5 ms·
> making software like this for sale to the highest bidder should not be something a company is able to do legally. I disagree. There ahould be nothing inheren
by hermitdev 7y ago
> making software like this for sale to the highest bidder should not be something a company is able to do legally.
I disagree. There ahould be nothing inherently illegal about owning, making or selling such software to an entity that can legally use it. (I would assume any country employing such software would indemnify there agents using it against foreign adversaries).
Not that I like it, and as a private citizen, I dont like thw prospect of being spied on, even though I have nothing to hide.
To stop it, I think you'd need to take a step back into the 90s and early 2000s and classify such programs as munitions and restrict export (not that all offerings are from US countries).
- georgespencer 6y ago> I disagree Have just read your answer and I totally see your point! I don't agree but it's definitely a judgement call. Perhaps this would be a better way of expressing my position (with a few simplifications of the current situation): 1/ It seems morally wrong for it to be possible for an American company to buy spyware which exploits security vulnerabilities in another American company's software. The act of exploiting those vulnerabilities is illegal in the United States and against the terms of service of the software developer. The outcome of the exploitation (mass clandestine collection of user data without any permissioning) is also illegal. 2/ The US government could solve this by making it illegal for US companies to use the software, outright. They and other nations could also solve or diminish the issue for foreign nations by precluding private companies within their jurisdiction from building commercial propositions around these vulnerabilities. So both a ban on domestic "import" of the product, and a ban on "export" too. 3/ Clearly government agencies need and will continue to produce and procure software like this in the same way as they need to produce and procure military-grade assault weapons, surface-to-air missiles, and stealth bombers. The production, trafficking, and purchase of these items is highly regulated and tightly controlled: I cannot simply start manufacturing firearms because I have the equipment! This regulation is in part a means of preventing widespread availability of dangerous items getting into the hands of consumers and bad actors. 4/ At the very least, the same ought to apply here: an infosec company wishing to auction exploits or sell spyware SaaS should have to be very tightly regulated by the state, and should be unable to sell any of its products or services to any domestic or foreign entity without state approval — a QUANGO of sorts.