Nuclear Option
This is clearly grandstanding with a lesser motive of getting Apple to provide a fix.
They could clearly motivate Apple to fix this without sharing the "how" of the exploit with the public.
Step 1. Discover exploit
Step 2. Inform Apple
Step 3. Wait requisite time (30 days was pretty arbitrary. I've worked with companies that can barely scratch their backside in 30 days, let alone deploy a software patch for multiple versions of an O/S across multiple devices)
Now, you can
A. Jump to the nuclear option share the "how" of the exploit, allowing others to replicate this and cause issues/pain/hardship for others.
or
B. Oh, I don't know, simply release video demonstrating the hack in action (to convince viewers that the threat is real), but not actually provide the information to allow viewers to replicate it. Users would be in an uproar for a fix all the same.
To use someone else's analogy, it is one thing to know how to break into my neighbor's house. By me broadcasting that fact to my neighbors/public and proving that I can do it would be pretty motivating for the neighbor to better secure their home. It is a completely separate thing for me to instruct public on how to break into my neighbors home.
This is clearly grandstanding with a lesser motive of getting Apple to provide a fix.
They could clearly motivate Apple to fix this without sharing the "how" of the exploit with the public.
Step 1. Discover exploit
Step 2. Inform Apple
Step 3. Wait requisite time (30 days was pretty arbitrary. I've worked with companies that can barely scratch their backside in 30 days, let alone deploy a software patch for multiple versions of an O/S across multiple devices)
Now, you can
A. Jump to the nuclear option share the "how" of the exploit, allowing others to replicate this and cause issues/pain/hardship for others.
or
B. Oh, I don't know, simply release video demonstrating the hack in action (to convince viewers that the threat is real), but not actually provide the information to allow viewers to replicate it. Users would be in an uproar for a fix all the same.
To use someone else's analogy, it is one thing to know how to break into my neighbor's house. By me broadcasting that fact to my neighbors/public and proving that I can do it would be pretty motivating for the neighbor to better secure their home. It is a completely separate thing for me to instruct public on how to break into my neighbors home.