Hacker News new | ask | show | jobs
by staticassertion 2130 days ago
The problem is that you hurt a lot of users a long the way in extreme cases.
1 comments

It's not you that hurt the users, it's the company for not being able to competently route, schedule, and fix their issue.

The reporter is only to blame if they actively exploit the vulnerability in order to harm users, not if they publish it publicly, with or without advanced notice to the company.

Or the bug fix can be hard to implement, test, and release in 3 months. I’m not saying it’s the majority of bugs but these could qualify