Earlier quoted context omitted.
Yea, legitimate with illegitimate is a weird kind of calculation, as the risk with illegitimate market is to end up in jail, and few people want to calculate the monetary value of lost time due to incareration and all the fallout that comes with it. The more interesting question would be, if the bug bounty is enough to keep legitimate researchers engaged to investigate and document the threats. But.. The bug bounty i…
Is it actually illegal to sell an exploit to the highest bidder? Obviously deploying or using the exploit violates any number of laws. From a speech perspective, if I discovered an exploit and wrote a paper explaining it, what law prevents me from selling that research?
https://www.law.cornell.edu/uscode/text/18/1029 gives the definition and penalties for committing fraud and/or unauthorized access, and it includes the development of such tools.
A lot of it includes the phrasing "with intent to defraud" so it may depend on whether the court can show you knew your highest bidder was going to use it in this way.
(apologies for citing US-centric law, I figured it was most relevant to the current discussion but things may vary by jurisdiction, though probably not by much)