Dual-Use Technology and Engineering Ethics: When the Same Capability Serves Defense or Attack

The skill that finds a bug in order to fix it and the skill that finds a bug in order to exploit it are the same skill. If technology itself carries no moral valence, then what exactly does the branching?

What this article is: This is one essay and opinion about technology and ethics — not a statement of settled fact, nor a report of any industry or academic consensus. We have checked sources for the historical cases and public reporting cited here as carefully as we could, but the ethical interpretation drawn from them is the author's own position, and it is genuinely open to disagreement. It is written on the assumption that some readers will reach different conclusions. This article also contains no specific or technical information about weapons, attack techniques, or fabrication methods of any kind; it stays at the level of history and of publicly published strategic and ethical commentary.

Starting Close to Home

For a company that builds security products, this question is not an abstract thought experiment — it is the daily work. The skill of finding software vulnerabilities (reading binaries, doubting the boundaries of every input, producing and observing states the designer never anticipated) runs in exactly two directions. In one, the flaw you found is reported to the developer, gets fixed, and users all over the world are protected. In the other, the same flaw is kept quiet and turned into a tool for intrusion that destroys someone's assets or someone's life.

What matters here is that these two are not "similar" skills — they are literally the same skill. Almost nothing additional needs to be learned to redirect the capability acquired for the first toward the second. All that is required is a decision. As people who build vulnerability-scanning tools, we cannot look away from this fact. Network vulnerability scanning and YARA malware detection rules alike can only be designed by someone able to reproduce an attacker's thinking.

This property — the same capability serving both construction and destruction — is generally called dual use. This article is an attempt to think through that old and new problem again, using historical cases as evidence and two East Asian ethical traditions, Daoism and Confucianism, as lenses.

Dual Use Did Not Begin with Cyber

Treating the dual-use problem as a new headache specific to information technology misses the point. It is a structure embedded in technological civilization itself, repeating across precision machinery, chemistry, aviation, and the life sciences for at least as long as there have been industrial economies. Here are some cases that actually happened.

Machine Tools: The "Mother Machine" and Ultimate Generality

Machine tools are called mother machines because they are machines for making machines. Lathes, milling machines, and the multi-axis numerically controlled (NC/CNC) machines that cut precise three-dimensional geometry all produce automotive engine components, medical implants, and aircraft structural members. And the same machines can, in principle, produce weapon components. What gets cut is a question of the machining program and the purchase order, not a question of the machine.

The best-known case in which this property erupted into international politics is the Toshiba Machine / Kongsberg scandal of 1987. It came to light that year that Toshiba Machine (then a Toshiba subsidiary) and Norway's Kongsberg Vaapenfabrikk had, during the first half of the 1980s, illegally exported multi-axis CNC machine tools and their numerical control systems — items restricted under COCOM, the Coordinating Committee for Multilateral Export Controls — to the Soviet Union. According to reporting and U.S. government investigation, the equipment was used to machine submarine propellers to high precision and was assessed to have contributed to improvements in the quietness of Soviet submarines. The affair produced serious friction in U.S.–Japan relations, executives of Toshiba Machine were prosecuted, and sanctions were imposed on Kongsberg.

What the case demonstrates is the stubborn fact that "the machining precision that makes a propeller quiet" and "the machining precision that makes ship propellers in general" are technically indistinguishable. Export control has no choice but to draw its line on the machine's own specifications — number of simultaneously controlled axes, positioning accuracy, and so on. But the use that lies on the far side of that line is decided by whoever receives the machine.

Jet Engines: Thrust Has No Civil or Military Version

Gas turbine and jet propulsion technology works the same way. Single-crystal casting of turbine blades that must keep spinning under extreme heat and pressure, thermal barrier coatings, combustor design — these are core technologies underpinning the fuel efficiency and reliability of commercial airliners, and they are equally core technologies of propulsion for military aircraft and missiles. Historically, jet engines were brought into practical use largely under military imperatives and then transformed civil aviation. The flow runs both ways: materials and manufacturing techniques honed in commercial work flow toward military applications, and vice versa. Here too, the capability to generate thrust is itself neutral with respect to purpose.

