Earlier quoted context omitted.
HT purchased these vulnerabilities with an understanding that they would not be made public and patched. Then they failed to safeguard them. Clearly these O-days, and conceivably all computer vulnerabilities, are not close to being as bad as smallpox, but what ethical obligations do actors (companies, governments, hackers, researchers) have to protect vulnerabilities which they plan to not protect the public again? S…
Why don't you 100% blame the people at fault: Adobe / the original developers. First, they were incompetent enough to not correctly develop their software. Second, non-assholes would have a standing price-match policy for bugs. Adobe should give you 110% of the highest bid you get for any 0-day. They could have fixed these a long time ago if they'd paid the discoverer $45k (or $150k -- times three for exclusivity.) T…
I agree Adobe is at fault for producing insecure software.
Blame is not a limited resource, there is always extra blame to go around. If I am driving recklessly and my brakes fail due to a manufacturing error, both I and the car company are at fault for the accident. One can always, as HT has done, make a bad situation worse but behaving in a reckless and unethical matter.
>Adobe should give you 110% of the highest bid you get for any 0-day.
This! This so hard.