A state operator holds an unfixed exploit for your fleet's document renderer — why use it on one person?
answer
- Value depends on something outside the holder
- Using it is what ends it
- The loss is global, not per-target
- Price the use against all future uses
- Cheap methods for everyone else
basics
~20 sAn unfixed exploit is a wasting asset. Every use puts a copy somewhere the operator does not control, and one recovery leads to a fix that destroys its value everywhere at once. Broad use burns it fast, so it is spent narrowly.
solid answer
~50 sBecause the exploit's value is destroyed by the very act of using it. It works only while the vendor has shipped no fix, and each delivery drops a copy onto a machine the operator does not own — where it can be recovered, sent to the vendor, and fixed. Crucially, the loss is not local: one recovery anywhere ends the exploit against every target in the world, including the one the operator actually cared about. So the calculus is per-use: is this recipient worth possibly never using this again? Against a single named person holding the information the operation exists to get, yes. Against a whole laptop fleet, almost never — mass delivery multiplies the chance of recovery while adding targets the operator has no interest in. Expect narrow delivery, gated so it only fires for the intended recipient, and cheaper techniques used everywhere else.
go deeper
Be ready to say that an unfixed exploit stops working once the vendor fixes the flaw, and that using it is what tends to get the flaw noticed.
Explain the mechanism of the loss: a copy has to reach a machine the operator does not control, one recovery anywhere produces a fix for everyone, so each use is priced against every future use.
Demonstrate the inversion — knowing an unfixed exploit exists for software you run predicts very little about your own exposure, and the real question is whether your organisation is worth spending it on.
Own the planning consequence: this economics is why an estate cannot buy its way out of the unfixed case, and why the threat assumptions you write down should turn on what you hold rather than on what exploits exist.
## The asset and how it is spent An exploit for an unfixed flaw is expensive to obtain — months of research, or a purchase — and its value comes entirely from a condition outside the operator's control: **no fix exists yet**. The instant that condition ends, the asset is worth roughly nothing, because the same access can then be bought by anyone patient enough to wait for unpatched machines. That makes it a *wasting asset* with a peculiar property: the main thing that ends its life is **using it**. ## Why use destroys it To exploit a document renderer on someone's laptop, the operator has to deliver something to that laptop: a file, a page, a message. Delivery means a copy of the trigger leaves the operator's control and lands on a machine belonging to someone else. From there several ordinary things can happen — the recipient forwards the odd-looking file to a colleague, the target organisation asks the vendor about a crash, the file is kept and looked at later. Any one of them can end with the vendor understanding the defect. The consequence is global, not local. A fix is not issued only to the victim; it ships to everyone. One careless delivery against a low-value target can therefore cost the operator the access it was saving for the target that mattered — an operation that has not even started yet. This is the argument that makes the wasting-asset framing more than a metaphor: **the cost of a use is not the risk to that operation, it is the option value of every future operation the exploit would have enabled.** ## What that predicts about behaviour - **Narrow delivery.** One recipient, or a handful, chosen because they hold what the operation wants. Not a fleet. - **Gating.** The delivered content is arranged so the exploit only fires for the intended recipient — checks on who opened it, from where, in what configuration — and does nothing otherwise. Every non-target who receives it is pure downside. - **Cheap techniques everywhere else.** The same operator will happily use a stolen password or a convincing message against the rest of the estate, because those cost nothing to replace when they fail. The unfixed exploit is reserved for the doors those cheap methods cannot open. - **Reluctance under time pressure.** An operator with a deadline may burn an exploit it would otherwise hold; an operator with time will look for another route first. - **Asymmetry by actor class.** Holding one only makes sense for someone whose objectives are worth more than the asset. A crew monetising volume cannot recover the cost, which is why unfixed exploits are rare in commodity operations and more common where the objective is one specific organisation's information. ## Reading it from the target's side The useful inversion for a candidate is this: being told that an unfixed exploit exists for software you run does **not** predict that you will be hit with it. It predicts the opposite for almost everyone. The relevant question is not 'does this exploit exist' but 'am I the kind of recipient someone would spend it on' — which is a question about what you hold, not about your software inventory. And conversely, if you *are* that recipient, the narrowness works against you: the operator will have taken care that the thing only fires for you, so the population of people who could have noticed it first is deliberately tiny. ## The second-order effect Because use is what kills the asset, an operator's holdings decay whether or not they are used. Vendors rewrite the affected code for unrelated reasons; another researcher finds the same defect independently; a whole class of bug becomes harder to exploit as the platform changes. An exploit held for two years may simply stop working one Tuesday, with no one having attacked anything. That decay pressure cuts the other way from hoarding: hold too long and you get nothing for it. The result is a genuine timing decision — spend it on this objective, or wait for a better one and risk having nothing to spend. ## Common mistake The wrong answer is 'because they want to stay stealthy'. Stealth is part of it, but it is a consequence, not the driver, and it misses the global nature of the loss. The driver is that a single recovery anywhere ends the asset everywhere, so each use is priced against every future use it forecloses.
- Does holding an unfixed exploit get safer the longer you wait?No — holdings decay on their own. The vendor may rewrite the affected code for unrelated reasons, another researcher may report the same defect, or platform changes may break the technique. An exploit held for two years can simply stop working without anyone having used it, so hoarding trades the risk of burning it against the risk of never getting anything for it.
- Why are unfixed exploits rare in high-volume criminal operations?Because the economics do not close. The asset is expensive and single-life, while volume operations make money from many cheap attempts against whoever is reachable. Mass delivery is exactly the usage pattern that gets an exploit recovered fastest, so the cost could never be recovered. Those crews reach for flaws that already have fixes, where the targets are the machines still running the old version.
It is a single-use key that also re-keys every matching lock in the world the moment anyone notices it was used.
saying these in an interview costs you the question
- Says the only reason is stealth, missing the global loss
- Assumes an existing unfixed exploit means everyone gets hit
- Thinks the loss is limited to the target it was used against
- Treats holding one as free, ignoring independent decay
- Expects volume crews to be sitting on unfixed exploits