This is something I'm struggling with as I attempt to educate myself more about security. I was a bit disappointed he went on to talk about the risk of a stunt , because there is virtually no quantifications of risks in anything I've read on the results of security research. This seems to be borne out by the arguments about, say, the speed of disclosure vs patching. There is no agreement, and seemingly no desire to q…
Nearly all results of security research are given at least some metric for risk quantification. https://cve.mitre.org is a single example of an attempt to quantify risk. I'm assuming at least at some point you have run across these numbers so the statement is patently false or a complete exaggeration.