Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I wonder, why doesn't Apple (and MS, Google, ...) throw all their weight into the ring and lobby for making selling exploits commerically a crime? It should be up there with counterfeighting money or selling nuclear secrets. NSO Group should be on sanction lists. Politicians should be ranting about how dangerous it is that foreign companies and countries can spy on US citizens (instead of what they are usually ranting about).

You could wake up one morning, and every billboard in Washington, every newspaper will have ads for this issue. Every representative would be followed around by lobbyists. And Apple could pay it from their coffee money.

Now, I get why we don't crack down harder on selling exploits. First, intelligence agencies love NOBUS (No one but us) exploits and believe something like this exists. Second, it is convenient because sometimes foreign intelligence agencies are used to spy where domesitc agencies are not allowed to; and third the US could probably do little (officially) against companies, say, in Israel.

But this is totally the kind of issue that you could escalate into a bipartisan national security thing. And it would be an incredible marketing, and security win if Apple could push any stricter legislation in that direction.



"I wonder, why doesn't Apple (and MS, Google, ...) throw all their weight into the ring and lobby for making selling exploits commerically a crime?"

I would be strongly, strongly opposed to this.

It is a clear-cut free speech / first amendment issue.

If you don't believe me, just imagine yourself describing the pseudocode of an exploit to someone over the phone - or sketching out the details of a vulnerability in a short note.

I believe we won't get to this place because we have the first amendment but I would really love to not waste ten years fighting about it ...


I would actually say morally it is clear cut in the opposite direction. Imagine you hack into a company or a government computer and steal secrets. That is clearly illegal.

Now imagine you figure out how to do the hack, do all the preparation, and sell it ready to use to somebody. And they are open about the fact that they are selling it to foreign powers. This should definitely be illegal, too. In the physical world, you also probably shouldn't be able to go around and sell instructions how to break into cars or houses.

> If you don't believe me, just imagine yourself describing the pseudocode of an exploit to someone over the phone - or sketching out the details of a vulnerability in a short note.

I don't see how any of this would be effected. You could still do hacking, security research, you could get bug bounties, report bugs to the vendor, the government, or even disclose them to the public. You just shouldn't be allowed to sell that kind of information to a third party.

There are many laws like that right now. In the case of insider trading, you are not allowed to share certain nonpublic information against some benefit with others.


One of my favorite youtube channels is Lockpicking Lawyer. He shows how to break into all kinds of things by defeating physical security. The videos are "free" but of course he's making money off ad views, sponsors etc like any youtuber.

Should that be illegal?


> Now imagine you figure out how to do the hack, do all the preparation, and sell it ready to use to somebody.

Now imagine you notify the vendor that they have a grave security flaw in their product. They could totally turn you in to the police and the PoC is sufficient to consider you guilty. You won't be able to prove yourself innocent without a long, expensive and life-destroying legal battle.

It would have a massive chilling effect on everything else instead of what you originally intended.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: