Maybe a good business is bug escrow company.
Maybe a good business is bug escrow company.
From wikipedia:
> Factoring is a financial transaction and a type of debtor finance in which a business sells its accounts receivable (i.e., invoices) to a third party (called a factor) at a discount.[1][2][3] A business will sometimes factor its receivable assets to meet its present and immediate cash needs.[4][5] Forfaiting is a factoring arrangement used in international trade finance by exporters who wish to sell their receivables to a forfaiter.[6] Factoring is commonly referred to as accounts receivable factoring, invoice factoring, and sometimes accounts receivable financing. Accounts receivable financing is a term more accurately used to describe a form of asset based lending against accounts receivable. The Commercial Finance Association is the leading trade association of the asset-based lending and factoring industries.[7]
For example, let's say I own a sheep farm. I hire people to trim the sheep, and they produce a bunch of cotton. Without the Bill of Exchange, if I want to pay the people I've hired then I will need to ship this cotton to the spinner, who then ships the spun cotton to the weaver, who then ships the woven cotton to the clothier, who then makes clothes and sells it to a consumer. Only after this has happened can I pay my employees with the money of the paying consumer.
With the Bill of Exchange, a bill is created when I deliver cotton to the spinner. This bill will require the spinner to pay me for the cotton delivered in e.g. three months. I can then take this bill to someone who trusts that the spinner will pay me in three months and ask them to buy the bill at a discount, such that they are paid in three months (when the bill expires). I can then use the proceeds from the sale of the bill to pay my employees immediately. And the buyer of the bill earns a bit of interest because he pays less for the bill than he is paid at maturity.
[1] https://professorfekete.com/articles/AEFMonEcon101Lecture5.p...
[2] https://professorfekete.com/articles/AEFMonEcon101Lecture6.p...
1. Company verifies the bug
2. Assigns it a price according to impact
3. Keeps details hidden until Apple pays them, then reveals the bug. Thus Apple is forced to pay, but bad actors dont get access.
Different bug markets can compete to correctly price bugs.
An alternative is public offer when Apple promises to not release a fix without payment. If it's not a bug, no need for a fix.
I agree with you on a moral basis: what difference does it make if I get payed not to publish it vs. If I just publish it without even asking to get paid. But I'm not sure the law would agree with us.
In this case you aren't just a vigilante targetting apple, there is established practice stretching decades.
There is also a duty on you as a security proffeshional, and there is a significant public interest in knowing about the vulnerability. So , most likely, it will be you doing your job.
Most countries have a culture against whistleblowers, starting from childhood ("don't be a tattletale", "don't be a rat").
If there is no intent to abuse the bug when not paied then there is no additional threat there from simply notifying the company that some threat is already present. How it can become a black-mail?
So every report about discovered bug can be considered as black-mail? If one discovers a bug, reports it to the company and says that after 3 months it will be public it's a black-mail too?
Or the payment request makes it different? And if person doesn't threat to publish the bug then it's ok?
[0] https://www.justia.com/criminal/offenses/white-collar-crimes...
Whoever, with intent to extort from any person, firm, association, or corporation, any money or other thing of value, transmits in interstate or foreign commerce any communication containing any threat to injure the property or reputation of the addressee or of another or the reputation of a deceased person or any threat to accuse the addressee or any other person of a crime, shall be fined under this title or imprisoned not more than two years, or both.
https://uscode.house.gov/view.xhtml?path=/prelim@title18/par...
What is a bugs correct price? The price that a bad actor would pay for it?
- Apple is a $2T company, that we trust with our data. That valuation is in part based on that trust. It's entitled of Apple to produce a product that contains shitty exploitable symlink handling and continue to have no meaningful repercussions (which is true in the industry as a whole).
If this was a bug in a small, under-resourced FOSS email client, or the exploit required many highly skilled person-years to find, maybe I'd feel differently.
People tend to vastly overestimate the economic impact of an exploited security vulnerability. A vulnerability which can be patched in a centralized manner has a low value half-life: it rapidly decreases in value over time. I would guess over 90% of active daily users of macOS already have the patch for this bug due to automatic updates. New buyers are essentially guaranteed not to have the vulnerability at all. The vulnerability would have to be absolutely catastrophic to be worth something, and in that case it would probably be used for targeted exploitation and burned after a short period of time.
Contrast with something like heartbleed, which is still around. That is a vulnerability with serious half-life and significant economic impact. The pool of available victims who can be exploited by heartbleed is nontrivial and persistent years later. Criminals will actually pay for something like that.