| ▲ | Veserv 2 hours ago | |||||||
... really? Zero-click RCEs can be used on arbitrarily many phones until they are discovered which usually takes on the order of months. You do not need to burn them on every individual target. As a example of how they might be used in that fashion for profit, NSO group had a revenue of 240 million dollars in 2020. Many of their customers were governments who wanted to spy on activists and journalists. NSO group was in the business of economies of scale to democratize access to journalist devices by reusing a small stockpile of exploits across many targets with enough revenue to assure a steady stream of new exploits as fast as they were burned. | ||||||||
| ▲ | orf 2 hours ago | parent [-] | |||||||
You’re right, I misstated. It’s not 10 million per exploitation, it instead limits the pool of people who can exploit you to those willing and have the ability to spend 10 million+ on an exploit. That is still quite a small pool, and there are other network effects preventing any Joe blogs with that much capital from launching an exploitation campaign. | ||||||||
| ||||||||