Auction Seeks to Provide Competitive Prices for the Discovery of Network Goods

| | Comments (0) | TrackBacks (0)

Michael Giberson

A Swiss software security research company, WabiSabiLabi, is establishing an online auction site to allow security researchers to auction off discoveries of software vulnerabilities. In their press release, they said:

Recently it was reported that although researchers had analyzed a little more than 7,000 publicly disclosed vulnerabilities last year, the number of new vulnerabilities found in code could be as high as 139,362 per year. Our intention is that the marketplace facility on WSLabi will enable security researchers to get a fair price for their findings and ensure that they will no longer be forced to give them away for free or sell them to cyber-criminals.

Yes, they will screen the bidders in the effort to determine that they aren't "cyber-criminals," and they will test reported vulnerabilities before allowing an item to be put up for auction. The Washington Post described vulnerability researcher Dino Dai Zovi as excited about the vulnerability auction service:

"I can see this service creating much more incentives for researchers to find flaws," Dai Zovi said. "Not everyone is willing to spend 20 to 40 hours looking for vulnerabilities in software just to receive a little thank-you note in Microsoft's security advisories."

The discovery of software vulnerabilities provides something of the nature of a network or club good. Presumably the software vendor - the provider of the initial good or service around which the network grows - would have an incentive to pay for acquisition of this information so as to put out a better product. But if the standard offer of payment is "a little thank-you note," perhaps the existing market for such intellectual property is not yielding competitive prices.

0 TrackBacks

Listed below are links to blogs that reference this entry: Auction Seeks to Provide Competitive Prices for the Discovery of Network Goods.

TrackBack URL for this entry: http://www.knowledgeproblem.com/mt/mt-tb.cgi/1108

Leave a comment


Type the characters you see in the picture above.

October 2008

Sun Mon Tue Wed Thu Fri Sat
      1 2 3 4
5 6 7 8 9 10 11
12 13 14 15 16 17 18
19 20 21 22 23 24 25
26 27 28 29 30 31  

Contact

Lynne Kiesling
Lynne-at-knowledgeproblem-dot-com

Michael Giberson
Mike-at-knowledgeproblem-dot-com

Archives

Creative Commons License
This weblog is licensed under a Creative Commons License.
Powered by Movable Type 4.1