from Daniel J. Bernstein:

Somewhat harder exploits => less frequent news about exploits => less panic => less funding for _real_ solutions. Not clear this is a win.


from Dino A. Dai Zovi:

I absolutely love fun bugs intellectually, but I also rationally know what will be more effective for defense than indulging my obsession.

from Justin Schuh:

This is the intellectual balancing act of defense. The key requisite skills also tend to pull you in less immediately useful directions.

from Tavis Ormandy:

If we ignore exploitation, then 0day would still be dime a dozen like they were in 1995. Today they're expensive, and getting more expensve.

from Tavis Ormandy:

Today 0day are out of the reach of many unsavory people, that's a huge win.