SLIDE 43 A Beautiful Journey Memory Error Protections The Aftermath Conclusions
Are Memory Corruptions still a Threat? I
Less bugs were reported: our speculation
1 The Great Recession
Before 2007, security experts were getting paid to look for bugs Things changed when companies ran out of money
Bug hunters fired or placed to do some “real” work
Results: less people searching for vulnerabilities
2 No full disclosure due to bounties
Ten years ago things were just different
You would even contact the corresponding administrator about your fix :-)
Today, large companies give out rewards to bug hunters (e.g., Google and Mozilla) as long as you don’t go public Real money is paid for your zero-day vulnerability (and exploit)
Lorenzo Cavallaro A Beautiful Journey 25/52