Well maybe there's some light at the end of the tunnel: If hackers had an easier way to gain recognition and being rewarded when they discover vulnerabilities, I'm certain most would choose to disclose their findings rather than try selling them on the black market. I'm working on a startup right now, www.crowdcurity.com, where we want to let any site easily create a bug bounty program (similar to Google, Mozilla, Paypal, etc.) and thereby leverage testers around the world to find vulnerabilities; hopefully initiatives like this will strengthen the security of web apps and websites around the world.

