Google, Amazon, Facebook, and Akamai (off the top of my head) will each pay that without batting an eye; that's $480k/yr. right there. I imagine they could probably get some banks in that club as well.
Google, Amazon, Facebook, and Akamai (off the top of my head) will each pay that without batting an eye; that's $480k/yr. right there. I imagine they could probably get some banks in that club as well.
If I find a vulnerability in code from a project which is pulling this sort of stunt, I will make sure I share details with distributors only under the strict condition that they are not allowed to tell the project about it.
Responsible disclosure usually means "start by telling the authors", because usually the authors know who needs to be contacted and will do that responsibly. If they're just going to sell off exploits to the highest bidders, they should have no role in the disclosure process.
Given how important OpenSSL is to the web's infrastructure (and the many companies who utilize it), I think there would be value in ensuring it has appropriate resources to fulfill that duty. This idea may not be a perfect solution, but calling it a "stunt" is hyperbole, IMO.
In my years as FreeBSD Security Officer, we in very rare cases gave advance notice of vulnerabilities to end users, and those decisions were made on the basis of "we happen to know that these people are using the software in a way which makes them particularly vulnerable". (In most or all such cases we didn't even provide a patch, just a warning of "make sure you have people around at 10AM tomorrow in case you need to release an update quickly".)
Nobody ever got advance notice by virtue of having donated money, and I reminded Security Team members that they should not give any advance disclosure to their employers.
Yes it is. If you disclose early to a select group, you are by definition delaying details to everyone else.
The paid early disclosure stuff used to exist all over the place, and it was a joke in terms of it being immediately leaked to those in the know.
What would you say if this was worded more like Patrick's "priority support" clause in his analysis of Tarsnap?Practically it would just mean they send an email to the priority support list before they send it to the listserv. I still think major enterprises would get on board.
Mail servers are fast enough these days that I don't think that it really matters what order the emails go out in. Maybe someone would want to pay to get a phone call when an advisory goes out, though.
I have no objection to providing support for paying customers, e.g., to help them figure out if they're affected by a bug. But money should not result in you hearing about a bug any earlier.
The goal is to give businesses who are already in the early-warning club an excuse to write $10k checks every month. The intention was not to solicit anyone and everyone.
It would continue to only be offered to organizations who are (in the collective opinions of the OpenSSL project leaders) going to neither leak nor use the vulnerability -- exactly what happens today.
They would be allowed to (and, I'd hope, would) waive the fee if a major stakeholder were obstinate about it, because (I hope) they actually care about the security of the Internet.
Also it assumes the OpenSSL team are the first to know about vulnerabilities. Heartbleed has shown that's not always the case.
2. Wait for next vulnerability
3. Immediately sell details to hackers via bitcoin
4. ???
5. PROFIT
Unless critical vulnerability is exploited in the wild, it should first be disclosed to big Linux distributors so they can prepare patches and to companies responsible for critical Internet infrastructure so they can fix their system before telling general public. With this proposal you just charge companies who can afford it membership fees and provide this service for free to open source/non profits who could not afford it.