PS: and by the way, I'm in no way circle jerking, this is not reddit, I'm here for a serious discussion on the topic.
PS: and by the way, I'm in no way circle jerking, this is not reddit, I'm here for a serious discussion on the topic.
There is virtually no market at all for serverside bugs, because they have no half-life: as soon as they're detected, they stop working against all targets instantaneously. Contrast that with browser clientsides, which have long half-lives.
A SQL injection bug in a Facebook service would not fetch much more than $50 from anyone but Facebook itself.
- How likely it is for someone else to find it (even internally)
- How long does it take for it to be identified and exploited, the impact of that, and time for mitigation/fixing
- How much would it cost to repair the trust of the users if the breach occurs. PR, marketing, organizational costs
Do you think a big company would pay $5k for a PR campaign to fix a mess due to a breach of private data? Not remotely.
You don't lock a $1000 bike with an $1000 lock, maybe with a $100 lock though