<div><strong>Proposition</strong></div>
<div> </div>
<div>Microsoft is a 280+ billion dollar corporation. Why don't/can't they have a standard ransom fee for security flaws? </div>
<div> </div>
<div>0day Remote OS flaw: $1,000,000</div>
<div>0day IE explorer flaws that give administrative shells: $200,000</div>
<div>0day (other flaws) that affect other products (ie office): $200,000</div>
<div>etc..(these fees could be much higher)</div>
<div> </div>
<div>Provided the person who discovered the vulnerability gives a full working patch, Then Microsoft could patch the hole right away and people could update. (yes i know lots of people don't update but at least it is a start, and then legally they would be so liable). Maybe this concept isint new and I am just in the dark about it.
</div>
<div> </div>
<div><strong>Question</strong></div>
<div><strong></strong> </div>
<div>Why does'nt Microsoft (or any company) do this? And also has Microsoft ever been held criminaly liable for negligence in a criminal case for not patching a flaw leading to a security breach? Or is there team of lawyers just to much for any normal person?
</div>
<div> </div>
<div> </div>
<div><br> </div>
<div><span class="gmail_quote">On 6/25/07, <b class="gmail_sendername">Kradorex Xeron</b> <<a href="mailto:admin@digibase.ca">admin@digibase.ca</a>> wrote:</span>
<blockquote class="gmail_quote" style="PADDING-LEFT: 1ex; MARGIN: 0px 0px 0px 0.8ex; BORDER-LEFT: #ccc 1px solid">On Sunday 24 June 2007 16:19, <a href="mailto:toto.toto@webmail.co.za">toto.toto@webmail.co.za</a> wrote:<br>
> I can't give detail here<br><br>Isn't this list called "full-disclosure"? - in otherwords: If you aren't<br>going to disclose anything: DON'T post that you "have something". This list
<br>is designed specifically for disclosing (and discussing on the occasion)<br>vulnerabilities, problems, etc to the entire community at once, not just<br>selectively who you choose (i.e. who buys your "0day").
<br><br>_______________________________________________<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html">http://lists.grok.org.uk/full-disclosure-charter.html
</a><br>Hosted and sponsored by Secunia - <a href="http://secunia.com/">http://secunia.com/</a><br></blockquote></div><br>