To me this raises a question about selling security vulnerabilities to state actors in general (in the context of the Facebook vulnerability thread where the standard discussion about value is being hashed out). Specifically, I live in the UK and one of the complaints law enforcement has is that US companies can (and do) totally ignore valid court orders because they don't apply in the US (reddit being an arbitrary c…
A US company (or individual) should absolutely ignore court orders from a non-US court; such courts have no jurisdiction. A "valid" court order necessarily must come from a court with jurisdiction.
Similarly, I'd expect a UK company to ignore US court orders.
(And in both cases, I'd ideally hope the court knows better than to take the case in the first place or to issue such an order.)