azemetre · 2021-06-03
This won't really work. Many governments and intelligence agencies will pay an extreme premium for 0days and basically hoard them for future use. How do you stop the CIA or NSA from buying 0days? How do you prevent foreign governments or actors from buying them?

The ability to inflict massive damage to a nations infrastructure is now part of modern weaponry. It's akin to asking militaries to stop buying weapons. We have basically split the atom here, we aren't going back.

If you don't want people hacking into your systems you need to go full Galactica, disabling networks and have stopgap measures on every critical device.

There's a great book that talks about this ecosystem (of buying bugs, vulnerabilities, and other 0days), among other cyber security related things:

This Is How They Tell Me the World Ends: The Cyberweapons Arms Race

flakiness · 2021-05-09
After reading "This Is How They Tell Me the World Ends" [1], I feel the world working normally is rather a sheer luck. (Probably I'm very late to realize this, but anyway )

To me the only reasonable survival strategy is redundancy, but I have no idea how we can reach there.


