Hacker News new | ask | show | jobs
by doesnotexist 799 days ago
I do not believe there are any restrictions on what 0-days can be sold to or bought by the American government. As far as I know the only thing resembling restriction is regarding export to non-allies which stems from the Wassenaar Arrangement. https://en.wikipedia.org/wiki/Wassenaar_Arrangement

And I'm not entirely certain how codified into law such restrictions are on private citizens and companies. There is always article 3 section 3 clause 1 of the constitution where it outlines the crime of treason as "levying war against them, or in adhering to their Enemies, giving them aid and comfort." Though I don't know that selling a security vulnerability to a foreign government would be considered treason or trigger any related laws. I'm unaware of any prosecutions or civil suits against private citizens or companies regarding the trade of 0-days.