Exploit Merchants?

Zero-day exploit merchants – those who sell information on vulnerabilities and tools for taking advantage of them for significant sums  of money – are a controversial bunch.

They’ve had many criticisms levelled at them. They’re merchants of death, said notable privacy campaigner Christopher Soghoian. They sell “burglary tools”, said the University of Cambridge’s Professor Ross Anderson.

Bad for security?

The main argument against them is that by selling at high prices – as much as £500,000 for one exploit – to government organisations, and not informing vendors, they are not only fanning the flames of cyber war, they are denying security for the 99 percent. They know about flaws in widely-used software and don’t want them to be patched, their enemies claim.

According to Anderson, exploit sellers are infiltrating open source software development, placing bugs in purposefully, only to highlight them when the product is generally available. They point out the flaw they created and earn money from it. If that’s happening, that is terrible news for security.

But exploit sellers have been biting back recently. At their opponents, at journalists and even at themselves. In our report on the market, the sellers said the talk of dirtying open source software was nonsense. And they claimed they were only benefiting the security world by finding vulnerabilities.

But what do you think of them? Would you buy from  them, or are they just too expensive? Let us know by voting below!

Loading ...
Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Apple Sales Rise 6 Percent After Early iPhone 16 Demand

Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…

22 hours ago

X’s Community Notes Fails To Stem US Election Misinformation – Report

Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…

23 hours ago

Google Fined More Than World’s GDP By Russia

Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…

24 hours ago

Spotify, Paramount Sign Up To Use Google Cloud ARM Chips

Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…

2 days ago

Meta Warns Of Accelerating AI Infrastructure Costs

Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…

2 days ago

AI Helps Boost Microsoft Cloud Revenues By 33 Percent

Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…

2 days ago