Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Banning trade with zero-day vulnerabilites? #81

Closed
realpixelcode opened this issue Jul 26, 2022 · 1 comment
Closed

Banning trade with zero-day vulnerabilites? #81

realpixelcode opened this issue Jul 26, 2022 · 1 comment

Comments

@realpixelcode
Copy link
Contributor

Basically, there are companies that specialise in finding zero-day security vulnerabilites in software (“zero day” stands for “zero days since the developer discovered the vulnerability”, meaning it hasn't been discovered at all). Since they sell that information to cyber criminals and even authoritarian countries, their business model directly harms the digital security of end users as well as our critical infrastructure. That's why I propose banning it altogether.

Possible phrase to be included in the licence:

the systematic trade with zero-day security vulnerabilites in software accessible to the general public, without disclosing them to the public, the developer or the responsible state authority

@tommaitland
Copy link
Contributor

This overlaps with #73 on hacking and cybersecurity so let's continue discussion there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants