Earlier quoted context omitted.
I'm not saying it's impossible to generate an intellectually coherent set of regulations for exploits, just that the process of doing so is going to damage the 1A protections of a lot of other things over the long run. Is it worth it? I don't think so. Unless you also regulate research , which is a non-starter, you're just driving exploit development out of the US. Substantial amounts of exploit dev are already done…
> If virtually all of it leaves the country, what public policy problem have you solved? A good point. A couple ideas, though neither is sufficient: * International agreements control distribution of other dangerous goods; that's doable. However, look at how well that works with drugs, and even nukes get around. * At least stop sophisticated organizations (defense contractors, SV firms, etc.) from making them for for…
It's a very difficult problem.
There's also some bigtime cognitive availability bias happening here. We read lurid stories centering on "zero-day exploits" and say "something must be done". But no matter what these articles say, it seems cosmically unlikely that an exploit dealer is worth a billion dollars; the entire exploit trade is a rounding error compared to the switching and filtering equipment companies knowingly sell China and Iran for use in putting dissidents to death.