Feeds

Security 'exchange' could hit costs

Swiss security lab opens secrets 'market'

Security and trust: The backbone of doing business over the internet

Software development costs could be increased by a new approach to security research. Swiss software security specialist WSLabi says the results of security research are falling into the wrong hands and has launched an online 'secrets' exchange to solve the problem.

Herman Zampariolo, CEO of WSLabi, said: "The world is creating an incredible amount of software and firmware and a lot of it is not secure. We decided to set up an exchange portal to sell security research to ensure researchers get properly rewarded for their work and, at the same time, hackers can't easily get hold of it."

He told Register Developer that WSLabi has evidence that security researchers in Russia and China often sell the results of their research to criminal elements who use them to exploit so-called zero-day vulnerabilities - holes in newly-released software that have not been spotted and patched.

Under the principle of ethical disclosure, security researchers are theoretically obliged to pass on their findings to software developers. But Zampariolo argues that the research is in fact intellectual property and there should be mechanisms to protect it and sell it at market value.

"The number of new vulnerabilities found in developed code could, according to IBM, be as high as 140,000 per year. The marketplace facility on WSLabi will enable security researchers to get a fair price for their findings and ensure that they will no longer be forced to give them away for free or sell them to cyber-criminals," Zampariolo explains.

WSLabi will vet any research results it receives before making them available through its exchange portal. It will advise researchers on the best way to distribute their result to maximise their income and it will only sell research on to genuine, authenticated software and firmware developers.

WSLabi will, of course, charge fees to researchers and purchasers to cover its costs. ®

Providing a secure and efficient Helpdesk

More from The Register

next story
New 'Cosmos' browser surfs the net by TXT alone
No data plan? No WiFi? No worries ... except sluggish download speed
'Windows 9' LEAK: Microsoft's playing catchup with Linux
Multiple desktops and live tiles in restored Start button star in new vids
iOS 8 release: WebGL now runs everywhere. Hurrah for 3D graphics!
HTML 5's pretty neat ... when your browser supports it
'People have forgotten just how late the first iPhone arrived ...'
Plus: 'Google's IDEALISM is an injudicious justification for inappropriate biz practices'
Mathematica hits the Web
Wolfram embraces the cloud, promies private cloud cut of its number-cruncher
Mozilla shutters Labs, tells nobody it's been dead for five months
Staffer's blog reveals all as projects languish on GitHub
SUSE Linux owner Attachmate gobbled by Micro Focus for $2.3bn
Merger will lead to mainframe and COBOL powerhouse
iOS 8 Healthkit gets a bug SO Apple KILLS it. That's real healthcare!
Not fit for purpose on day of launch, says Cupertino
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
The next step in data security
With recent increased privacy concerns and computers becoming more powerful, the chance of hackers being able to crack smaller-sized RSA keys increases.