3D Printing: Democratized Manufacturing and Its Reverse Face

Additive manufacturing may be the technology that has made this structure most dramatically visible. It compressed prototyping lead times from weeks to hours, made low-volume high-variety parts supply viable, and drastically lowered the threshold for individuals and small businesses to participate in manufacturing at all. These are unambiguous benefits.

At the same time, the other face of the same technology has been reported repeatedly. In 2013, the U.S. group Defense Distributed (Cody Wilson) announced and test-fired a handgun, the "Liberator," printed almost entirely in polymer, and published its design files. Reporting at the time recorded downloads on the order of a hundred thousand within days of release, before Wilson was ordered by the U.S. State Department to remove the files from his site. (This article records only the course of events; it addresses no information whatsoever about design or fabrication.) More recently, reporting on the war in Ukraine has described 3D printing being folded into supply chains for military components at considerable scale — drone frames and various housings produced across distributed small-scale "print farms," with volunteer networks handling parts supply. Accounts to this effect have appeared in a number of media outlets and trade publications.

What deserves attention here is not the vividness of any individual case, but the consistent trend that appears along the time axis.

Machine tools (20th century)Require a national industrial base and enormous capital. The objects of export control are relatively easy to identify, and regulation can (imperfectly) function
Jet engines (later 20th century onward)Still at the scale of giant corporate or national programs. But materials and manufacturing techniques increasingly flow in from the commercial side
3D printers (21st century)Priced within reach of individuals. Design data circulates freely across networks, and control at a physical border becomes extremely difficult
Vulnerability research and software (now)Capital requirement is essentially zero. All that is needed is knowledge and time, and the output propagates at zero cost of reproduction

The barrier to acquiring powerful capability has fallen consistently and continues to fall. Everything in the second half of this article rests on that one observation.

Daoism: Cook Ding's Blade, and a Warning Against the "Machine Heart"

East Asia has an unusually early body of thought about the relationship between technology and the human being. The Zhuangzi in particular places two views of technology side by side that can be read as opposites.

The first is the parable of Cook Ding carving the ox (庖丁解牛, páo dīng jiě niú), from the "Nurturing Life" chapter. The cook Ding butchers an ox with movements so fluid they resemble a dance, and when Lord Wenhui praises his skill, Ding replies to the effect that what he cares about is not skill itself but the Dao (the Way), which lies beyond skill. For the first three years, he says, he could see nothing but the whole ox; eventually he came to meet it with his spirit rather than his eyes, and because his blade travels through the gaps that already exist between joints, it has gone nineteen years without needing to be sharpened.

What the parable suggests is an understanding in which excellence in skill consists not in forcing oneself upon the material, but in reading the material's natural grain and moving along it. This is a deeply familiar sensation to engineers. When you read a well-designed system and put your hands into it along the grain of its structure rather than breaking it by brute force, the resistance disappears. That feeling.

The second is the parable of the machine heart (機心, jī xīn), from the "Heaven and Earth" chapter. Zigong suggests to an old gardener drawing water by hand that a device — the well-sweep (桔槹, a counterweighted lever) — would spare him the labor. The gardener responds, in substance: where there are machines, there are inevitably machine affairs; where there are machine affairs, there is inevitably a machine heart, a mind given over to calculation and contrivance. With a machine heart in one's breast, the pure and simple is spoiled, and the life of the spirit knows no rest. In the original, the line is 「有機械者必有機事、有機事者必有機心」 — a passage frequently cited in discussions of technology criticism.

Setting the two side by side, it becomes clear that the Zhuangzi neither simply affirms nor simply condemns technology. Cook Ding's blade achieves excellence by following the Dao; the well-sweep alters the human interior. What produces the difference is not the performance of the tool but which way the inner life of the person using it is facing. For the purposes of this article, that reads as a formulation of the dual-use problem stated more than two thousand years ago.

Confucianism: Cultivating the Person, Not Just the Skill

The Analects (論語, Lúnyǔ) addresses more directly the question of how to form a person who holds a skill. At its center are two concepts: ren (仁, variously rendered benevolence, humaneness, or human-heartedness) and junzi (君子, the exemplary person, often translated "gentleman" or "noble person").

Ren is often glossed as compassion, humaneness, or regard for others, but it is closer to a root disposition of character out of which the individual virtues appear than to any single virtue on its own. The junzi is a person who is working on themselves in the direction of ren. What matters is that the junzi is spoken of as a goal to be approached, not a social rank to be held.

