ahh well thats the age old argument about security by obscurity vs full (and timely) disclosure expecially now that the security organisations in general are more mature and have their own agendas (eg information only for those that pay yadda ya) basicly leaving the rest of us in the dark.
Quote:To summarize my opinion, I feel that security information must simply be
made available to as many people as possible as quickly as possible, and
let corporations, systems staff, and security professionals handle the
problems. "The public has a right to know.." and any comparisons to
dislosing national security technology to the full disclosure of software and
network security problems should be totally ignored as they simply don't
apply.
(taken from
http://www.deaddrop.org/LenRose.html)