[RFC] A Sketch of an International Vulnerability Equities Process and a 0-Day Emissions Trading Regime

In September 2019 I participated at the interdisciplinary conference ‚Science, Peace, Security‘ in Darmstadt. There, I held a talk on cyber-arms control and presented a paper presenting a draft idea of an International Vulnerability Equities Process and a 0-day vulnerability emissions trading regime. I looked at the current state of research on cyber-arms control regimes and pretty much every paper said, arms control is not working. I compared the different regime approaches that have been taken by others and present my findings. Based on this the idea was: if traditional arms control models do not fit to the the digital domain, lets consider other regime types that deal with negative emissions – 0-days technically are negative emissions of industrialized software production – and see what we can learn from this. The other idea was to international the local Vulnerabilities Equities Processes that pop up in the US, UK, Germany, China and other countries. If governments start to limit their offensive cyber-capabilities by selecting certain 0-days for exploitation, and report others to vendors for disclosure, what could an internationalized mechanic for this look like? While I am doubtful about the incentive structure of a regime, this could at least serve as a confidence building measure to restrict the most damaging cyber-attacks. Since this is pretty much research in progress and a wild idea, I invite comments on my paper, hence the RFC or Request for Comments in the title. You can find the full paper in the conference proceedings here. You can either drop me a note in the comments below or send me an email to percepticon[at]protonmail.com.

