Ethics of the software vulnerabilities and exploits market
本文论证了在专有软件中识别漏洞及开发、销售、购买非零日利用在伦理上合理,但在自由/开源软件中仅限极窄情形;并建议民主政府立法激励企业内部漏洞识别与修复。
In this article we establish three claims: (1) When the target software is proprietary, in the absence of other overriding ethical considerations, the identification of a vulnerability and the development, sale, and purchase of non-zero-day exploits are ethically justified; (2) when the target software is Free/Libre/Open Source, the buying and selling of vulnerabilities can be ethically justified only in a very narrow situation, while the sale and purchase of non-zero-day exploits is ethically justified absent of any other overriding information; and (3) democratic governments should promote legislation that either incentivizes corporate in-house vulnerability identification and mitigation programs or requires firms to more fully absorb the societal costs of insecure software.