
Why Governments Love to Buy the Bugs in Your Favorite Apps🎙Darknet Diaries Ep. 98: Zero Day Brokers
Source: YouTube · Jack Rhysider · published Oct 19, 2023 · 50:14
This video explores the secretive grey market for exploits where vulnerabilities are sold to governments and companies, operating legally but with extreme confidentiality 0:00.
Key Takeaways:
• The host has interviewed various cyber-crime stakeholders, but exploit sellers consistently refuse interviews 0:04
• The grey market for exploits is legal, with governments as primary buyers who want vulnerabilities kept secret 0:23
• Extreme confidentiality measures including NDAs protect both the exploits and the identity of buyers 0:28
This underground market highlights the ethical complexity of cybersecurity research and government acquisition of digital weapons 0:34.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
JACK: Hey, it’s Jack, host of the show. I’ve been
making this show about cyber-crime for a few years now. I’ve interviewed attackers, defenders,
black hats, white hats, law enforcement, even nation state actors. But there’s
one type of person who always refuses to be interviewed for the show, and that’s
people who find vulnerabilities and sell those exploits to governments or companies
that will use it to attack people with. This is the grey market for exploits. It’s
completely legal since it’s often governments who buy the exploit, but it’s just very
secretive. Maybe there’s NDAs behind each deal where the people who bought it want the exploit
to remain as unknown as possible. On top of that, they don’t want anyone to know they just acquired
it, because if someone buys an exploit…