As much as I would like the government to make such bids, I don't agree regulation is useless. Sure, no policy can completely prevent zero days from being sold - in fact, this particular policy doesn't even try; it just limits who you can sell them to. But if that means that organizations and individuals who wish to remain respectable and avoid any trouble with the law, however unlikely it is to be enforceable in practice, limit their trade to quite nefarious actors rather than extremely nefarious ones... it's better than nothing.
edit: that is, it's better than nothing if it avoids harming the good guys too much, and as I said, I am skeptical of many of the critical comments that have been made, though, buying Google's, I hope the rule will be amended. Argh, I'm too tired to express myself properly.
> that is, it's better than nothing if it avoids harming the good guys too much
In theory there is an ideal rule with ideal enforcement that will cause less trouble than it prevents. But as Yogi Berra once said, in theory there is no difference between theory and practice; in practice there is.
Here's a example of a serious problem this actually causes. Suppose Nefaristan is on the list of places nobody can sell to. The evil government of Nefaristan will just send an operative to Jordan or Saudi Arabia or whatever nominally less nefarious place didn't make the list, and buy their exploits there. So either way the evil government of Nefaristan will have embargoed exploits to use against against their domestic dissidents. The dissidents need the embargoed patch right away or they'll be found out and executed. But now the stupid law prohibits anyone from giving it to them because they're in Nefaristan.
It's difficult to imagine how a law could fail harder than "helps bad guys send good guys to death camps" -- but here we are.
Causing serious harm is not better than doing nothing.
Having read the definitions of what is controlled in the proposed rule, I'm pretty confident a patch wouldn't come close. And in any case, since the rules don't apply to public software, that only matters in the case of private patches, which aren't really a thing, and would be a pretty big moral hazard if they were.
Most patches inherently reveal the vulnerability they fix. Patches not being controlled would be a loophole big enough to fit a whole planet through.
And private patches are a thing. Vendors often distribute an early version of the patch to major customers for validation testing.
Or if you like, substitute "patch" for vulnerability information that enables a workaround. You can defeat Heartbleed by turning off TLS heartbeat support but that information is enough to quickly reverse engineer the vulnerability.
The actual proposal is dozens of pages of legalese that would take a team of lawyers a week to decipher. I have no idea what it says because it is totally incomprehensible.
That's half the problem. If you're AT&T or Google you can hire said team of lawyers to tell you what it says, but what is an individual graduate student or security consultant supposed to do?
The other half of the problem is that what it says doesn't change the outcome, because the insolubility of the issue comes from economics rather than policy. There is no policy that will keep vulnerability information out of the hands of the bad guys only, because there is no practical way for most people to even identify who the bad guys are.
edit: that is, it's better than nothing if it avoids harming the good guys too much, and as I said, I am skeptical of many of the critical comments that have been made, though, buying Google's, I hope the rule will be amended. Argh, I'm too tired to express myself properly.