Re: Policy Change - in the Wrong Direction
Two quick observations on your points.
First, there is plenty of evidence - if not overwhelming evidence - that the US had cracked Japanese Navy ciphers and had decided the message that informed the fleet of Japan's intent to surrender *before* Enola Gay dropped "Little Boy" on Hiroshima, on August 6th, 1945. I don't think that undermines the spirit of your argument - that sometimes you need to "make a move" that also "makes a statement" .. but I don't think I can agree with anyone who says that it was right to "make a statement" that resulted in the deaths of between 80,000-140,000 people, most of whom were civilians.
Second, I may have failed to articulate my point clearly. In your reply you suggest that many vulnerabilities may be of the "use them or lose them" variety and this is why it made sense for the US to exploit those back doors before they were discovered and patched. I think there's something of an argument that we might be able to make in that regard... if the target had access to new technology and the budget to keep their tech and vulnerability patching up to date. But my point was much more "ATT&CK" than "CAPEC" - namely that the risk to the US was as much about "sources and methods" (Tactics and Techniques) as it was about specific vulnerabilities.
For example, think about SPECTRE and Meltdown, the two high-profile speculative execution vulnerabilities that were found in Intel chips a little while back. As soon as news of those flaws became public, other researchers found similar vulnerabilities in other silicon. It wasn't knowing that SPECTRE existed on Intel chips that was the big deal, it was knowing how it was found, what to look for, how to scan an environment to find similar examples and so on.
China, Russia and others are going to be able to "work backwards from the point of impact" and learn a great deal about US techniques. They may find forensic evidence left behind. They may find new ways to scan for the exploited vulnerabilities - once they know what they are and devise test to detect them for themselves.
But most importantly of all... the last thing you want to be doing with your cyber offense capability is a "shock and awe" campaign. Not when you don't know who else is watching or what they will see.