| ▲ | parhamn 3 hours ago | |
> Valuations for server-side vulnerabilities are low, because vendors don't compete for them. Why don't they? | ||
| ▲ | devmor 3 hours ago | parent [-] | |
Because as soon as they are patched, they are worthless. People pay for vulnerabilities because they want to exploit them - if there’s a limited window, there’s limited demand. Even if there’s something worth a lot behind the exploit, a potential criminal would be better off obtaining whatever that is and selling it instead. | ||