Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yes, I'd publish either right away or after a short delay to allow especially important websites to revoke RSA certificates. (I'd ask some better-informed cryptographers which is best.)

Perhaps you're thinking that you could make huge $$$ breaking into computers with it. Not really. There are already ways of breaking into many webservers and stealing info and crooks already do this, so we know how profitable / risky it is: not very / very.



I'm not so sure, unlike other vulnerabilities we talk about here as being nearly worthless (things against facebook, etc) this would take a serious amount of effort to protect the internet against and have a very long tail of patching. I would bet that you could get a pretty penny selling it. To either a state agency or a large criminal enterprise.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: