Skip to main content

Netragard stops selling exploits for fear of how they may be used

kentucky hospital subjected to ransomware hacker keyboard
Digital security firm Netragard has announced that its controversial Exploit Acquisition Program (EAP) will be halted moving forward, after it was discovered that it had been selling exploits to Italian firm Hacking Team, which was recently found to be doing the same to regimes guilty of human rights violations. Although Netragard still believes zero-day exploits are important, it cannot continue to sell them without knowing their potential end-game usage.

“Our motivation for termination revolves around ethics, politics, and our primary business focus,” said Netragard CEO Adriel Desautels in a blog post. Although he said that it wasn’t the responsibility of a seller to determine what customers would do with their products, in light of what Hacking Team was found to be up to, it could no longer ethically continue selling them.

The reason it’s possible for Netragard to do this, is because as Desautels points out, EAP isn’t the company’s many focus – even if it has proved a strong revenue stream.

While Desautels wants to pull Netragard back from the brink of being linked with Hacking Team’s immoral sales of exploits to countries headed by decried regimes, he did take a moment to defend the development and use of zero-day exploits. Highlighting how the FBI used a flaw in the Flash player in 2013 to help close a child pornography ring, he suggested that those that are against the use of such ‘tools’ were merely uneducated about them.

Moving forward, Netragard will only reintroduce its EAP system if a framework is put in place to regulate it better. However, Desautels did add the caveat that he didn’t want to see the practice of discovering these exploits restricted, as that would negatively affect those striving to improve software security around the world, he said.

Editors' Recommendations

AI is making a long-running scam even more effective
An elderly person holding a phone.

You’ve no doubt heard of the scam where the perpetrator calls up an elderly person and pretends to be their grandchild or some other close relative. The usual routine is to act in a distressed state, pretend they’re in a sticky situation, and ask for an urgent cash transfer to resolve the situation. While many grandparents will realize the voice isn’t that of their grandchild and hang up, others won’t notice and, only too keen to help their anxious relative, go ahead and send money to the caller’s account.

A Washington Post report on Sunday reveals that some scammers have taken the con to a whole new level by deploying AI technology capable of cloning voices, making it even more likely that the target will fall for the ruse.

Read more
The popularity of ChatGPT may give Nvidia an unexpected boost
Nvidia's A100 data center GPU.

The constant buzz around OpenAI's ChatGPT refuses to wane. With Microsoft now using the same technology to power its brand-new Bing Chat, it's safe to say that ChatGPT may continue this upward trend for quite some time. That's good news for OpenAI and Microsoft, but they're not the only two companies to benefit.

According to a new report, the sales of Nvidia's data center graphics cards may be about to skyrocket. With the commercialization of ChatGPT, OpenAI might need as many as 10,000 new GPUs to support the growing model -- and Nvidia appears to be the most likely supplier.

Read more
Gmail client-side encryption adds security for businesses
Google services (YouTube, Gmail, Chrome, Duo, Meet, Google Podcasts) icons app on smartphone screen.

Google has made client-side encryption (CSE) available for a number of its Workspace applications after introducing the function in beta mode last December.

Detailing the feature in a blog post on Tuesday, Google announced that client-side encryption would allow professional users to send data in Gmail and Calendar apps in such a way that no one except those in the organization and the recipients can access or read the content. Google as an entity is not even able to access data sent or created through Gmail or Calendar as it would be encrypted before reaching its servers. This is yet another way Google is using AI to the benefit of customers the brand said.

Read more