The nature of open-source distributed systems leaves some vulnerabilities open to exploitation, but should bugs be exploited publicly or disclosed in private?