From an engineering-ethics standpoint, one line is especially suggestive: 「君子不器」 (jūnzǐ bù qì, Analects 2.12), conventionally rendered "the exemplary person is not a vessel." A qi (器) — in the context of the period, a ritual vessel dedicated to one specific ceremonial use — has exactly one function. The passage is generally understood to mean that the junzi must not be that kind of single-purpose instrument. An engineer whose world closes at the boundary of their own specialty, who holds no axis on which to judge the consequences lying outside it, is precisely such a vessel — and the more sophisticated a single-purpose vessel they become, the more thoroughly they become something to be used by someone else.

The second is the passage in which Zilu asks about the junzi (Analects 14.42). Confucius answers first that the junzi cultivates himself with reverence; pressed further, he extends the answer to 「修己以安人」 (xiū jǐ yǐ ān rén) — cultivating oneself so as to bring peace and security to others — and then further still to 「修己以安百姓」, cultivating oneself so as to bring peace to all the common people, adding that even the sage-kings Yao and Shun would have found the last of these difficult. The structure being set out is that self-cultivation is not an end in itself; it acquires meaning only when it connects to making others secure.

What Confucianism is handling here is not a question about the performance of a technology. It is a question about training the subject who holds the skill. And that, this article suggests, may be the only variable in the dual-use problem that can seriously be moved at all.

A Western Parallel: Phronesis and DURC

The same intuition is present in the Western tradition. Aristotelian virtue ethics distinguishes the knowledge involved in making things (techne) from the knowledge of judging what is good in a particular situation (phronesis, practical wisdom). Possessing excellent craft and being able to judge correctly when and to what end to apply it are different capacities — and that distinction is, more or less exactly, the skeleton of the dual-use problem.

As a modern institution, the life-sciences framework of DURC (Dual Use Research of Concern) is worth referencing as an actual attempt to institutionalize this dilemma. In the U.S. government's definition, DURC is life sciences research that, based on current understanding, can reasonably be anticipated to provide knowledge, information, products, or technologies that could be directly misapplied to pose a significant threat with broad potential consequences to public health and safety, agricultural crops and other plants, animals, the environment, materiel, or national security. In May 2024 a new U.S. government policy was published covering oversight of both DURC and pathogens with enhanced pandemic potential (PEPP), with an effective date in May 2025 — and subsequent moves to revise it mean the framework remains in flux.

What makes the DURC framework interesting is that its design premise is not "prohibit dangerous research" but "preserve the benefits of such research while minimizing the risks" — a formulation that assumes both must be held at once. That is an honest acknowledgement of what the dual-use problem actually is, because it begins from the premise that the danger cannot be subtracted out on its own.

This Article's Position: Moral Valence Lives in the Orientation

With that material in hand, here is the position this article takes. It is one interpretation, not a demonstrated proposition.

Technology in itself carries no moral valence; the moral valence lives in the orientation of the one who wields it. More concretely, this article argues that what is decisive is which of two directions a person is facing.

The building orientationMaking things, enriching how people live, protecting people. Sustaining it as an enterprise, carrying forward employment and craft. Even defensive capability belongs here, when it is designed so that someone's life is protected
The taking orientationConquest, plunder, deception. Converting another party's assets, safety, or autonomy into one's own benefit without their consent. Independently of whether the means happen to be legal, some intentions face this way

Because the same capability serves both, no branch point can be built on the technology's side. You cannot implement a "does not cut weapon components" feature in a CNC machine, and you cannot excise "the part usable for attack" from the skill of vulnerability research. The decisive variable therefore shifts away from the nature of the technology and onto the ethical formation of the individuals and institutions that handle it. That, this article suggests, is the contemporary meaning of the Confucian insistence on "cultivating oneself" carrying the same weight as "honing one's skill."

It should be said that this position has counterarguments. The criticism that "technological neutrality is an ideology that lets designers off the hook" is a serious and recurring position in the philosophy of technology — the argument being that some technologies have particular patterns of use built into their very design. This article does not answer that criticism adequately. It is more accurate to read what is claimed here not as "technology is entirely neutral" but as the narrower claim that the more neutral a given domain of technology is, the more decisive human formation becomes.

