You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
You can do so much damage/return with an exploit that affects > 30% of the population. Get 5 of those and sky is the limit.
I think this has a lot to do with government agencies buying any exploit they can get their hands and there is basically no market besides that. I don't know if that is illegal in the US, but it seems that government is the only buyer.
Extremely unlikely. The risk/reward if found out is too lopsided. Conviction for insider trading has you pay a penalty and transform your fund into a family office -- Raj Rajaratnam going to prison for a decade is a unique exception not the rule.
Conviction for insider trading in combination with wire fraud, espionage, and all the other exploit-related charges will send everyone involved to prison for 10-20 years, pretty much guaranteed. What use is a bigger hedge fund if you have that sword of Damocles hanging over you?
Lots and lots of other charges but if no insider is giving you info then it wouldn’t be insider trading.
What would be 100% legal would be if you bought an exploit and then traded on the release of that exploit. Depending on the severity of the exploit it could move the stock price a bit. And, even though people wouldn’t like it, that’s kind of the point of the market. You get rewarded for helping with information and price discovery.
What does this mean?
Some companies put a lot of effort in security (Apple, Google, Facebook, etc). Usually they have engineering driven cultures.
The other majority of companies see security just as a cost center that needs to be covered in order to reduce legal liabilities.
The second kind of companies do not have a bug bounty programs because they know that they have too many holes and prefer not to attract too much interest.
For those companies that may have huge capitalization and profits, paying $1M for a vulnerability is not practical.
I expect that in general all companies (including those in the first group) detect compromised accounts and services from time to time but unless they have to disclosed because the laws demand it, they prefer to avoid the bad PR and potential lawsuits.
But while I expect the first kind of companies doing a root cause analysis and improving the systems, the companies in the second group of companies usually just clean up the detected compromised systems and avoid to look too much deep because either they do not have the skills or they are afraid to find things they will have to disclose and be liable for.
If I were to discover a vulnerability is there a legal way I could cash in on it (aside from this case with Apple)?
Following this line of thinking leads to some pretty absurd conclusions, like 7% of Tesla's value being predicated on Elon Musk not smoking a joint[1].
1. https://www.cnbc.com/2018/09/07/tesla-sinks-8percent-after-b...
> Shares of Tesla plunge after news of a pair of C-suite executive resignations and a bizarre video showing CEO Elon Musk smoking pot on a podcast.
Also I heard in person, so I cannot quote.
Not sure how legal this is, but there are even vulnerabilities brokers, who set you up with buyers.
100k exploits most likely what has been resold few times over before it reached the "professional infosec" space
I presume that it is a legal minefield, selling 0days and extortion are first cousins, at least. If you could hold a bid, no doubt an Arab country would pay $50 Mil for one...but they buy them from companies that sell "software" and services.
If you found an unfound gaping crater of an exploit somewhere -- how much would that be worth to them? Likely a lot more than $1m. I'm sure you could negotiate that number up, a lot.
But bug bounties like this are competing with the shadier markets. I suspect they found out the shady companies are offering more than their existing bug bounty program did.
As Warren Buffet says there is plenty of money to be made in the centre
It makes sense to invest way over the top if you can kill bug classes outright --- and Apple does this, too. For example, people that were doing DMA hardware attacks against macOS a couple years ago are now on Apple's payroll, designing hardware to defend against those attacks. That's a meaningful serious investment in defense. Rewriting their kernel in a memory safe language would be another example (one they haven't done yet).
Massively outbidding the current spot price for a bug doesn't accomplish anything like that. Think about who they're really bidding against. They can drive the price of bugs way up, and they are doing that gradually, but there will still be a price and people selling them.
The important thing they're doing on this is making unlocked devices available for researchers, and lowering the bar for research for people who would never sell to brokers.
I'm absolutely sure that saudi arabia would pay much more than that for an exploit like that and I don't need to have experience doing it, it's common sense.