WabiSabiLabi may shut down its online marketplace for security vulnerabilities, focusing instead on the line of OneShield unified threat management (UTM) appliances it developed with Italian defense company EuroTech.
Last year, WabiSabiLabi opened an online auction site for unpatched security vulnerabilities, also called 0days. The company"s stated aim was to provide a market that would allow independent security researchers to earn a living from the vulnerabilities they discover. To prevent vulnerabilities from ending up in the hands of criminals, only qualified buyers are permitted to use the WabiSabiLabi auction site.
While security companies routinely pay researchers for vulnerabilities and then keep this information under wraps, some believe researchers should first disclose such vulnerabilities to vendors free and, when a patch is released, make details of the vulnerability publicly available, a practice known in the security community as ethical disclosure.