Do you actually believe this?

The CIA ran one of the world's largest cryptography companies, for DECADES[1]. Are you truly so naive that you believe intelligence agencies that have more to gain from stifling the discovery of vulnerabilities they know of and use wouldn't do so?

[1] https://www.washingtonpost.com/graphics/2020/world/national-...

You should probably realise that the world has radically changed since then. This kind of thing works when you have a significant lead in the field that makes keeping vulnerabilities open sufficiently low risk for your own side. But if your adversaries have similar capabilities, then the calculation changes.

Has anything changed? Governments are hoarding undisclosed vulnerabilities, using them as they see fit instead of fixing. Every espionage, surveillance, or war campaign (see Russia v Ukraine, US/Israel v Iran etc) is followed by a ton of burned 0-days.

>This kind of thing works when you have a significant lead in the field

No? It works even if the adversary has the same capabilities. It only stops working when everything is fixed.

I believe it is unlikely. (Not because I do not believe NSA is hoarding 0-days, but for many other reasons.)

I'm curious: to any professional vulnerability researchers reading this, what do you think?

I used to call everything a conspiracy theory, but then Glenn Greenwald published "No Place to Hide: Edward Snowden, the NSA and the Surveillance State".

Now i know that reality is worse than the worst conspiracy theorist.

I don't think reasonable people post here much anymore. It's mostly galaxy brained conspiracy theorists and ignormamuses posting political garbage. Reddit-lite on the way to full blown Reddit

Why would you even believe the opposite? US spooks have been amassing vulnerabilities and relying on them for decades, they literally pioneered it in the 90's if not earlier. Everyone does it now but the US is the biggest of them all. Surely this devalues a lot of what they did. Moreover, the way the US government handled new capabilities, and OpenAI's training policy (they are in bed with the government) just scream "we want to create weapons for cyber-offence and deny them to everyone else"

It might not be the reason, but of course it's a contributing factor.

[flagged]

Good thing I said nothing of that (especially nothing about China). Reread it again to understand you built an incredible strawman and ignored my last sentence.

Well we know that the US government is pushing to restrict access to such models while the Chinese are publishing them for free, so it's mostly a matter of motivations, not the actual facts of the matter. And the USG has a documented history of unsavory behavior (including toward its own citizenry) in that area.

So we might ask if one of the reasons the US is being the bad guy is it's usual spying antics, and we're left asking why China is being the good guy.

Intelligence agencies have been known for exploiting and planting software and hardware Buga for decades, going as far as weakening cryptographic standards or intercepting hardware in transit to implant a backdoor device.

Why do you _not_ believe it's a possibility?

Critical thinking says this is not only possible but likely too.