Hacker News new | ask | show | jobs
by thegeekbin 1911 days ago
In my opinion, the right decision is to release your research and have the vulnerabilities patched. I'm not a fan of the argument "only we know the bug" "it's for counterterrorism, seriously"... because I'm doubtful. If you found the bug, odds are someone else given the effort could.

Secondly, I think it's fair to say governments absolutely abuse any vulnerability they can at any point in time.