> Recently, there have been several articles about the new market in zero-day exploits: new and unpatched computer vulnerabilities.
It's not a new market. Exploits have been bought and sold (as far as I'm aware) going back into the 90s. My visibility of the market ends there, but it may well go back further. Companies like ZDI, Immunity and Rapid 7 have been in this market for a long time (doing different things), but it shows that there has been a market for a while.
> This market is larger than most people realize, and it's becoming even larger.
I suspect that the impression of the market becoming larger is due to more of the market being publicly visible, which in turn may generate more interest and growth, or may not.
> In fact, it took years for our industry to move from a norm of full-disclosure -- announcing the vulnerability publicly and damn the consequences -- to something called "responsible disclosure": giving the software vendor a head start in fixing the vulnerability.
This is quite a shocking statement for me to see. The industry (if you want to call it that) didn't push for "responsible disclosure", the vendors did. "Responsible disclosure" was nothing more than a marketing statement to shift the blame from the origin of a software defect to the person disclosing it if they didn't toe the vendor line on waiting months or years for a fix and keeping shtum at the time.
> This is why the new market for vulnerabilities is so dangerous; it results in vulnerabilities remaining secret and unpatched.
This assumes that software security is a zero sum game, which it isn't. Just because a bug exists and a zero day exploit exists, doesn't mean that you'll be exploited. A zero day exploit in VLC doesn't automatically result in compromising your system if your usage pattern for VLC doesn't intersect with the exploit pattern.
> No commercial vendors perform the level of code review that would be necessary to detect, and prove mal-intent for, this kind of sabotage.
> And unlike the previous reward of notoriety and consulting gigs, it gives software programmers within a company the incentive to deliberately create vulnerabilities in the products they're working on -- and then secretly sell them to some government agency.
> No commercial vendors perform the level of code review that would be necessary to detect, and prove mal-intent for, this kind of sabotage.
This is utter FUD. Vendors like Microsoft routinely work with governments directly to provide secure products, while the governments in question have their own teams to spot vulnerabilities and develop their own bugs. They don't need a vendor programmer putting bugs in for them, it would massively damage the relationship if they were caught.
> With the rise of these new pressures to keep zero-day exploits secret, and to sell them for exploitation, there will be even less incentive on software vendors to ensure the security of their products.
Except for the fact that we have legislation and regulation at the end-user side that makes software security a requirement for a vendor, something we didn't have 20 years ago. Many larger vendors already have a fully integrated process for security management. Companies like Microsoft have even gone public with the Security Development Lifecycle.
I would make the counterpoint that the disclosure that the market exists makes responsible vendors even more determined to build more secure code. A vendor without a software security capability is no different whether or not there's a public market as the bugs will still exist and going from bug to exploit isn't necessarily hard when the vendor hasn't considered security. A vendor with a mature software security capability will build in layered defences to ensure that the cost of exploit development grows higher.