Legal restrictions against reverse engineering devices make security researchers afraid of disclosing vulnerabilities. Everyone ends up worse off.

For a responsible disclosure program, researchers need:

- A point of contact,
- No legal consequences,
- Financial reward

Openness is important too, sharing discoveries after they've been fixed has value.

