Earlier quoted context omitted.
While what you say is true, I feel strongly that it shouldn't be. It is morally right to show if a product that is used by many fellow students is marketed as "100% secure"* is in fact very vulnerable. If some less ethical hackers got a hold of that data, much worse things could have happened. * that's the biggest red flag. A company saying 100% obviously has very little actual security expertise. PS: I'm a big fan o…
Devil's advocate: I get into your home by bypassing (poor) security. I take pictures and make copies of anything inside. Then I publicly announce the breach and demand that you fix your security based on a deadline I made up. Then I say "trust me, bro" when I promise to never reveal the data I stole. Nobody would find any of that moral. The analogy breaks down because your home is not a place where sensitive data of…
I'd say you checking the front door to find it unlocked, then taking a few pictures for proof is perfectly moral. In this case, I think most people would agree it is a step too far to expect you to come to me first, rather than immediately announcing to the entire neighborhood that I'm being incredibly lazy and reckless with their valuables (on top of outright lying to all of them).