> "However, I’ve decided to publicly disclose this one because I think it’s not necessarily more secure to have vulnerable code running on servers for a month of more while attackers, if any (for this vulnerability), are not bound to release cycles and have the advantage of time."
So he's publicly disclosing this even though it's not patched in the latest version, and he only notified the OpenSSL team less than a week ago? That's irresponsible! There's room to debate how long you have to wait before disclosing an unpatched vulnerability to the public, but I think we should all agree it's longer than that.