Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you were an enterprising hacker with a lot of time on his/her hands, I imagine Adobe Reader and Flash Player would be a great place to focus on for selling software exploits to the US Government. I hear they are paying nicely these days for verifiable not-yet-released in the wild exploits.


The US government would have to pay each independent discoverer of the not-yet-released exploit, no? If they said 'no thanks, we've already got that one,' the second discoverer could just turn around and disclose it, making the original purchase a lot less valuable.

What, besides their own sense of ethics, stops the original exploit discoverer from selling the exploit to someone else, who will then resell it back to the US government? That seems like a lot easier way to get more money from your exploit than, say, developing contacts with a second government.

The only way I can think of for the US government to effectively prevent you from reselling your exploits is to monitor your communications and finances for anything shady - whenever the exploit is independently discovered, they would have to do some research into your behavior to make sure it was actually independently discovered. Hell, why wouldn't they do this monitoring all along to make sure you're not trying to sell it to a foreign government?

I'm probably just paranoid, but being one of the few people who know something the US government would like to keep a secret doesn't sound like a good position to be in. I'd want to be rather well paid.


In the U.S., the National Security Agency and other branches of the U.S. military, law enforcement and intelligence agencies are among the biggest buyers of vulnerabilities. But there are other buyers, including any party with an interest in being able to penetrate an adversary's computer network.

http://www.npr.org/2013/02/12/171737191/in-cyberwar-software...


How exactly do you sell a vulnerability to the US Federal Government?


You don't (for the most part). You'd actually sell it to one of about a dozen small firms around the beltway who purchase vulnerabilities (who in turn either license "exploit-packs" to the government, or who work on specific tactical campaigns using said exploits).


I've always wondered how one would find a contact within such a community. I know there's an old joke about looking for a job at the NSA: "The NSA offers exciting and interesting work for recent college graduates in mathematics and computer science. Pick up the phone, call your mom, and ask for an application."


I imagine it's easier than you think ;)


They have a contact page these days: http://www.nsa.gov/public_info/contacts/index.shtml.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: