You say that because you are not on the other end of this and don't suffer any of the consequences as a result of the actions of people who create some of these things which make it for sure easier for more people to exploit systems.
Please don't take this as an attack but your perspective is based upon your job [1] and your apparent lack of exposure to how people have to scramble and are actually impacted by certain types of disclosures. I mean the end users of the technology. Who in no way are in a position to get the vendors to do anything or make things more secure, in general.
This is for sure different from vendors and developers needing to write secure code and not make mistakes.
So have a bit of empathy. Not appropriate to call parent commenter, imo, a "jerk".
[1] "I'm a hacker in the computer science department at the University of California"
I think that things like metasploit and heartleech are an almost purely unalloyed good. In my experience, the "bad guys" already have easy-to-use tools. What publicly available tools do is give defenders access to these techniques, which they can use to demonstrate that problems really are a Big Deal. There is a certain kind of person (who seem to gravitate towards management) that cannot be convinced to take an issue seriously unless they can see the impact with their own eyes. A tool that prints out the private key of their production server is worth a dozen blog posts and security advisories as far as convincing them the danger is real.
Getting a private key using the extent simple scrypts is quite complicated, with lots of difficult steps. This is no barrier to teenage kids, who has lots of time on their hands that can play around until they get things right.
As a defender, however, you don't have that much time. For you, it's really easy. If you have a server, and want to know if the private key is visible, just download the Windows heartleech binary from github, run it against a server, walk away for 10 hours, and then come back to see if it's gotten the key.
In short, as you say, a tool that effortlessly prints the private key of a production server is worth a bazillion blogposts and security advisories. Code or GTFO, IMO :)
For a huge majority of folks, some unfortunately in the position of making decisions and policy surrounding security, the attack just isn't real until there's a nicely usable and widely available tool.
That all aside, the job of the security community is not to make your life or my life easier. And neither you or the person I was replying to gets to be angry at someone for exposing a problem because it inconveniences you or your colleagues.
The only thing that will do you any good is to fix your shit.
Pretending that it is someone else's fault that you have to scramble to fix your shit is not okay. I think my comment was phrased bluntly, but was both truthful and appropriate. I understand the emotions that cause it, but no one who blames others for their own problems has much high ground to stand on when it comes to empathy.
Writing offensive security tools is bound to get the attention of the vendors, to cause a storm that will get attention from the vendors.
What you're advocating amounts to shooting the messenger. How dare some person write software that disrupts your falsely ingrained peace of mind.
The fact of the matter is, vendors have been notorious throughout the ages for not listening to the security community. So many easily preventable mistakes have led to so many breaches.
Well, it's time to get people to listen. What better way to do that then demonstrate, first-hand, the gravity of their errors?