Asymmetric Deterrence: This Section Is Speculation, Not Doctrine

About this section: What follows is the author's own organization of themes that are widely discussed in publicly available defense and security commentary and journalism — informed speculation. It is not an account of established military doctrine, and contains nothing about operations or employment. The figures cited are approximations that have appeared in public reporting, not independently verified numbers. Please read this as an observation about economic structure and ethics from someone who is not a military strategy specialist. It contains no information whatsoever about the construction, manufacture, or use of weapons.

Since 2022, the Russia–Ukraine war has pushed one theme to the front of public commentary on defense technology: the claim that cheap, new technology can impose an asymmetric cost exchange ratio on expensive, mature technological systems.

The approximation most often cited in public reporting and analysis runs roughly as follows: a small FPV drone manufactured for a few hundred to a thousand dollars can neutralize an armored vehicle worth millions. Analysis attributed to the Royal United Services Institute (RUSI) has been reported as finding that tactical drones account for a substantial share of damaged and destroyed equipment. The precision of such numbers is debatable, but the observation that the cost differential runs to one or two orders of magnitude has come from multiple independent commentators.

What makes the point interesting in strategic terms is that cost asymmetry can relatively devalue advantages that take a long time to build. Highly trained crews, expensive platforms requiring long procurement cycles, large conventional forces — these are assets that take decades to accumulate. Cheap mass-produced items, given an industrial base, can be stood up in a matter of months. Hence the argument that matchups which once had an obvious hierarchy may become more fluid.

Substantial caveats are required, however. First, the simple picture of "cheap beats expensive" frequently fails to hold on actual battlefields, where everything sits inside a continuous interaction with countermeasures — electronic warfare, protection, changes in how forces operate. Second, a favorable cost exchange ratio works equally well for the attacker and the defender. Asymmetry can function as an equalizer for the weaker party, and it can just as easily function as a mechanism that lowers the threshold for initiating attack; the second consequence is no less important than the first. Third, whether deterrence holds at all is not determined by the cost structure of technology, but by a far more complicated phenomenon including political will, alliances, and perception. This article does not assert that the argument is correct; it takes as its starting point only the fact that the argument is widely made.

And the implication this article wants to draw from it is not military. It is ethical. If the argument holds, it holds as a consequence of how dramatically the cost of reaching powerful capability has fallen. And that falling cost, as the table above sets out, sits on the continuation of a single line running from machine tools to 3D printers to software.

The lower the barrier to capability falls, the more decisive the ethical formation of the individuals and institutions who can reach it becomes. When the barrier was high, only large organizations could hold the capability, and organizations come with internal controls and accountability mechanisms — imperfect, but functioning to some degree. When the barrier disappears, that layer disappears with it. What remains is only what the individual people holding the capability choose.

Why Law and Export Control Alone Are Not Enough

One response at this point would be: then strengthen international law and export control. This article agrees that both are necessary. But it also holds that they are insufficient in principle, for a simple reason — the object of regulation cannot be defined.

Our own industry has experienced this difficulty firsthand. In 2013, the Wassenaar Arrangement (the multilateral framework for export controls on conventional arms and dual-use goods and technologies) added control entries covering "intrusion software" and IP network surveillance systems. The stated aim was to restrain the trade in commercial spyware sold to authoritarian states — an objective most people could support.

When the U.S. Bureau of Industry and Security (BIS) published a proposed rule implementing it in May 2015, however, the security industry pushed back hard. The proposal drew close to three hundred comments, many of them warning that legitimate vulnerability research, penetration testing, and incident response would be swept up along with everything else. The United States subsequently renegotiated the Wassenaar text across 2016 and 2017, and the controls were revised into a narrower form more permissive of legitimate research activity.

What that episode demonstrates is that any attempt to separate "attack technology" from "defensive research" in the words of a regulation will almost inevitably catch the latter. This is not a failure of competence on the regulators' part. It is that the things to be separated are technically identical. The same structure that appeared with the machine tools in the Toshiba Machine case is repeating here.

On top of that, general-purpose technology cannot be made un-invented. 3D printers, the methodology of vulnerability research, and small uncrewed aerial platforms are already distributed broadly across the world. Export control is a mechanism for governing transfers across a physical border, and knowledge and design data have no border. Institutions still matter greatly — but this article's view is that they are a boundary condition, not the solution. Whatever corresponds to the solution remains outside the institutions, on the human side.

