DISQUS

Matasano Chargen: WabiSabiLabi Co-Founder Arrested

  • PaulM · 2 years ago
    I think WabiSabiLabi proved that there is an inherent problem in trying to sell vulnerabilities in a marketplace environment. The primary problem being that, in order to market your vulnerability to buyers, you have to describe it enough that the vulnerability can be found by other researchers before its sold.

    The fact that Preatoni got busted only serves to confirm what most above-board infosec pros already suspected about the shadiness of WabiSabiLabi.
  • ivan · 2 years ago
    According to all public sources, the arrest of Roberto Preatoni is not at all related to WabiSabiLabi so this hardly serves to confirm any of the suspected shadiness of WSL.
  • cmlh · 2 years ago
    @Dave G,

    Based on the failing (due to agenda) of (particular) Researchers, Coordinators (i.e. FIRST Members) and Vendors - Which "trusted person or organization" is left "that can represent vulnerability researchers whose reputation is at stake when dealing with vendors."?
  • Dave G. · 1 year ago
    @ivan:

    The jury is still out on all of this, and he could very well be innocent. But this is the CEO and Co-founder of a company that was arrested for something that absolutely would degrade one's trust that allegedly happened just prior to starting WSL.
  • Steve Christey · 1 year ago
    cmlh - some vulnerability researchers have tried and failed to organize on a couple occasions. Maybe it's due to the heavily independent nature of researchers as a group, but the Pwnies is the best they/we have been able to come up with so far. I liked the Pwnies, but it's nothing compared to a guild or non-profit advocacy organization that speaks solely for researchers. This failure to organize continues even in light of growing legal threats.
  • cmlh · 1 year ago
    @Steve Christey,

    The only prior effort that I am aware of is when Greg Hoglund built “Zero-Bay”, which he then abandoned due to the “possibility” of legal threats prior the launch.
  • cmlh · 1 year ago
    @Dave G

    I disagree to your response to Ivan – ppl tend to focus on the company rather then senior individuals of a company as the Executive can be reshuffled or the company is sold.

    That stated, their existing sellers would lose “trust” in WabiSabiLabi if they attempted to take ownership or resold their IP without their consent.
  • Dave G. · 1 year ago
    @cmlh

    I think it depends on the size and stage of the company. In a small startup, the senior individuals ARE the company. If the allegations were true, I would think their existing sellers (and buyers), would have to wonder if WSL is re-using this information.
  • sigsegv · 1 year ago
    I love it when a so called "whitehat" is publicly revealed in a manner like this. It always brings a grin to my face.

    But honestly, who really trusted somebody affiliated with zone-h? Would you hire the people who were part of the original PHC or were responsible for the production of el8 and trust them implicitly (and for the record, any of those guys would be far more skilled than the WSLabi guys)? Probably not.

    The same idea should apply to "security professionals". You do have the college educated kids these days, who lack real world hacking experience (they got into computer security for money), and you have the so-called reformed hackers who now work for a company. You really need to know who you have working for you.

    And Dave, I agree with you when you say that you're not sure if selling exploits is a good idea. It's not. It's a terrible idea. One of the worst I've heard in my life. It's no different than the arms trade.

    And I wouldn't be surprised if the WSLabi guys took a copy of the 0day for themselves. Could you honestly say you'd pass up 0day (and money!)?
  • cmlh · 1 year ago
    @Dave G,

    I disagree that this will be the case.

    WabiSabiLabi will simply put themselves on the market for a buyer if Roberto is innocent until proven guilty at the conclusion of this trial that is either:
    1. Unaware of the trial.
    2. Aware but willing to invest to limit the damage caused (e.g. rebranding WabiSabiLabi)

    If Roberto is found not guilty, then this will exonerate Roberto and (in your mind) WabiSabiLabi.
  • swinky · 1 year ago
    Indeed, Preatoni started his recruitment for Telecom Italia 4 years ago. Among them, DkD (Damien) famous french script kiddy and cyber jihadist (here is interview with him from Zataz (the worst security magazine ever) http://www.zataz.com/interviews-securite/7049/d...)

    So now, how Telecom Italia can accept to recruit ex defacer for islamic jihad ??? Maybe Preatoni never talk about his past before ??? Who is really this zoneh guy ???

    As for myself, Preatoni will be charged for this because i'm really sure he is guilty. I mean he even tried to recruit defacers from Morocco and Egypt .. hell, this is really nut !!!
  • sohbet · 4 months ago