In the software security community, a debate rages around when and how to disclose vulnerabilities and bugs. One camp wants a fixed deadline in order to somewhat force software vendors to fix their bugs before word goes out to the public. Others want a slightly more secretive approach that will only disclose such issues if and only if a fix …