Hacker News new | ask | show | jobs
by tsimionescu 635 days ago
I don't agree with your alternate metaphor. In your example, publicly pointing out the leaking pipe can't cause any damage to the existing clients. In this case, publicly pointing out an exploitable vulnerability that gives access to personal information does bring extra harm to the customers.

If you want, a more apt comparison might be going around a business park and sticking big signs on every unlocked archive door you find. The companies not properly locking the doors are at fault, and customer data may already have leaked; but, you are virtually guaranteeing that even more customer data will leak by doing this. It should absolutely be illegal.