OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Re: [Dailydave] Vulnerabilities Market

From: Michal Zalewski (lcamtufcoredump.cx)
Date: Fri May 21 2010 - 17:58:57 CDT


> I agree, the multiple-decimal percentages aren't real useful.

No, my point is that the whole study is probably meaningless. With 26
data points, I am guessing they had about 10 participants, yet ask
incredibly granular bucketing questions. The results are going to be
just random.

Looking at the volume of vulnerabilities released by ZDI and the
likes, it's evident that hundreds of sales are taking place every
year, so it's not just that the market is very small.

/mz
_______________________________________________
Dailydave mailing list
Dailydavelists.immunitysec.com
http://lists.immunitysec.com/mailman/listinfo/dailydave