Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...
Now, with EDR widely deployed it's likely that the exploit usage ends up being caught sooner than later, but pretty sure some dictatorship intelligence agency would have found all those journalists deep compromise worthwhile...
How?
I've been paid by bug bounties (although not that big) and I have no idea how I would find a trustworthy criminal to sell to.
I guess I'd need to find a forum? Unless my opsec is exemplary then I'm risking being exposed. I'd need to vet that the buyer would actually pay me and not just steal it from me. Even if they do pay me, I'd be worried that they'd blackmail me or try to extract something from me. But assuming they're good black-marketeers, I still have to explain to the authorities where this large amount of cash came from.
So how do I go about selling to the black market in a safe way?
Oh, and I don't get to write a blog post about the bug or get my name in front of other researchers and recruiters. That can be worth a huge amount - both in cash and reputation.
There are companies that specialize in getting grey market bugs in important software, ie browsers and OSes. They are repwat players and have a reputation to actually pay out.
How much of a premium are they paying to make it worthwhile?
You can find some by researching. AIUI most intros are via personal connections. I'd be wary of the potential ethical implications. There is more than money to life.
Sure, I'd say the "sell it elsewhere" stuff is always a bit overly optimistic but due to the nature of this specific exploit I am pretty sure you could find a buyer offering good compensation.
You can also go through ZDI (owned by Trend Micro), but the payout will be lower. It’s in Trend Micro’s interest so they can get ahead in detections.
Yes, maybe the exploit could likely be modified to be more reliable. That's more work though.
Or just sell it to the israelis.
Not going to happen.
Between 'calculative trust' and 'personality based trust' there are many poles (and other varieties of trust besides), on the whole you're much better of trusting a non-criminal than a criminal.
It won't be tax-free, though; you'd probably get a 1099, but if you're smart could set it up as corp to corp and deduct a bunch of other expenses from it. Part of the sale is signing a bunch of NDAs, etc so you can't then release it to others.
The exploit developer avoids violating the CFAA by developing the exploit on their own computer... because you are authorized to access your own computer.
The government doesn't violate the CFAA when using exploits because government agencies are exempt under 18 USC § 1030 (f)
CFAA doesn't have anything to say about vulnerability research itself. You'd be just as liable as an accomplice if you knowingly and deliberately provided free wi-fi to a hacker.
That makes me wonder - may be the original bug was really a backdoor created as a result of a deal with an intelligence agency/vendor. So, can it be that Google gets money (or more generally some kind of browny points; also interesting aspect - giving that the agencies may exploit individual engineers, it would seem to be more preferable for the company to play ball and have it organized under the company's control) for a backdoor, and once backdoor is found - pays the bug bounty. The bug bounty is thus a kind of backdoor quality control program :)
unless you are an agent posing questions to get people to sink themselves.
Getting paid in cryptocurrency isn't necessarily a dodge either because even if you claim you mined it or something, the authorities have got wise to this a while ago IIUC and will expect to see evidence to back that claim up too.
They also have every incentive to make sure you're guilty enough to not go blab to the authorities later, or sell it to someone else.
And since you're trying to be anonymous in this, you aren't going to be getting a regular tax receipt either.
I grew up in an area known for people growing cannabis before it was legal. An enormous amount of taxes got dodged through cash land deals, but tons of people just claimed the income under various categories and no one ever came knocking because of that.
Its usually the other way around. If you caught the Fed's eye, then they might try to get you on tax evasion or something. Although, frankly even that was very rare. There are just a lot of very obvious fish to fry.
https://www.irs.gov/publications/p525#en_US_2024_publink1000...
>Illegal activities.
>Income from illegal activities, such as money from dealing illegal drugs, must be included in your income on Schedule 1 (Form 1040), line 8z, or on Schedule C (Form 1040) if from your self-employment activity.
> but you'll also have to come up with a fake but auditable story of where it came from
And now you did.
That thorny ethical issue aside, I'm fond of pointing out that the IC's main alternative to CNE intelligence collection is human intelligence, and the cost of HUMINT simply in employee benefits dwarfs any near-term possible cost of exploit enablement packages; 7 figures is a pittance (remember: most major western governments are essentially benefits management organizations with standing armies).
Even given the seemingly vast sums earned by organized crime, government buyers are positioned to decisively outbid crime over the medium term. It's really early days for these markets.
In that light, what others would do is rarely a reliable indicator that you shouldn’t think twice about your actions, lest you regret later, once the thinking has happened.
My point is that this fact shouldn’t belong in a discussion about ethics, given how often widely held moral positions have come to be a source of regret.
Security services tend to anonymously report security flaws they use after use against any high value target, since they don't want the opponent using those same flaws back at them.
Yes they will.
If you are the murderer, there will be.
Honestly I’d be more worried about crossing the blackhats.
...come to think of it, how does that work? Aren't the most important exploits to patch the ones being actively used in the wild?
In other words, how do they avoid someone playing both sides? "I found an exploit being used by the LEETH4X0R malware [which was in fact created by the guy I sold this exploit to] to steal people's gmail cookies."
You'd have to find out about LEETH4X0R before other researchers, but of course, you'd have a head start.
The mechanism grey-market buyers have to protect their interests against over-selling bugs is tranched payments. Sellers make much of their returns from bugs on the back end through "maintenance agreements", which both require the seller to keep e.g. the offsets in their exploits current and reliable against new patch levels of the target, and also serve to cut off payment once the vendor kills the bug.
If you sell to both sides, you quickly kill the back end business from the grey market buyers. If you sell to too many or too sketchy grey market buyers, the bug leaks --- vendors see it exploited "in the wild", capture samples, kill the bug; same outcome: tranched payments stop.
This is one reason it can make sense to take a bounty payment that is substantially smaller than what a bug might be worth on the market: you get certainty of payment. Another reason is that the bounty program will only want POC code (perhaps proof of reliability in addition to just exploitability), while the market will want a complete enablement package, which is a lot of work.
Not necessarily. On slide 72 of this presentation, it says sandbox escape or bypass for Chrome is worth up to $200000:
https://nocomplexity.com/wp-content/uploads/2024/06/bluehat2...
(I originally found this presentation on github[1], but github seems down right now[2].)
[1] https://github.com/mdowd79/presentations/blob/main/bluehat20...
[2] https://www.reddit.com/r/github/comments/1mnlgc5/is_github_d...
https://citizenlab.ca/2016/08/million-dollar-dissident-iphon...
You'll think of something. If you can hack one system, you can hack another.
$250k fully legally and with recognition is probably a good incentive not to bother. White hats have their privileges.
Your hookers and blow dealers won't report you to the taxman.
And yeah if you want normal stuff like a house or car you'd need to wash the money. How do I know? Breaking Bad. Which lets be honest is probably for most of us, our only reference point here.
[1] https://www.elizabethhoney.com/45--47-stella-street.html
The IRS isn't referring suspicious (whatever that means) tax returns to the authorities. What happens if you are a criminal is that the authorities have there attention on you because you are doing illegal things. One angle of attack for them is your finances. That is why money laundering exists.
lol
You can't deny that you are way more likely to burn the exploit using it on a machine under watch than on a machine that is not...