Comment by hinkley
1 month ago
No, because we've already had documented cases of people socially engineering exploits into OSS projects.
See also https://wikipedia.org/wiki/Confused_deputy_problem
You don't need permission to publish an exploit, you just need someone or something else to do it for you.
No comments yet
Contribute on Hacker News ↗