A GREAT example of this was when Firesheep forced Facebook (and countless other sites) into embracing https. Firesheep was a firefox plugin that anyone could run on a public wifi (e.g. coffee shop) and instantly start getting the passwords of anyone on the same network that logged in to anything over http. At the time Facebook was http by default. So, it made the news and forced Facebook to make https required basically overnight. Many other companies followed suit, and it's likely fair to say that the release of that plugin single-handedly accelerated https adoption by a considerable margin.
I don't know that this release will be that impactful, but its certainly better than having this be a technique that only black hats know about.
It was released in 2019 and it is still going on, so unfortunately it wasn't.
From my perspective, I'm happy that Martin Vigo released this information (in 2019) as it helped me inform my employers (and now my clients) to additional threat model vectors to consider before deciding how to best perform password resets.
Also in his defense: 1) He originally released a rather crippled form of the PoC 2) It requires a Twilio account, which raises the barrier to entry and provides a data point for analysts were the tool to be used criminally.
That method leads to the worst evils in the world. Many have concluded, or used it to justify everything from, 'it's ok to take these poor people's land and give it to megacorp, because we'll get a factory' to 'it's ok to silence these journalists because it's for the public good' to 'it's ok to kill my enemies because I think they are bad' to 'it's ok to commit genocide against this group because the world will be better off without them'.
Who am I, or who are you, to decide what is good or bad, or how good or bad, or to weigh those things for others? Beyond our obvious cognitive limitations (as humans, we are too flawed cognitively and morally to make judgments for others) and lack of legitimacy (who elected us?), there is our obvious bias - 'good' is what is good from our perspective, based on our biases, subject to our ignorance of others.
That's why human rights exist: It's their right and you can't make that decision for them; it's up to the person involved. If you think their land, etc. is so important, then ask them - it's up to them whether they want to do it. They have property rights, speech rights, etc. and nobody can abridge them, and in the limited circumstances where they can be abridged, there is a whole infrastructure of legitimacy (democracy), protection from corruption (separation of powers, juries, etc.), process (law, due process).
>>> One way of assessing these decisions is answering the question "Is more harm done than good by releasing information this to the public?"
Obviously, it's not like anything can or should be done to change this, as it's mostly just human nature, and keeping the security industry capable of operating legally and in the open is paramount. But sometimes people just wanna brag. And they get big mad about it and sputter about how literally any possible end justifies literally any actual means if you point it out (see: the other person responding to the top level comment lol)
Meanwhile, I can almost certainly say that the number of ways to bury your head in the sand instead of simply facing an uncomfortable problem massively outweighs the good reasons for doing so anyway.
A person who is in need of money and lacking in empathy will not fail to use any technique available and it is thus good to know the defenses of that or at least be aware of it.
"Creepy" arguments (appeals to shame or disgust) are fallacies.
Security researcher types are well aware of the good-actor motivations behind white-hat-hackerdom. Is it wrong that I can buy a book on lockpicking? Would I be seen by some as a bad parent if I taught it to my kid when he expressed curiosity about it?
I mean creepy as in a violation of a right to privacy. I don't consent to you knowing my phone number or any PII I put into private websites.
It's a lot easier to get caught lockpicking and it has some legitimate uses. This is like more like an autopicking machine imo.