Hacker News new | ask | show | jobs
by dorian-graph 3323 days ago
The reality is, this is very common.
1 comments

Then what, realistically, can be done when nation-state knowledge of vulnerable systems is hoarded for cyber-warfare purposes?
Frankly, there is only one solution I can see anymore:

Laws must be passed to:

* Force the US government to report vulnerabilities to vendors

* Create a regulatory body to monitor the use of vulnerabilities in clandestine operations and ensure that mandatory reporting is upheld

I cannot see anything less working.

Get that through US and EU governments, and you'll likely have the vast majority of vulnerabilities being reported and patched.

Of course this is akin to asking the US and Russia to convert their nuclear stockpile into reactor fuel.