Hacker News new | ask | show | jobs
by lmm 3401 days ago
What's true is true - better to know it than stick our heads in the sand. If these boxes have vulnerabilities (who am I kidding, they do parsing, they're probably implemented in C "for performance", of course they have vulnerabilities), we are better off for knowing about them than not.
1 comments

But what of the equities issue - what to do with that knowledge, once discovered? Might it depend on who "we" are?

My point is that actually helping this particular vendor, for example, may not be everyone's cup of tea.

Yes, good point. One might aim to 'help' them into an early grave whilst actually helping them to strengthen their product.