Unfixable security vulnerabilities and when to STFU (Shut the Fuck Up).
Computer security has a notion of "responsible disclosure", which can be summarized as (1) If you find a security bug, you should tell the people who can fix it. (2) If they do not fix the bug in a timely fashion, you should alert the public to the danger, even if this also means alerting potential attackers. And this policy has mostly worked well, in my opinion! But this policy critically depends on security vulnerabilities being fixable. What if a security vulnerability can't be fixed?
In the physical world, there are often unfixable vulnerabilities. Some of these vulnerabilities can be mitigated, though doing so may be very expensive. Many of these vulnerabilities are known to specialists, or could be known if they looked in the right places. Sometimes these vulnerabilities are even documented in an obscure government report somewhere. But these vulnerabilities aren't common knowledge.
Normally, I would love to give you some concrete examples. I know of three physical vulnerabilities which are moderately horrifying. A friend of mine knows of another—I don't know the specific details, but I do know that some very nice national security people once encouraged him to never talk about it again. They had no legal basis for this request. And indeed I'm pretty sure plenty of specialists discovered it before my friend. But what he found definitely isn't common knowledge, and the government wants to keep it that way. My friend agreed that the government was being reasonable.
So instead I'm forced to give you some examples that did become public knowledge. These example were at least mitigatable, though we're all paying the price for those mitigations decades later. Specifically, airport security. Once upon a time, many people realized that it would be possible to smuggle explosives through security by hiding them in clothes. Eventually two murderous clowns figured this out, and we had the "Shoe Bo