Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Blackhat markets will always be able to pay better.

... than Google?

> Selling to Google though you aren't chancing jail time.

Why would you go to jail for selling a vulnerability? It's free speech.

 help



"Aiding and Abetting" crime is also a crime. Free speech has nothing to do with it.

Has anyone actually been convicted of abetting a crime by selling a vulnerability, by itself, not conspiring with the buyer to commit a crime using said vulnerability? Not as far as I can see. It would be absurd to jail someone for accurately describing a bug.

It would be absurd to jail someone for accurately describing a bug on their blog or whatever.

Not so much for taking money from someone who the buyer should know has no reason to be interested in buying the information. And either you know who your counterparty is, in which case you know that they are using it nefariously, or you don't know who your counterparty is, in which case you know that they are using it nefariously. Any court and any jury should see straight through this.

Similarly if you figure out how to get the ATM down the street to give you free money, and you "accurately describe the bug" to people who pay you, and they use it to steal money from the ATM, expect to be charged for participating in, and in fact being an instrumental enabler of their crime. Because it is beyond all reasonable doubt that you could've believed they could have been interested enough to pay you for any other reason.


Has anyone actually been charged and convicted for disclosing knowledge of a vulnerability in exchange for money with no further collusion to commit a crime?

Jeremy Jethro seems to be an example. His lawyer claimed he had no knowledge of what the exploit would be used for, and that it didn't even work, but he ultimately pled guilty to criminal conspiracy.

Hmm. Are you aware of any publicly identifiable security researchers that openly talk about selling their exploits on the black market?

Since it's all so legal and risk-free, you'd think selling an exploit for a million bucks would be quite the feather in their cap!

It may also be helpful to visualize being interviewed by the FBI and being asked "Did you sell this exploit? To whom? How much did you receive? For what purpose did you think it would be used?". And to remember they already know the answers to these questions, and lying to the FBI is also a crime.


My question stands.

"this vulnerability is being sold for research purposes only and must never be used outside of a tightly controlled research sandbox"

courts are very good at reasoning about things like this and figuring out its bullshit. Zerodium is probably the closest you could get to some reasonable denial about this. Selling an exploit on crime.com for "research puposes only" will get you laughed at on the way to the cell.

Telling someone the steps to rob a bank world probably catch you some charges, I'm assuming.

Are true crime authors going to jail? Or even authors of heist fiction?

No, it wouldn't.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: