It causes severe disruption to multiple teams, it prevents processes built to optimize testing of multiple patches on parallel, it leads to many customer support nightmares, bad press, overworked employees,... Just bad on many fronts.
1
You will notice that some of the things listed are not financial, there's more to it than just money.
Cost is only one aspect of this, employee moral matters assuming you work at a company that's not soulless, effect on customers matters as well,...
1
1
Let me rephrase
- The cost of a vuln is what $company has to pay for it (money, time, reputation).
- The price of a vuln is what $bughunter gets from it (money, fame, glory).
- The value is what $company gets from the $vulnerability.
With FD is the value-cost<0?
2
How do you put a monetary value on the pain experienced by customers, the mom who lost all photos of her little child to a ransomware exploiting an 0-day ?
What's the monetary cost of burnt out employees ?
It's not just financial mathematics
1
Easy. Will the knowledge of the vulnerability allow you to prevent new ones from being introduced and exploited in the future? What's the likelihood of exploitation for each? Qualitatively is the knowledge of the vulns today more valuable for your customers in the long term?
2
You could get that knowledge through other means that are less costly.
Double the price of the bounty for coordinated disclosure and give 0 to FD, I bet you will achieve better results for cheaper, and that mom will be able to see her little child's photos.
1
1
I *personally* think that a lot of people are able to find bugs, but few are able to build a proper exploit and provide all the details of a solid report.
So I could see enabling these people as a potential benefit if you can get automation to do root cause & severity analysis
1
Aside of that, not sure what a median step between CD and FD would be.
You guys (as does MS) have lots of internal tooling for debugging / analysis. It appears publicly sometimes but better tooling out there likely would lead to more findings
1
What’s the impetus of the researcher to disclose right away? Why can’t they wait until the vuln is fixed?
Jul 23, 2019 · 3:09 PM UTC
1


