<?xml 
version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:thr='http://purl.org/syndication/thread/1.0' >
	<title>Company:Vupen - Seenthis</title>

	<link href="http://seenthis.net/tag/company:vupen" />
        <id>http://seenthis.net/tag/company:vupen</id>
        <updated>2013-05-23T17:35:05Z</updated>
        <link rel="self" href="http://seenthis.net/tag/Company:Vupen/feed" />






	<entry>
	<id>urn:uuid:50fbca6f-21a0-4ea0-9d64-41d76984afe9</id>
	<title>Zero-day exploits : Should the hacker gray market be regulated ? - Slate Magazine</title>
	<author>
		<name>Simplicissimus (@simplicissimus)</name>
		<uri>http://seenthis.net/people/simplicissimus</uri>
		<email>simplicissimus@seenthis.net</email>
		
	</author>
	<published>2013-01-20T10:43:59Z</published>
	<updated>2013-01-20T10:43:59Z</updated>
	
	 <link href="http://seenthis.net/messages/108750" />
	
	<link rel="edit" href="https://seenthis.net/api/messages/108750"/>
	<summary><![CDATA[Zero-day exploits: Should the hacker gray market be regulated? - Slate Magazine
http://www.slate.com/articles/technology/future_tense/2013/01/zero_day_exploits_should_the_hacker_gray_market_be_regulated.html

Faut-il réguler le "marché gris" des _zero day exploits_ ?

Il existe des courtiers spécialisés en _exploits_. Mais, attention, on trouve de tout sur le marché. Pour celui-ci, qui vend les _exploits_ entre 16 000 et 250 000 dollars, il ne vend pas à n'importe qui : uniquement à des (gentils) états-uniens.

❝Unlike other companies and sole traders operating in the zero-day trade, Desautels has adopted a policy to sell his exploits only domestically within the United States, rigorously vetting all those he deals with. If he didn’t have this principle, he says, he could sell to anyone he wanted—even Iran or China—because the field is unregulated. And that’s exactly why he is concerned.❞

et d'ailleurs, le même connait des méchants :

❝Desautels says he knows of “greedy and irresponsible” people who “will sell to anybody,” to the extent that some exploits might be sold by the same hacker or broker to two separate governments not on friendly terms.❞

Tiens, d'ailleurs, le paragraphe d'après un (méchant ? ce n'est pas précisé) Français (86% de ses ventes à l'exportation en 2011) :

❝The position Desautels has taken casts him as something of an outsider within his trade. France’s Vupen, one of the foremost gray-market zero-day sellers, takes a starkly different approach. Vupen develops and sells exploits to law enforcement and intelligence agencies across the world to help them intercept communications and conduct “offensive cyber security missions,” using what it describes as “extremely sophisticated codes” that “bypass all modern security protections and exploit mitigation technologies.”
Vupen’s latest financial accounts show it reported revenue of about $1.2 million in 2011, an overwhelming majority of which (86 percent) was generated from exports outside France. Vupen says it will sell exploits to a list of more than 60 countries that are members or partners of NATO, provided these countries are not subject to any export sanctions. (This means Iran, North Korea, and Zimbabwe are blacklisted—but the likes of Kazakhstan, Bahrain, Morocco, and Russia are, in theory at least, prospective customers, as they are not subject to any sanctions at this time.)❞

Certains trouvent que le problème est surfait : pas besoin de _zero day exploit_ pour attaquer l'ordi d'un cadre ou d'un militant, une bonne vieille faille bien documentée suffit (quand ce n'est pas le comportement de l'utilisateur lui-même…)

❝Some claim, however, that the zero-day issue is being overblown and politicized. “You don’t need a zero day to compromise the workstation of an executive, let alone an activist,” says Wim Remes, a security expert who manages information security for Ernst & Young.❞

