Google directly competes with the grey market for vulnerabilities. They are competitive in a bunch of different directions:
* They pay for vulnerabilities without reliable exploits (more for vulnerabilities that are demonstrably reliable).
* They don't require you to actually build a reliable exploit chain.
* They pay up front, not in tranches.
* They work with essentially all comers, unlike the grey market, where you're generally subcontracting to sell your first few.
They pay in plain old money, too. On the market your counterparty will be a criminal who is trying to scam you every step of the way.
Not so much, the grey market is pretty well structured.
Is there anywhere I could read more about this?
Sound very interesting!