Protip: academic board observed secret and so did vendors. The OpenBSD patch went unnoticed. It was the Infosec community that screwed up.https://twitter.com/marcan42/status/919972354947796993 …
You can add location information to your Tweets, such as your city or precise location, from the web and via third-party applications. You always have the option to delete your Tweet location history. Learn more
I'm assuming someone may already know of this bug and be actively exploiting it. This is exactly the kind of ubiquitous bug govts love.
So you must be angry at the silent “early” update not at the disclosure to an “academic review board”.
I'm annoyed that disclosure to an academic review board (with zero benefit to security and low but nonzero risk of leak)...
So, based on your unproven assumption, you are calling out as unethical a behavior that followed a standard coordinated disclosure behavior
On top of that, you are presuming to lecture who found the bug on what YOU think he should have done with HIS bug. Fascinating.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.