Yes, that approach is the wrong approach. "Responsible Disclosure" works both ways. The company with the software gets the vulnerability before the public, but they have to not try to sue/prosecute the security researcher. If companies are known to attack security researchers like you mention, then they can forget about responsible disclosure. Those companies will find out about vulnerabilities in the newspapers. Can't have your cake and eat it.
Comments
Yes, that approach is the wrong approach. "Responsible Disclosure" works both ways. The company with the software gets the vulnerability before the public, but they have to not try to sue/prosecute the security researcher. If companies are known to attack security researchers like you mention, then they can forget about responsible disclosure. Those companies will find out about vulnerabilities in the newspapers. Can't have your cake and eat it.