Exploits are not weapons, they are research. They are the discovery of the correct sequence of bytes that someone else's program has been written to accept as input and perform actions that the author (probably) did not intend. Exploits are not any act of doing this, they are the knowledge of how to do it.
There is no physical analogy. A bomb doesn't care what its target is, it's an indiscriminate destructive force. You cannot do something similar with an exploit. The exploit only has context within the rules set forth by the programmer of the target software.
Just because I know which inputs you accept that cause unintended behavior, that you put there and I had nothing to do with, does not mean I have "created" something, positive or negative. Fundamentally, exploits are not created, they are discovered.
This discovery process is expensive, and it's easy for you to say that it is ethical for me to share what I've found for free. I think that's arrogant and disrespectful, and I also think that criminalizing my knowledge is far more dystopian than what you think my knowledge might be used for if shared with someone else.
I don't like what some governments are doing with them or that my tax money is feeding the industrial complex, but such a fundamental attack on freedom cannot be tolerated.
There is no physical analogy. A bomb doesn't care what its target is, it's an indiscriminate destructive force. You cannot do something similar with an exploit. The exploit only has context within the rules set forth by the programmer of the target software.
Just because I know which inputs you accept that cause unintended behavior, that you put there and I had nothing to do with, does not mean I have "created" something, positive or negative. Fundamentally, exploits are not created, they are discovered.
This discovery process is expensive, and it's easy for you to say that it is ethical for me to share what I've found for free. I think that's arrogant and disrespectful, and I also think that criminalizing my knowledge is far more dystopian than what you think my knowledge might be used for if shared with someone else.
I don't like what some governments are doing with them or that my tax money is feeding the industrial complex, but such a fundamental attack on freedom cannot be tolerated.