> If everyone sets a cooldown, there will be no early adopter. Everyone is waiting for everyone else to be the canary, and the canary does not exist. Except there are researchers chomping at the bit to download every new release of packages in search of vulnerabilities they can exchange for fiat, reputational credit, or both.
100% agree. I hated this post because it's all based on this unfounded assumption as an axiom, which it presents using zero evidence. Different groups have different risks tolerances, and it's absurd to think that nobody is going to pull releases before the default cool down period.
Why is that absurd? It seems like a more likely outcome than just assuming there are enough "security researchers" out there doing this for every package?! IMO both sides here seem to have no evidence that the other is wrong.