1) It would result in more vulnerabilities found
This is fairly axiomatic. An open market increases the price of vulnerabilities which in turn increases the number of vulnerabilities found (unless you want to argue the ability to find vulnerabilities is inelastic for some reason).
2) It would result in more vulnerabilities being disclosed to the proper authorities rather than malicious parties
This is more debatable, but since there should always be significantly more incentive on good actors to prevent the exploit (i.e. the software creators and/or community) than bad actors, the good actors should always win the bid. Indeed, one could argue that it is only the prevention of free negotiation in the sale of vulnerabilities is the reason an exploit is ever sold to bad actors (e.g. if I found a Windows vulnerability and told Microsoft $10m or else, I'm a criminal).
3) It would ultimately increase the quality of software
Given more vulnerabilities are found and more vulnerabilities would be disclosed to good actors, the quality of software increases.
I believe that 2) is essentially the Coase theorem (http://en.wikipedia.org/wiki/Coase_theorem), but I am only an arm-chair economist. Also, I'm not sure that what Mitnick is doing actually is a free and open market for vulnerabilities.
Imagine he had said: I believe a free and open market for weapons would be a good thing, because it would reduce the number of defenseless people, would result in a power imbalance that puts generally-okay actors at an advantage (say what you will, but the mob doesn't have 1% of the resources the US government does), and would therefore reduce crime.
I do not personally find that argument compelling (and it is of identical structure to the above), but me disagreeing with it does not mean it isn't of sufficient quality for Hacker News.
[1] As a case in point, I showed the headline of the email for the bash vulnerability to a coworker today on the commute and he instantly described in accurate detail how it probably works. Not that this was a particularly difficult case, but I think the principle holds.
Wait a second...won't increasing the number of vulnerabilities found push prices down? If I'm looking to penetrate a system I only need to buy one vulnerability, so in effect different vulnerabilities are somewhat fungible and so should compete on price. Hence, if more vulnerabilities are being found and coming to market, prices should be going down.
On the other hand, with a free and open market for vulnerabilities there would likely be people who would NOT have bought vulnerabilities on the black market buying vulnerabilities on the safer, easier to use free and open market, so demand could go up, raising prices.
That's impossible to tell. You could just as easily say that the price will crash when you take away all the costs and risk of running a black market and give buyers a place to compare multiple "products." The demand side could just as easily be inelastic (or at least saturated) as the supply.
> the good actors should always win the bid
This works if you're talking about Microsoft, but not if you're talking about smaller companies or open source products. Maybe a Google or a Facebook would step up and pay off the market for things that they use, but "the rich people will take care of us" is not a setup that I'm comfortable with.
Our only proper response is secure software development practices, employment of security reseachers, and adoption of security-centric practices in critical systems... such as the Linux kernel. Which is embarassingly not the case at the moment. For ex: http://unix.stackexchange.com/questions/59020/why-are-the-gr...
Especially if we think of small software companies or open-source projects (like OpenSSL) who cant afford to pay hundreds of thousands of dollars to secure their own exploit.
On your overall point... I think this issue of selling 0days is more a debate of ethics, and I don't think economics can solve a problem of ethics.
What's your logic behind this? I believe this to be false. To my knowledge the black market commands artificially high prices on illicit goods as a rule, except when the good is available on the open market. See:
1) The goods are stolen and need to be unloaded quickly.
2) Open market prices are artificially high thanks to things like taxes (example: alcohol, cigarettes)
The comment section of this post has an underlying anger towards the hi-jacking of the word 'hacker' as it was and is applied to kevin mitnik and thus misunderstood by the public waaaaay too often.
Lawyers have power, Doctors have power, Hackers have power.
The alternative to free markets isn't "no markets" or some flowery hippie ideal world. It's mafia and black/dark markets operating in complete or partial secrecy.
The Finnish software house Reaktor recently invited Mr. Mitnick as a "keynote speaker" into their popular event for software developers:
To be honest, I didn't understand the relevance at all. The idolization seemed quite childish.
and
> The rise of libertarianism in geekdom seems to fall under the same dynamic.
I can agree to the first, the second can be simply attributed to an understanding of the first. It is unfortunate that you don't see the connection.
The corruption of traditional causes and activism is what leads people toward libertarianism.
I wonder if money could be made selling 'Fuck Kevin' shirts and bumper stickers now.
Incidentally, Fuck Kevin.
Wow what a first class dick. He's implying that he will be glad to sell zero days to the government to illegally monitor ACLU activities (e.g. free speech, etc.)?
A glorified reseller and scumbag. Pathetic.
I don't agree with the attitude and sale of vulnerabilities, but if someone approaches the vendor and get the responses "this is not a vulnerability" or "why are you hacking our software, we're calling the authorities" this is where it ends up...
"Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between."
Can anyone shed light on these "researchers" and how they sell their exploits now? Or is this just a friendly way of saying "we pay hackers for exploits and then blackmail vendors"?
Either way, an exploit market is a grimy business, basically war profiteering. I wonder who is off-limits to sell to - certainly the Iranians, but who else, and who decides who is evil and who is good? People will die from some of these sales.
I think we'll see pervasive encryption and P2P (blockchain-based) applications that will push back tyranny a bit. There will be technological solutions to things like secret legal proceedings and warrantless wiretaps. And by pushing computation back out to decentralized nodes, there won't be such juicy targets to attack.
EDIT: I realize he's been trading on his name for a while now but I was cool with it when he was a "white hat".
I know he didn't find them himself. The boy can't code.
It's going to bring way way way more detriment than it is benefit, especially if his clients start looking at using semi-legal tactics to protect their investments.
"Pay us for all your secret vulnerabilities or we'll sell them to the highest bidder".
Don't get me wrong, im sure hes a nice guy. But he hasn't demonstrated anything useful for 20+ years and it seems he is mainly making a living writing vague non-technical h4ax0r books and giving interviews. Hell, i think he cant even code.
I wonder if maybe that has occurred to anyone.
Is the ACLU of all groups really interested in stopping/censoring people from sharing ideas?
We shall have wait and see how that works out for him.
All of you who don't produce 0 day: You don't get to have a say. Your opinion doesn't matter and you don't get a seat at the table, not even as an observer.
And now back to telling other people what to do with their work product...