RE: Trend Micro's Vista "0day exploit auction" claim
- From: "Chris Poulter" <Chris.Poulter@xxxxxxxxxxxxxxx>
- Date: Wed, 20 Dec 2006 10:54:18 +1100
50k per vulnerability opposed to hundreds (unlikely) 60-100k/year
(unlikely) - the Q/A's might only get 40-50k/year, a security
vulnerability technician would be the one getting paid the big bucks,
but there wouldn't be "hundreds" of them? - how do you work that one out
to be more feasible?
Considering everyone is presuming there will be lots of exploits,
50k/exploit will equate to a much larger payout....
And exploit the exploiters? - how do you figure this one as well?
Someone getting paid 50k/exploit is far more beneficial to the
"exploiter" than getting nothing and just sharing the love....where MS
would lose out more if this happened and leave them more exposed...
I'm not arguing for either side of the case as I haven't looked into it
enough to make my own judgment, but I don't think your assessment is
accurate...
-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of Cody Tubbs
Sent: Wednesday, December 20, 2006 10:40 AM
To: Radu Oprisan
Cc: pen-test@xxxxxxxxxxxxxxxxx
Subject: Re: Trend Micro's Vista "0day exploit auction" claim
It's cheaper to pay kids 50k for actually finding flaws, rather than
paying hundreds of QA engineers 60-100k a pop to spend months finding
nothing. Another reason M$ sucks, exploit the exploiters.
-Cody Tubbs
Radu Oprisan wrote:
Ryan Meyer wrote:CTO,
A number of popular tech news sources are reporting Trend Micro's
zero-dayRaimund Genes, publicly claiming that there are "auctions" for
fetchingWindows Vista exploits. Further, he claims these auctions are
FUD.approx $50,000.
Could anyone verify Trend Micro's claim?
It seems dubious, at best, to me and possibly nothing more than pure
Sorry to get off topic.
Ryan Meyer
This could also be some covert way for microsoft to find their own
vulnerabilities. That has happened before.
- Follow-Ups:
- Re: Trend Micro's Vista "0day exploit auction" claim
- From: Cody Tubbs
- RE: Trend Micro's Vista "0day exploit auction" claim
- From: Sels, Roger
- Re: Trend Micro's Vista "0day exploit auction" claim
- References:
- Trend Micro's Vista "0day exploit auction" claim
- From: Ryan Meyer
- Re: Trend Micro's Vista "0day exploit auction" claim
- From: Radu Oprisan
- Re: Trend Micro's Vista "0day exploit auction" claim
- From: Cody Tubbs
- Trend Micro's Vista "0day exploit auction" claim
- Prev by Date: Re: Trend Micro's Vista "0day exploit auction" claim
- Next by Date: RE: Trend Micro's Vista "0day exploit auction" claim
- Previous by thread: Re: Trend Micro's Vista "0day exploit auction" claim
- Next by thread: RE: Trend Micro's Vista "0day exploit auction" claim
- Index(es):
Relevant Pages
|
|