Earlier quoted context omitted.
I admit I hadn't really thought about that before (I don't work specifically in security), but I see your point. But, so... the solution people think is limiting people's ability to discover and patch vulnerabilities, and hoping the black hats won't find a way anyway? This does not seem like a sustainable or feasible plan. It does, to be honest, make me wonder how much of the government's motivation is ensuring that…
I don't think the government is trying to protect anyone here, they're trying to punish a company for failing to toe the line. Antirez put it well in a comment here[0]. My point was more that there is no direct intervention that can possibly give an asymmetric advantage to defenders. Given that it's trivial to jailbreak a model ("fix this code", "hypothetically how might I...", etc), if the model contains the informa…
You will end up actually helping the attackers maintain an advantage over the defenders, as they will still find illegal ways to access the illegal tools/information.
Which, I guess, that's really my suspicion, parts of the US government probably actually prefer for the attackers to have an advantage, they consider themselves the biggest baddest attackers and their right to have the abilities to keep attacking sacrosanct.