Hacker News new | ask | show | jobs
by tptacek 3591 days ago
To your second question: because some projects are fundamentally irresponsible, and providing vulnerability reports to them means making an engineering contribution, which decreases the likelihood that the project will fail.