That can't possibly be an argument for forbearing security vulnerabilities in software. It's an argument for prioritizing hypothetical flaws over real ones.
If these flaws are so important, users of open source (business or individual) need to pay up - literally. Pay the maintainers enough to justify spending the time on these things, including the opportunity cost of not working at other software jobs during that time.
Pay each maintainer an absolute minimum of $200K a year or shut up and do the work yourself - in a fork if necessary.
If these flaws are so important, users of open source (business or individual) need to pay up - literally. Pay the maintainers enough to justify spending the time on these things, including the opportunity cost of not working at other software jobs during that time.
Pay each maintainer an absolute minimum of $200K a year or shut up and do the work yourself - in a fork if necessary.