Earlier quoted context omitted.
For what it's worth, Steve Thomas's vulnerability was not the most important in that code. I think Steve Thomas (fair warning: a friend) might dispute the "full disclosure" comment you made, as well.
Thomas, aren't you trying to make security-related products and infosec in general too "reputation-based"? Do you really think that some bad code or design or lack of theoretical background during early career should be an "out-of-profession" sentence for lifetime? Hadn't you ever made such mistakes yourself?
Good for his consulting rate, no doubt, but probably not good for society.