Earlier quoted context omitted.
Every response to this I've seen from "the infosec community" (my connection to that community tends sharply towards vulnerability researchers, since that's my background) has been critical of this guy. I can't think of anyone I've seen cheerleading him. I've even seen rare glimmers of people criticizing EFF for trying to make a cause celebre of him. But you're taking things too far by casting aspersions on all of "s…
I've seen a lot of people cheering for him. I've seen the man in person at various cons, and I think he's brilliant. The problem is, what are we supposed to do? Responsible disclosure: companies don't give a shit and will hide it. Full disclosure: you get sued and thrown in jail. Stunt hacking disclosure: people get scared even though it's easy to do. People demand something be done about it. The person who did the d…
This is what I have concerns with. It's this "ends justify the means" argument that disregards some important consequences.
There are many ways to breach these topics. You can go to the FAA. You can go to the individual companies. You can post on mailing lists. Ultimately, it may be a grind. But going the press route with inflammatory statements has consequences that exceed your own experiences with law enforcement. The legislators want to regulate infosec. It won't be pretty when they do.
We need people to understand that a successful disclosure doesn't require headlines in arstechnica. You have to be empathetic to interactions with large organizations. Flashy press may get attention to your issue, but it can also have disastrous consequences for the rest of the community. Is it worth it?