Obviously I'm going to employ that very popular zoolander meme. Because i think InfoSec (not exempt unfortunately in its vulnerability to group think hypnosis) is becoming this meme.

Critically speaking:
The amazing culture that has taken over what seems to be a large section of the InfoSec community is to shame and lambast people who publicly report bugs. This is done with the notion that exposing potential attackers to knowledge of the bug somehow makes matters worse.  (If i understand it correctly)

Couple interesting questions:

Will lambasting and shaming cause more people to make us aware of the bugs?Does it really make things worse for users?How much worse is this worse for users? Can we argumentatively determine the weight of the worse-ness for users?Is it always always better to only report to the vendor?Is every bug when reported publicly immediately worse in effect before the vendor responds? Now that last question is the ringer for me. I'll start with this one: "…

