Price of zero-day exploits rises as companies harden products against hackers
1–7 of 7 posts
Re: Price of zero-day exploits rises as companies harden products against hackers
#2Re: Price of zero-day exploits rises as companies harden products against hackers
#3Re: Price of zero-day exploits rises as companies harden products against hackers
#4What is the legal status of a US citizen selling a 0-day targeting an American company to the American government? Is it legal?
Re: Price of zero-day exploits rises as companies harden products against hackers
#5Re: Price of zero-day exploits rises as companies harden products against hackers
#6What is the legal status of a US citizen selling a 0-day targeting an American company to the American government? Is it legal?
And I'm not entirely certain how codified into law such restrictions are on private citizens and companies. There is always article 3 section 3 clause 1 of the constitution where it outlines the crime of treason as "levying war against them, or in adhering to their Enemies, giving them aid and comfort." Though I don't know that selling a security vulnerability to a foreign government would be considered treason or trigger any related laws. I'm unaware of any prosecutions or civil suits against private citizens or companies regarding the trade of 0-days.
Re: Price of zero-day exploits rises as companies harden products against hackers
#7What is the legal status of a US citizen selling a 0-day targeting an American company to the American government? Is it legal?
In the specific case, it's unlikely to be illegal to sell, however it would generally be illegal for the g-men to buy. With the exception of certain intelligence community members. And even then within say e.g. the Army. The Cyber component likely could buy your zero-day, but Human Resources Command or Recruiting Command absolutely could not.
And even then, say you do sell your sweet, exquisite zero-day rce to the correct part of the CIA: there's a legally mandated Vulnerability Disclosure Process that if your shit is so good it will foreseeably cause the next NotPetya then the vuln will be responsibly disclosed in any event.
Edit: if you are interested in top cover for your dalliances, here is an exemplar job listing from LockMart https://www.lockheedmartinjobs.com/job/hanover/reverse-engin...