Faut-il réguler ? Attention, si les réglementations se durcissent sans augmenter les primes pour la révélation de faille, l'appât du gain poussera les hackers à déserter le marché gris au profit d'un marché noir qui ne demande qu'à se développer.]]></summary>
	<content type="html">&lt;div lang=&quot;fr&quot; dir=&quot;ltr&quot;&gt;&lt;p&gt;Zero-day exploits : Should the hacker gray market be regulated ? - Slate Magazine&lt;br /&gt;&lt;span class='lien_lien' &gt;&lt;a href=&quot;http://www.slate.com/articles/technology/future_tense/2013/01/zero_day_exploits_should_the_hacker_gray_market_be_regulated.html&quot; class='spip_out' title=&quot;Zero-day exploits: Should the hacker gray market be regulated?&quot; hreflang=&quot;en&quot;&gt;&lt;span class='lien_court'&gt;&lt;span class='lien_protocol'&gt;http://&lt;/span&gt;&lt;span class='lien_racine lien_raccourci'&gt;&lt;span class='lien_host'&gt;&lt;span class='lien_www'&gt;www.&lt;/span&gt;slate.com&lt;/span&gt;/&lt;/span&gt;&lt;span class='lien_off'&gt;articles/&lt;/span&gt;&lt;span class='lien_off'&gt;technology/&lt;/span&gt;&lt;span class='lien_off'&gt;future_tense/&lt;/span&gt;&lt;span class='lien_off'&gt;2013/&lt;/span&gt;&lt;span class='lien_off'&gt;01/&lt;/span&gt;&lt;span class='lien_fin'&gt;&lt;span class='lien_fin_coupee'&gt;zero_day_exploits_should_the_hac&lt;/span&gt;&lt;span class='lien_fin_cachee'&gt;ker_gray_market_be_regulated.html&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;Faut-il r&#233;guler le &#171; march&#233; gris &#187; des &lt;em&gt;zero day exploits&lt;/em&gt; ?&lt;/p&gt;&lt;p&gt;Il existe des courtiers sp&#233;cialis&#233;s en &lt;em&gt;exploits&lt;/em&gt;. Mais, attention, on trouve de tout sur le march&#233;. Pour celui-ci, qui vend les &lt;em&gt;exploits&lt;/em&gt; entre 16 000 et 250 000 dollars, il ne vend pas &#224; n'importe qui : uniquement &#224; des (gentils) &#233;tats-uniens.&lt;/p&gt;&lt;blockquote lang=&quot;en&quot; dir=&quot;ltr&quot;&gt;&lt;p&gt; Unlike other companies and sole traders operating in the zero-day trade, Desautels has adopted a policy to sell his exploits only domestically within the United States, rigorously vetting all those he deals with. If he didn't have this principle, he says, he could sell to anyone he wanted&#8212;even Iran or China&#8212;because the field is unregulated. And that's exactly why he is concerned. &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;et d'ailleurs, le m&#234;me connait des m&#233;chants :&lt;/p&gt;&lt;blockquote lang=&quot;en&quot; dir=&quot;ltr&quot;&gt;&lt;p&gt; Desautels says he knows of &#8220;greedy and irresponsible&#8221; people who &#8220;will sell to anybody,&#8221; to the extent that some exploits might be sold by the same hacker or broker to two separate governments not on friendly terms. &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Tiens, d'ailleurs, le paragraphe d'apr&#232;s un (m&#233;chant ? ce n'est pas pr&#233;cis&#233;) Fran&#231;ais (86% de ses ventes &#224; l'exportation en 2011) :&lt;/p&gt;&lt;blockquote lang=&quot;en&quot; dir=&quot;ltr&quot;&gt;&lt;p&gt; The position Desautels has taken casts him as something of an outsider within his trade. France's Vupen, one of the foremost gray-market zero-day sellers, takes a starkly different approach. Vupen develops and sells exploits to law enforcement and intelligence agencies across the world to help them intercept communications and conduct &#8220;offensive cyber security missions,&#8221; using what it describes as &#8220;extremely sophisticated codes&#8221; that &#8220;bypass all modern security protections and exploit mitigation technologies.&#8221;&lt;br /&gt;Vupen's latest financial accounts show it reported revenue of about $1.2 million in 2011, an overwhelming majority of which (86 percent) was generated from exports outside France. Vupen says it will sell exploits to a list of more than 60 countries that are members or partners of NATO, provided these countries are not subject to any export sanctions. (This means Iran, North Korea, and Zimbabwe are blacklisted&#8212;but the likes of Kazakhstan, Bahrain, Morocco, and Russia are, in theory at least, prospective customers, as they are not subject to any sanctions at this time.) &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Certains trouvent que le probl&#232;me est surfait : pas besoin de &lt;em&gt;zero day exploit&lt;/em&gt; pour attaquer l'ordi d'un cadre ou d'un militant, une bonne vieille faille bien document&#233;e suffit (quand ce n'est pas le comportement de l'utilisateur lui-m&#234;me&#8230;)&lt;/p&gt;&lt;blockquote lang=&quot;en&quot; dir=&quot;ltr&quot;&gt;&lt;p&gt; Some claim, however, that the zero-day issue is being overblown and politicized. &#8220;You don't need a zero day to compromise the workstation of an executive, let alone an activist,&#8221; says Wim Remes, a security expert who manages information security for Ernst &amp; Young. &lt;/p&gt;&lt;/blockquote&gt;&lt;p&gt;Faut-il r&#233;guler ? Attention, si les r&#233;glementations se durcissent sans augmenter les primes pour la r&#233;v&#233;lation de faille, l'app&#226;t du gain poussera les hackers &#224; d&#233;serter le march&#233; gris au profit d'un march&#233; noir qui ne demande qu'&#224; se d&#233;velopper.&lt;/p&gt;&lt;/div&gt;</content>
	
	<link rel="related" href="http://www.slate.com/articles/technology/future_tense/2013/01/zero_day_exploits_should_the_hacker_gray_market_be_regulated.html" title="Zero-day exploits : Should the hacker gray market be regulated ?" hreflang="en"/>
	
	
	<category term="Company:Vupen" label="Vupen" scheme="http://seenthis.net/tag/company:vupen"/>
	<category term="Currency:USD" label="USD" scheme="http://seenthis.net/tag/currency:usd"/>
	<category term="Country:Iran" label="Iran" scheme="http://seenthis.net/tag/country:iran"/>
</entry>

</feed>

