Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

What if this turned into an open source client combined with a standardized API for reporting vulnerabilities directly to vendors and similar escrow services?

Ultimately, yes, it's meant to be easier and more open than current initiatives.



I think that could be interesting then.

One thing that can make it more useful than ZDI is that you lower the barrier of acceptance for a bug. In ZDI, you send them the bug, they decide if they want to buy it from you, and if you accept, they work with the vendor to get it resolved.

I can see numerous examples of bugs that they wouldn't necessarily be interested in buying from you, that a system like this could still provide for.

I happen to be in the camp who thinks the biggest problem with vulnerability reporting is the lack of response from vendors. A system like this, if it were to become popular, could serve as another way to keep them honest. But in order for it to be ubiquitous, you'd pretty much have to handle dealing with the "biggies", which I think would mean submitting vulnerabilities in the way they advertise.

I agree that it shouldn't ideally be up to the vendor how they deal with vulns, but I think you'd have to have tremendous momentum to shift that burden from you to them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: