> I decided to stick with my October deadline. [...] > I also decided (even before the bounty) that I am too scared to actually put out the live bug and since the fix was less than a month away, it was not really worth it anyway. I decided to wait for the fix. I have gone through similar trepidation. What were you scared of?
Security researchers (like the one here) don't want harm to come to people from their actions. If they announced the live bug before it was patched a lot of people and organizations might have been adversely by this before the fix was applied.
I should have asked "at what point did you decide that the wait outweighs the risk?"
That is, at what point wait becomes too long, and is worse?