Live data from Hacker News

Chrome 0-day exploit used in Operation WizardOpium

securelist.com

11–20 of 159 posts

Re: Chrome 0-day exploit used in Operation WizardOpium

#11
post #9

Tragedy of our generation is that people who are so smart and determined to find and exploit these vulnerabilities, can't find better uses for their talents.

Or maybe society isn't providing them an accessible application for their talents.

Re: Chrome 0-day exploit used in Operation WizardOpium

#12
post #9

Tragedy of our generation is that people who are so smart and determined to find and exploit these vulnerabilities, can't find better uses for their talents.

Or maybe society isn't providing them an accessible application for their talents.

One good application that comes to mind in this case would be the Google Chrome bug bounty program.

Re: Chrome 0-day exploit used in Operation WizardOpium

#14
post #9

Tragedy of our generation is that people who are so smart and determined to find and exploit these vulnerabilities, can't find better uses for their talents.

Or maybe society isn't providing them an accessible application for their talents.

Don't improve the product, just find dumber customers!

Don’t lose weight, just buy bigger trousers!

Don’t take personal responsibility, just blame society!

Re: Chrome 0-day exploit used in Operation WizardOpium

#15
post #12

Earlier quoted context omitted.

Or maybe society isn't providing them an accessible application for their talents.

One good application that comes to mind in this case would be the Google Chrome bug bounty program.

The writer of this exploit was almost certainly paid more than the bug bounty reward.

Re: Chrome 0-day exploit used in Operation WizardOpium

#18
post #12

Earlier quoted context omitted.

One good application that comes to mind in this case would be the Google Chrome bug bounty program.

The writer of this exploit was almost certainly paid more than the bug bounty reward.

Agreed, exploits on the deep Web pay 10x what the big bounty programs do, the mismatch is laughable

Re: Chrome 0-day exploit used in Operation WizardOpium

#19
post #12

Earlier quoted context omitted.

One good application that comes to mind in this case would be the Google Chrome bug bounty program.

The writer of this exploit was almost certainly paid more than the bug bounty reward.

Yeah, that’s a hard thing. Because the exploit is almost certainly worth more to the buyer than having it fixed is worth to Google.

Re: Chrome 0-day exploit used in Operation WizardOpium

#20
post #12

Earlier quoted context omitted.

One good application that comes to mind in this case would be the Google Chrome bug bounty program.

The writer of this exploit was almost certainly paid more than the bug bounty reward.

Sure. I'm not saying that the moral way is just as profitable as the alternative; only that it exists.
Post reply on HN