back
116 comments
People will decry this, but I'd argue a free and open market for vulnerabilities would be a great thing. Here's why:

1) It would result in more vulnerabilities found

This is fairly axiomatic. An open market increases the price of vulnerabilities which in turn increases the number of vulnerabilities found (unless you want to argue the ability to find vulnerabilities is inelastic for some reason).

2) It would result in more vulnerabilities being disclosed to the proper authorities rather than malicious parties

This is more debatable, but since there should always be significantly more incentive on good actors to prevent the exploit (i.e. the software creators and/or community) than bad actors, the good actors should always win the bid. Indeed, one could argue that it is only the prevention of free negotiation in the sale of vulnerabilities is the reason an exploit is ever sold to bad actors (e.g. if I found a Windows vulnerability and told Microsoft $10m or else, I'm a criminal).

3) It would ultimately increase the quality of software

Given more vulnerabilities are found and more vulnerabilities would be disclosed to good actors, the quality of software increases.

I believe that 2) is essentially the Coase theorem (http://en.wikipedia.org/wiki/Coase_theorem), but I am only an arm-chair economist. Also, I'm not sure that what Mitnick is doing actually is a free and open market for vulnerabilities.

I upvoted, not because I agree, but because I believe the people downvoting you are downvoting because they disagree and not because your comment shouldn't be heard.

Imagine he had said: I believe a free and open market for weapons would be a good thing, because it would reduce the number of defenseless people, would result in a power imbalance that puts generally-okay actors at an advantage (say what you will, but the mob doesn't have 1% of the resources the US government does), and would therefore reduce crime.

I do not personally find that argument compelling (and it is of identical structure to the above), but me disagreeing with it does not mean it isn't of sufficient quality for Hacker News.

I'm not sure you can, in practice, have a completely free and open market for vulnerabilities, since any information about the vulnerability released broadly is likely to shorten the path to others discovering the same vulnerability [1], devaluing it implicitly through partial disclosure. So there's an interest in the market being small and secret. For the seller to keep the price high and for the buyer to maintain exclusivity on the exploit.

[1] As a case in point, I showed the headline of the email for the bash vulnerability to a coworker today on the commute and he instantly described in accurate detail how it probably works. Not that this was a particularly difficult case, but I think the principle holds.

> This is fairly axiomatic. An open market increases the price of vulnerabilities which in turn increases the number of vulnerabilities found (unless you want to argue the ability to find vulnerabilities is inelastic for some reason)

Wait a second...won't increasing the number of vulnerabilities found push prices down? If I'm looking to penetrate a system I only need to buy one vulnerability, so in effect different vulnerabilities are somewhat fungible and so should compete on price. Hence, if more vulnerabilities are being found and coming to market, prices should be going down.

On the other hand, with a free and open market for vulnerabilities there would likely be people who would NOT have bought vulnerabilities on the black market buying vulnerabilities on the safer, easier to use free and open market, so demand could go up, raising prices.

>An open market increases the price of vulnerabilities

That's impossible to tell. You could just as easily say that the price will crash when you take away all the costs and risk of running a black market and give buyers a place to compare multiple "products." The demand side could just as easily be inelastic (or at least saturated) as the supply.

> the good actors should always win the bid

This works if you're talking about Microsoft, but not if you're talking about smaller companies or open source products. Maybe a Google or a Facebook would step up and pay off the market for things that they use, but "the rich people will take care of us" is not a setup that I'm comfortable with.

I mostly disagree with arguments to rationalize the sale of exploits, they create a massive power balance towards bad actors, but we have to be honest with ourselves, and like drugs, 0days are not going away.

Our only proper response is secure software development practices, employment of security reseachers, and adoption of security-centric practices in critical systems... such as the Linux kernel. Which is embarassingly not the case at the moment. For ex: http://unix.stackexchange.com/questions/59020/why-are-the-gr...

On your second point.... Governments should be assumed to be bad actors and they certainly have some of the deepest pockets. If an open market increases the price, it would seem to make it a better market for bad actors.

Especially if we think of small software companies or open-source projects (like OpenSSL) who cant afford to pay hundreds of thousands of dollars to secure their own exploit.

On your overall point... I think this issue of selling 0days is more a debate of ethics, and I don't think economics can solve a problem of ethics.

An open market increases the price of vulnerabilities

What's your logic behind this? I believe this to be false. To my knowledge the black market commands artificially high prices on illicit goods as a rule, except when the good is available on the open market. See:

1) The goods are stolen and need to be unloaded quickly.

2) Open market prices are artificially high thanks to things like taxes (example: alcohol, cigarettes)

The market concept is nice for the reasons you listed, but doesn't it add an incentive to introduce obfuscated exploits into code then sell an exploit to them later?
I don't agree with you (on all points) but none the less applaud your ideas and the way you formulate your arguments.
It amuses me to hear how middle-class people are baffled by the fetishization of criminality in hip-hop culture, when we fetishize the same type of assholes in our culture. Mitnick is a criminal and all the pro-hacking sympathies have been wasted on a very, very undeserving person. Funny how easily you can manipulate public opinion with the right PR and anti-government message. Everyone wants to be the rebel against "the system." Everyone seems to think they're the Ayn Rand hero amongst the idiots, when in reality, the rebels and the intellectually vain are easily co-opted politically. The rise of libertarianism in geekdom seems to fall under the same dynamic.
As far as I could ever tell, 90% of the sympathy for Mitnick was because of the excessive sentencing passed down by the government. It's less like hip hop idolizing gangsters and more like sympathy for Rodney King, who was drunk driving at 100 miles per hour and resisted arrest before he was beaten by the LAPD.
I was fooled into this when his first book was released, "The Art of Deception". I think I read the first three pages and heart sank because it wasn't a book about computer stuff really at all and I started thinking this guy is a fraud. but mostly I was fooled by marketing. (I was 12 at the time). I just remember being very let down by the book and not being a fan of Mitnik for that reason.

The comment section of this post has an underlying anger towards the hi-jacking of the word 'hacker' as it was and is applied to kevin mitnik and thus misunderstood by the public waaaaay too often.

Is a criminal, or was a criminal? If you claim he is (in 2014) a criminal, is it because of his crimes pre-1995, or some crime he committed in the past year? If your answer is the former, then you are essentially saying "once a criminal, always a criminal." And if you claim that, I will throw some counterexamples in your face, beginning with myself.
I think you give them too much credit. I think they just want power. It's seductive.

Lawyers have power, Doctors have power, Hackers have power.

Your pro-government rant doesn't fit in this case because the government is one of the customers in the zero day market.
Maybe it's because I'm pretty much in the libertarian/anarchist spectrum, but I think that if what he's doing is legal, it's for the best that it's done openly.

The alternative to free markets isn't "no markets" or some flowery hippie ideal world. It's mafia and black/dark markets operating in complete or partial secrecy.

One of the prime examples from my corner of the world:

The Finnish software house Reaktor recently invited Mr. Mitnick as a "keynote speaker" into their popular event for software developers:

http://reaktordevday.fi/2013/

To be honest, I didn't understand the relevance at all. The idolization seemed quite childish.

Most people don't fetishize this asshole
> the rebels and the intellectually vain are easily co-opted politically.

and

> The rise of libertarianism in geekdom seems to fall under the same dynamic.

I can agree to the first, the second can be simply attributed to an understanding of the first. It is unfortunate that you don't see the connection.

The corruption of traditional causes and activism is what leads people toward libertarianism.

"Mitnick became a symbol of government oppression in the late 1990s, when he spent four and a half years in prison and eight months in solitary confinement before his trial on hacking charges. The outcry generated a miniature industry in “Free Kevin” T-shirts and bumper stickers."

I wonder if money could be made selling 'Fuck Kevin' shirts and bumper stickers now.

Incidentally, Fuck Kevin.

"My clients may use them to monitor your activities? How do you like them apples, Chris?" -- Mitnick to ACLU technologist, last line of article

Wow what a first class dick. He's implying that he will be glad to sell zero days to the government to illegally monitor ACLU activities (e.g. free speech, etc.)?

I've always thought it would be a just punishment for a neutral, but government arbitrated, third party to hold a highest bid auction for zero-day exploits, where the breached company has the opportunity to buy back their bad security at a market price. I feel as though making it public and legal would force larger targets to make better security decisions, instead of the current status quo of letting them off with tiny fines if anything at all.
“Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between.”

A glorified reseller and scumbag. Pathetic.

Well, this is what happens when researchers are snubbed by software vendors.

I don't agree with the attitude and sale of vulnerabilities, but if someone approaches the vendor and get the responses "this is not a vulnerability" or "why are you hacking our software, we're calling the authorities" this is where it ends up...

For those wanting to criticize Mitnick's actions, what I gather from the following quote is that there is an existing "industry" around finding, and selling these exploits...

"Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between."

Can anyone shed light on these "researchers" and how they sell their exploits now? Or is this just a friendly way of saying "we pay hackers for exploits and then blackmail vendors"?

My initial thought was "this should be illegal" - but if there's no market for exploits, security will remain poor. So, this sort of business is a bump on the road to global security, which I have some hope we're heading towards.

Either way, an exploit market is a grimy business, basically war profiteering. I wonder who is off-limits to sell to - certainly the Iranians, but who else, and who decides who is evil and who is good? People will die from some of these sales.

I think we'll see pervasive encryption and P2P (blockchain-based) applications that will push back tyranny a bit. There will be technological solutions to things like secret legal proceedings and warrantless wiretaps. And by pushing computation back out to decentralized nodes, there won't be such juicy targets to attack.

I'm old enough to remember this guy's moment in the sun by getting himself arrested. It was easy to fall into the "Free Kevin" mindset but now he's just trading on the name to make money. It's hard to keep that same "fuck the man" vibe when you become the man.

EDIT: I realize he's been trading on his name for a while now but I was cool with it when he was a "white hat".

So the same people who support Silk Road and black markets suddenly say, "Yeah, Fuck Kevin Mitnick!" because he's a capitalist and using essentially the same system to make some money??
... I think a lot of geeks might be burning their "free kevin" t-shirts.
So, who did he buy the 0days from?

I know he didn't find them himself. The boy can't code.

https://keenot.es/read/kevin-mitnick-is-celebrated-nobody

It's all very nice hoping that a free market for this kind of thing will improve security, but I don't see how that's going to happen. Government agencies are probably going to be his top customers... let's face it, they obviously have more funding for this kind of thing than they know what to do with, and it saves them having to do any hard work.

It's going to bring way way way more detriment than it is benefit, especially if his clients start looking at using semi-legal tactics to protect their investments.

The prevalence of 0-day exploits and the booming marketplaces for them are the biggest challenge for our industry today. The economic incentives mean that the worst vulnerabilities will increasingly be sold instead of responsibility reported. Why report it to the company in hopes of a 5k bounty, when the US gov will pay you 100X that for exclusive use? We're at a point now where everything has been compromised -- the network, every OS, every browser, every popular application. The software we all rely on can not be trusted to be secure from governments or well-funded organizations. Having unbounded access to every computer in the world is a frightening amount of power for any government or organization to hold. Until we find a way to change the economic incentives, I'm afraid the consolidation of power and the associated abuses are only going to continue. I have no idea how we fix this.
Isn't this blackmail?

"Pay us for all your secret vulnerabilities or we'll sell them to the highest bidder".

Basically, he is doing arm trade in 21st century.
It's disappointing to see that Kevin would sell exploits to a government body, but I don't otherwise see a problem with an exchange for exploits. I mean, they're going to get developed and sold eitherway, whether it's here, on some darknet forum, or whatever.
Not another story about this overrated dude.

Don't get me wrong, im sure hes a nice guy. But he hasn't demonstrated anything useful for 20+ years and it seems he is mainly making a living writing vague non-technical h4ax0r books and giving interviews. Hell, i think he cant even code.

As an off-topic note, I'd like to see if the font is showing up as poorly for anyone else as it is for me. The kerning is atrocious, and several rounded lower-case letters run into each other. This article is hard to read. ea, oa, ce...
If I were, say, some sort of Global Passive Adversary, I would try very hard to spy on Mitnick's communications. Then I could have all the vulnerabilities, and know who is buying and selling.

I wonder if maybe that has occurred to anyone.

I was surprised by the ACLU response given that sharing source code is very clearly free speech.

Is the ACLU of all groups really interested in stopping/censoring people from sharing ideas?

Why does anyone need to legitimately buy a zero-day?
His website look like very "Free Kevin" era, with Flash replaced by CSS tricks.
This again, reminds me that money can buy you anything... apart from a free CONSCIENCE.
At least this way large corporations will start paying more for their bounties.
t'would appear he cares about nothing and no-one, and has opted to use his powers for evil.

We shall have wait and see how that works out for him.

His website needs some work
Let me inturrupt this fascinating discussion for an important PSA:

All of you who don't produce 0 day: You don't get to have a say. Your opinion doesn't matter and you don't get a seat at the table, not even as an observer.

And now back to telling other people what to do with their work product...