Yahoo caused the damage the second they put it up for download and someone downloaded it, at that point the cat was out of the bag and the certificate compromised.
When dealing with certificate signing and compromised private certs "Maybe no one noticed" is not a good enough response.
(I am assuming he used various methods of contacting Yahoo directly as well as publicly calling them out of course.)
EDIT: Thinking about it he MIGHT have caused damage because maybe no one else may have noticed before yahoo got the cert revoked, but that chances that no one else (blackhats for example) noticing before the cert was revoked are very small in my opinion.
I agree with you. I think it's unethical not to publicly announce this one. I understand that some bugs may be best treated in private, but compromised certificates can cause real havoc.
Yahoo caused the damage the second they put it up for download and someone downloaded it, at that point the cat was out of the bag and the certificate compromised.
When dealing with certificate signing and compromised private certs "Maybe no one noticed" is not a good enough response.
(I am assuming he used various methods of contacting Yahoo directly as well as publicly calling them out of course.)
EDIT: Thinking about it he MIGHT have caused damage because maybe no one else may have noticed before yahoo got the cert revoked, but that chances that no one else (blackhats for example) noticing before the cert was revoked are very small in my opinion.