And Then, Honesty

Finally, the point this article most wants to argue. Handling powerful dual-use technology must never, under any circumstances, be accompanied by deception or fraud. This is not a moral ornament; it is a functional requirement.

Here is the reasoning. A dual-use technology is, in itself, no more than "something dangerous if misused." Society has many ways of living alongside dangerous things — licensing, inspection, insurance, supervision, accident investigation. Every one of them rests on the premise that information about capability and intent is disclosed honestly. So long as what something can do, and who intends to use it for what, is broadly and accurately declared, society can design a response.

Deception destroys that premise itself. Misrepresenting intent, concealing the actual use, overstating or understating capability to regulators, customers, or the public — at that moment, a technology that was "dangerous if misused" becomes a threat that cannot be responded to. The magnitude of the danger has not changed; what has been taken away is society's capacity to react. It is telling that in the Toshiba Machine case, what drew condemnation was, quite as much as the performance of the machines themselves, the procedural deception of a falsified export license application. That the technology crossed a border mattered less than that it crossed under a disguise, which is what stripped the institutions of their ability to respond.

The line 「巧言令色、鮮矣仁」 (qiǎo yán lìng sè, xiǎn yǐ rén, Analects 1.3) is generally understood to mean that clever speech and a carefully composed expression seldom accompany genuine ren. Pulled toward engineering ethics, the reading would be that eloquence of explanation is not evidence of honesty. The ability to state precisely what a thing can and cannot do, and the ability to present it favorably, remain different abilities.

The security industry has an example of this principle crystallized into an actual institution: the practice of coordinated vulnerability disclosure. A researcher who finds a vulnerability notifies the developer privately first, allows a grace period for a fix, and publishes the details after the fix ships. This sequence is not a mechanism for concealing dangerous knowledge. It is the opposite — a procedure for disclosing dangerous knowledge honestly, in the right order. The researcher does not misrepresent what they found, the vendor does not deny that the flaw exists, and in the end users learn what it was that endangered them. People holding dual-use capability, by sharing a single commitment not to deceive, make it possible for society as a whole to respond. That is not abstract ethical theory; it is a mechanism that actually runs. It is not perfect, and it does get broken. Even so, it is surely one of the very few effective answers humanity has to the dual-use problem.

Honing the skill, and cultivating the self. Cook Ding's blade, and the warning against the machine heart. The claim that these two deserve equal weight has been made and remade for more than two thousand years. In an age when the barrier to capability is vanishing, it is not nostalgia — it is probably the most practical engineering requirement we have.

Summary

  • Vulnerability research is the purest instance of the dual-use problem: finding a flaw in order to fix it and finding one in order to intrude are literally the same skill
  • Real cases — machine tools (the Toshiba Machine/Kongsberg scandal, 1987), jet engines, 3D printing (the Liberator, 2013) — show that this structure is in no way specific to cyber
  • Placed in chronological order, those cases reveal a consistent trend: the barrier to acquiring powerful capability keeps falling
  • The Zhuangzi's parables of Cook Ding and of the machine heart suggest that what makes the difference is not the tool but the interior of the person using it
  • The Analects' ren, junzi, "the exemplary person is not a vessel," and "cultivate oneself so as to bring peace to others" propose training the subject who holds the skill, rather than the skill
  • This article's position is that moral valence lives in whether one faces the building orientation or the taking orientation (though this is one interpretation, and criticisms of technological neutrality carry real force)
  • The discussion of asymmetric deterrence is an organization of themes widely aired in public commentary — not established military doctrine and not settled fact
  • Export control is necessary but insufficient in principle: the 2015 turmoil over the Wassenaar intrusion-software controls demonstrated how hard it is to separate attack from defense in regulatory text
  • Deception is what converts a dual-use technology from "dangerous if misused" into a threat that cannot be answered; honest disclosure is what sustains society's capacity to react
  • Coordinated vulnerability disclosure is one of the few institutional examples of that principle actually working

See a Concrete Case of Dual-Use Technology

We've published a deep dive into VPNs and cryptocurrency — technology used for both privacy and crime.

Read VPNs, Anonymity & Cryptocurrency Crime