The net result is probably safer software for all.
The net result is probably safer software for all.
Did the .gov pwn TPB and put their exploit up there?
I don't think that follows. Clearly there are folks in some governments who would fund finding zero day exploits so that they can use them to conduct cyber-warfare operations. Stuxnet comes to mind and the HBGary emails were telling in this regard. It seems there is a market for 0 day attacks that are not known to the manufacturer. So while Google would clearly give them $13,373 for the bug report but that is no doubt mouse nuts compared to what the someone would pay them while it's not in the 'known' state.
So I find Vupen's business model not unlike the business of creating munitions. No doubt profitable but not something I'd personally want to participate in.
Safer software for all, because it's a better thing that VUPEN discover the bug than if it's discovered by some criminals who keep it secret and scam/hack
I suppose it depends on the point of view, but having it exclusively in the hands of governments can easily mean it's limited to criminals who keep it secret and hack.
Why would a entity as big as "the government" would invest in breaking one browser used by a minority (~10%) of users in the web? Wouldn't it be much easier to just compromise their Internet connections?