How does a 3rd-party researcher find the next heartbleed if they can't even decrypt the binaries for analysis?
As someone who has done quite a bit of reverse engineering work, I have no idea how I'd identify and isolate a vulnerability found by fuzzing without the ability to even look at the machine code.