Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Isn’t the implication that the vulnerability had already been found and exploited instead of reported to Google, because its value to Google was so low? Whoever found it originally had more incentive to sell it on the grey/black market. Or is the incentive structure truly different for vulnerabilities discovered to be already in the wild?
 help



Some exploit hunters sell strictly to the grey/black market to avoid opsec issues. If you're selling on both, you're more likely to be identified by both.

Surely google has telemetry when their sandbox is escaped? (Only mostly /s)



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: