Hugs Not Bugs
ID: 5f301abe-b999-5b89-8fff-35f197f58fcf
STIX ID: report--5f301abe-b999-5b89-8fff-35f197f58fcf
Feed Name: Zscaler Security Research Blog
This opinion piece critiques the expectation that researchers should freely disclose vulnerability details and argues vendors should pay for vulnerability research. It recounts the history and role of programs like iDefense's VCP and the Zero Day Initiative, discusses the market pressures that drive governments and criminals to buy undisclosed bugs, and recommends vendors adopt transparent, fixed-price bounty programs to properly compensate researchers and reduce the incentive for secret or malicious sales of vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
