If it is about a few highly specialized firms finding the vulns we should let them do it before publication and we do not need cooldowns.
If it is not about that and we still subscribe to Linus's law then cooldowns will just postpone the problem.
If it is not about that and we still subscribe to Linus's law then cooldowns will just postpone the problem.
If we believe the point made above that the many eyeballs are not that important then releasing before we have done everything to make the software as secure as possible is irresponsible.