Perhaps these things (firmware, exploits) are more about scientific observation of experiments and less about reading documentation or literature to understand how to develop something. Commercial software development can be like that too. You may need to understand assembly code to figure out how library routines work (without access to the source). The documentation is usually incomplete or incorrect (as in "security by obscurity"). And people whose minds work in a particular way, who can back out what is going on from a set of empirical results, can get things done that others cannot.