<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Selling Vulnerabilities and Ethics</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/18/selling-vulnerabilities-and-ethics.aspx</link><description>Shoaib just blogged on Hacking &amp;amp; Security Community - Ethical or Unethical? . To start with: I do not claim that I know all about ethics and that there is only one view on ethics but I have a clear view on certain things. I blogged on this theme several</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Selling Vulnerabilities and Ethics</title><link>http://blogs.technet.com/rhalbheer/archive/2008/05/18/selling-vulnerabilities-and-ethics.aspx#3057153</link><pubDate>Mon, 19 May 2008 07:13:05 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3057153</guid><dc:creator>Shoaib Yousuf</dc:creator><description>&lt;p&gt;Hi Roger,&lt;/p&gt;
&lt;p&gt;As you mentioned - WabiSabiLabi tells us that they will not sell to the bad guys and that they check the identity.&lt;/p&gt;
&lt;p&gt;We all know for the matter of fact - it is just take few mins to create identity. We need to keep in mind that bad guys can do anything dirty to cause any harm. They don't care for ethical and unethical stuff but we do.&lt;/p&gt;
&lt;p&gt;If any security researcher finds any vulnerability - i think he should notify the vendor first as you said.&lt;/p&gt;
&lt;p&gt;Cheers&lt;/p&gt;
&lt;p&gt;Shoaib&lt;/p&gt;
</description></item></channel></rss>