There's been controversy over revelations of security flaws in software products. Some believe all should be public. Others claim nothing should be revealed. On this issue, taking a middle course seems best and is gaining support. Going for maximum publicity has merits. Those that want to disclose the exact techniques used to exploit security weaknesses cite vendor intransigence. When secrecy prevails, it is all too easy for vendors to describe loopholes as "theoretical" and do nothing. And publicity is hugely attractive to people who want to make a name for themselves in the security sector. Scare stories get coverage.