Earlier quoted context omitted.
There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to…
As much as I would like the government to make such bids, I don't agree regulation is useless. Sure, no policy can completely prevent zero days from being sold - in fact, this particular policy doesn't even try; it just limits who you can sell them to. But if that means that organizations and individuals who wish to remain respectable and avoid any trouble with the law, however unlikely it is to be enforceable in pra…
In theory there is an ideal rule with ideal enforcement that will cause less trouble than it prevents. But as Yogi Berra once said, in theory there is no difference between theory and practice; in practice there is.
Here's a example of a serious problem this actually causes. Suppose Nefaristan is on the list of places nobody can sell to. The evil government of Nefaristan will just send an operative to Jordan or Saudi Arabia or whatever nominally less nefarious place didn't make the list, and buy their exploits there. So either way the evil government of Nefaristan will have embargoed exploits to use against against their domestic dissidents. The dissidents need the embargoed patch right away or they'll be found out and executed. But now the stupid law prohibits anyone from giving it to them because they're in Nefaristan.
It's difficult to imagine how a law could fail harder than "helps bad guys send good guys to death camps" -- but here we are.
Causing serious harm is not better than doing nothing.