I'm all for encouraging "responsible disclosure", as long as the fixes are timely. It's when someone "responsibly discloses" a bug to the manufacturer, and half a year later it's still not fixed, and so the guy goes public, causing hysteria, and the manufacturer snipes back in a public response, crying about his lack of "responsible disclosure". You lose the right to cry Use Public Disclosure when you drag your feet on it.

When someone fixes things quickly in response, that's how things should work.


I work for the Department of Redundancy Department