This article was originally published on my personal blog: https://fughil.li/blog/security-exchange/
The economics of finding security bugs are upside down. Clean disclosure routinely pays less than exploitation, resale, or reporting a flaw only after you’ve used it — and the vendors on the other side can quietly benefit from keeping weaknesses out of view. AI is about to make both attack and remediation dramatically faster. I’m working on whether we can align the money, the evidence, and the decision rights around that faster cycle, so that the protective move is also the profitable one.
This isn’t a conclusion from years in the field; it’s what a single side quest made obvious. In a recent audit, a remotely reachable, pre-association memory-safety bug in a widely shipped chip was fixed — and shipped as a silent binary blob bump, with no CVE and no advisory. Not because anyone acted in bad faith, but because the vendor bears the cost of transparency while its benefits land on downstream integrators and their users. When the party who pays for protection isn’t the party who needs it, protection gets underprovided. Look once and you see it everywhere: the apparatus we lean on to handle security disclosure is quietly, structurally inadequate. That’s an incentive problem, and incentive problems don’t yield to good intentions<sup>[1]</sup> — only to better incentives.
So: a security exchange, designed to make verified disclosure more attractive than exploitation, while giving vendors a real reason to protect the people who depend on them.
The easiest way to see what that means is to pull up a chair for each person the current system fails — and then imagine the same chair once the incentives are fixed.
Six chairs #
The user
Today. You bought the thing — a camera, a door lock, a health gadget — with no way to know whether its security was ever tested, or whether the last silent “firmware update” quietly closed a remote takeover. You learn you were exposed after it has already been used against you.
Tomorrow. The device carries a record you can actually read: what was tested, what failed, what was fixed, and what nobody ever looked at. Safety stops being an adjective on the box and becomes something you can check.
The vendor
Today. Every disclosure is a threat — a support cost, an optics problem, a buyer question you would rather not field — so the rational move is to patch quietly, downplay, and skip the advisory. Doing the right thing loudly is the option that gets punished.
Tomorrow. You fund a bounded, pre-agreed testing budget and get something back for it: verified remediation that lowers your risk charges, and a public record that rewards the fix instead of the silence. Protecting users becomes something you advertise, not a liability you bury.
The innovator
Today. You choose a chip or a platform on price and time-to-market, because that is what you can see. The real security of your options is invisible at the moment you commit — the kind of thing you would have to disassemble a blob to learn — so it never enters the decision, and you inherit whatever you couldn’t check.
Tomorrow. Security is a spec line with numbers beside it, comparable across vendors. You can pick the part that respects your users without having to reverse-engineer it first — and “we tested, here is the record” becomes a reason customers pick you.
The hacker
Today. You found something real. Your options: sell it to someone who won’t tell anyone, report it and let the vendor decide whether, when, and how much you are paid, or simply use it. Clean disclosure is usually the worst-paid, slowest, and least-respected of the three, and the vendor holds every lever<sup>[2]</sup>.
Tomorrow. Priority is timestamped the instant you submit, the payment is reserved before you start, and no vendor can reclassify your finding into nothing after the fact. Clean disclosure competes with the alternatives on money and speed instead of losing to them by default.
The insurer
Today. You price cyber risk on questionnaires and hope. You cannot tell a genuinely hardened fleet from a lucky one, so everyone pays the blended rate and the careful subsidize the careless.
Tomorrow. You fund verified protection where it measurably lowers losses, and price policies on evidence instead of attestations. The premium finally rewards the thing you actually want: fewer and smaller incidents.
The legislator
Today. You can mandate disclosures and CVEs, but you cannot conjure the market that makes them worth issuing. Rules without incentives get met on paper and evaded in practice.
Tomorrow. There is an evidentiary substrate to aim policy at — portable, auditable records of what was tested and fixed — so “reasonable security” can be measured instead of argued, and the incentives carry the enforcement a statute alone never could.
What I won’t pretend #
None of this is magic. An exploit is copyable, so buying a disclosure cannot prove exclusivity or stop a seller from collecting both a bounty and the proceeds of abuse. A bigger reward alone does not fix that. The model’s job is to make that failure mode explicit and measurable — and then to test, in a bounded paid pilot on one ecosystem and one narrow class of failure, whether people actually prefer clean disclosure when the incentives are arranged this way. It is a hypothesis with a funding constraint attached, not a finished system, and it should be held to that standard.
Looking for collaborators
I’m looking for people who want to build this with me. If you work in security research, mechanism or market design, cryptographic settlement and custody, or you’ve run a disclosure program — or you operate an ecosystem that could host a first pilot — I want to talk.
For the curious: a closer, more technical description — the participants, the settlement and verification mechanics, and the open problems — is written up here.
Notes #
- This is the same conviction that runs through The Monolith : you cannot secure something as important as trust on the strength of good intentions. You have to build the system so that the incentive and the right outcome point the same way — and then be able to show that they do.
- Prefunding, managed programs, and some protections for outstanding rewards are already part of, e.g., HackerOne’s published customer terms (§§5–6). The open question this exchange targets isn’t whether rewards are funded — it’s who holds the decision rights over classification, timing, and disclosure. These are incentive risks to validate, not allegations about any platform’s conduct.