Should U.S. Hackers Fix Cybersecurity Holes or Exploit Them?
theatlantic.com
theatlantic.com
As a third option, a country may decide to just patch their devices, but not disclose the vulnerability. Protect themselves while leaving others vulnerable.
When other parties find and exploit the vulnerability (and they will), the best case scenario is, "Darn, we can't exploit that anymore". The worst case scenario is that exploitation causes some major disaster (widespread power outage, loss of SCADA control, etc.) that impacts us all somehow and that could have been avoided.
Broad, public disclosure and patching seems the best choice for everyone.
That said, the idea of an entity using the moniker of "cyber-weapons arms manufacturer" gives me goosebumps. I know it's mostly just undisclosed vulnerabilities, but these are complicated machines we have in our laps. How long until they find a way to weaponize them? Or has that ship sailed?
Helping protect people just gets you harassed.
On the other hand, I've also reported a lot of bugs to projects over the past couple of years. Most projects are grateful for the help, a few (Taylor Otwell of Laravel and Daniel Kerr of OpenCart) are arrogant and hostile, but they're not the norm.
Reporting critical ones that results in major changes tends to win hatred and negative attention overall. There is positive mixed in but it does not outweigh the negative.
Possible ways to handle critical vulnerabilities:
1. Sell them to the highest bidder. Typically that bidder is the government. There is an open legal market for this. Result: You make some money, the government uses bugs against people, and you are viewed as a traitor by the software community.
2. Sell them to the black market. This is criminal behavior. Figure this one out for yourself.
3. Do nothing. This is what most people do. Result: You are normal.
4. Use them in some illegal fashion for yourself. ( See #2 )
5. Tell your boss. Result: If you were told to be looking at it, you will get kudos. If you were not, you will get yelled at for wasting time, and told to do #3.
6. Tell the company who makes the software. Result: If there is a bug bounty program and you report it through that, you get a small bit of money ( not worth it ), and it gets fixed. If there is not, your message will likely be ignored.
7. Tell the public. Result: You will be ignored.
8. Tell the public loudly. Result: You will be mocked.
9. Tell the publicly loudly and demonstrate the problem. Result: Everyone will attack you for making it possible for people to abuse the problem.
10. Demonstrate the problem for yourself. Notify the company first anonymously. If they don't listen or do anything notify the public, including documentation of your attempting to notify the company. If the public still ignores you also publish the demonstration. At no point let on who you are; it is just not worth it.
Only #10 is a solution that works in all scenarios, and it brings little reward for the person finding and reporting the issue.
I am obviously ignoring the case where you are hired as a pentester. That is a whole different story.