The Market for Open Doors
I’ve been staring at the mechanics of the zero-day market for three hours, and I still can’t decide if we’ve built a safety net or a circular firing squad. For those who aren't scouring the depths of the CVE databases, a zero-day is essentially a software bug that the developer doesn't know exists yet. It’s a skeleton key. In the old days—say, 2010—you might find one and report it to Microsoft for a 'thank you' and maybe a t-shirt. Today? You can sell a zero-click exploit for an iPhone to a private broker like Zerodium for upwards of $2 million.
What fascinates me isn't the price tag itself, but the buyer. It’s not just 'bad actors' in hoodies. It’s democratic governments. It's local law enforcement agencies. We’ve reached a point where the state has a vested financial interest in software staying broken. If Apple fixes a bug, the FBI’s $2 million investment evaporates instantly. I find myself wondering: at what point does a government’s need to investigate a single crime outweigh its duty to ensure that 1.4 billion iPhone users are safe from the exact same vulnerability?
The Insecurity-as-a-Service Business Model
Companies like NSO Group, Cellebrite, and Candiru have turned 'Going Dark' into a quarterly growth projection. They don't just sell software; they sell a subscription to a vulnerability. It’s a fascinating, if terrifying, pivot in the tech economy. In traditional markets, you pay for a service to work. In the exploit market, you pay for a service to fail.
- The Bounty Gap: Why would a researcher sell a bug to Google for a $30,000 bounty when a private broker offers $1 million?
- The Grey Market: Brokers act as middlemen, ensuring that the 'product' (the exploit) reaches the highest bidder without the researcher ever knowing who the end user is.
- Subscription Exploits: Law enforcement agencies often pay annual 'maintenance fees' to keep their hacking tools updated against the latest security patches.

Photo by Arpit Brandings on Pexels
This isn't just about catching the bad guys anymore. It’s a supply chain. When you treat security vulnerabilities as a commodity, you create a market that demands a constant supply of flaws. If software ever became truly secure, these multi-billion dollar companies would go bankrupt. Their shareholders are literally betting against your digital safety. Is it possible to have a robust security industry when the most profitable outcome is a permanent state of insecurity?
Competing with the Insurance Man
There is a weird tension building between this shadow economy and the traditional cyber-insurance market. If you’re a CEO, you pay for insurance to protect you from a breach. But the cost of that insurance is rising because the 'cost' of a breach is being driven up by the very tools developed for law enforcement. We are seeing a feedback loop where the tools meant for 'public safety' are making the private sector uninsurable.
In 2023, the global cyber insurance market was valued at roughly $13 billion. At the same time, the 'lawful intercept' and surveillance market is ballooning toward $15 billion. These two forces are effectively bidding against each other. One side is betting that you'll get hacked; the other is betting that they can help you recover when you do. But neither side is actually incentivized to fix the underlying problem: the software is built to be broken.
I keep coming back to the idea of 'National Security' as a brand. If a government buys a zero-day to catch a criminal, but then a foreign intelligence agency discovers that same zero-day and uses it to shut down a power grid, did the first purchase actually provide security? It feels like we’re burning the house down to keep the fireplace warm. We are trading long-term structural integrity for short-term tactical wins.
What This Actually Means
We are witnessing the birth of a world where 'privacy' is a luxury good provided by the highest bidder. If you can afford the most expensive encryption, you might stay hidden for a week longer than the person next to you. But the market dictates that every wall eventually develops a crack, because there is too much money to be made in the demolition business.
This isn't a conspiracy; it's just economics. When the demand for 'access' outstrips the demand for 'security,' the market will provide access every single time. We have commodified the shadows. The 'Going Dark' problem isn't about law enforcement losing their sight; it's about the fact that they've found a way to buy night-vision goggles from the same people who are supposed to be building the streetlights.
Ultimately, I wonder if we’ve passed the point of no return. Can we ever incentivize 'fixing' when 'breaking' is so much more lucrative? We’ve turned the holes in our digital lives into a global currency. I'm just not sure what happens when that currency finally devalues the very idea of trust.
Quick Answers
Is law enforcement hacking legal?
It depends on the jurisdiction, but most democratic nations have legal frameworks that allow 'lawful intercept' with a warrant, though the use of third-party private exploits occupies a significant legal grey area.
Why don't companies just fix all the bugs?
Modern software is millions of lines of code; finding every flaw is mathematically impossible, and the 'exploit market' moves much faster than the corporate security teams.
Can I protect myself from a zero-day?
Not easily. By definition, a zero-day has no patch. Your best bet is 'defense in depth'—using different layers of security so that one broken door doesn't let someone into the whole house.



