Described in those terms, what would you say to an exception that permitted possession by authorised information security personnel?
That's akin to the legislation we have in the UK with regards to explosives and controlled substances.
Described in those terms, what would you say to an exception that permitted possession by authorised information security personnel?
That's akin to the legislation we have in the UK with regards to explosives and controlled substances.
There should never be a legal concept of an "authorized" information security person. It's about like defining a concept of an "authorized" painter or musician, since all are talents that can be developed in isolation.
But that's a whole different argument. At present it is "programmers" (self-taught or academic or industrially trained) who make things and routinely test them for hardness. You can't suddenly invent rules that say only certain types of programmer may use and deploy "hacking" tools. That won't work because there is no defined path to test suitability or career fitness in the majority of people who define themselves as "programmers". Too broad a church. Too many disciplines and areas of specialisation. And too few people qualified to legitimately or meaningfully assess that either way. Or are we going to say, for example, only Microsoft Certified Pros are allowed to test? God in heaven forbid!
Reputation (from both peers and clients) and demonstrated output that works is the only test for whether someone is a good or bad (read, fit or unfit) programmer.
And no, in answer to your question, we don't allow only certain government regulated individuals to have legal access to perfectly ordinary systems analysis tools. They are probably the last people you want doing it.