From what you've said it seems like the difference is more an issue of framing. You're focused on the effects for the end user, which are the same no matter what in my opinion and I agree on that. At the same time, if you're publishing exploits that are cutting edge and primarily only apply to the competition then, because you (in this hypothetical) are a company, the overall effects of the research are self serving. Why not publish more vulnerabilities that apply to your own systems otherwise? Surely you (again, the hypothetical you) are in a better position than other entities to engage in introspective research that benefits the end user. Obviously there's a possibility that the explanation is "Because the competition has more flaws than our/my own product" but without evidence such is the case then there isn't a lot of reason for outside critics to give the benefit of the doubt. Also, I'm not a security researcher so I realize some of my points might not be accurate to the state of the industry. I'm moreso trying to highlight the lines of thinking that lead to criticism of P0 and why I don't think they're easy to refute without a certain degree of burden on Google's/Totallyrelatedbutnot-google's part.