Anyone who hasn't should read Byron's latest blog entry. This, and the contrast with Jay's entry is the beauty of allowing people to share their opinions.
The fact is (even on a team of 20 people) we're divided on issues around worms, exploits, and responsible disclosure. And we exist as a microcosom of the security industry - this industry is incredibly divided over who is truly the evil in the industry.
And there are certainly people who agree with Byron - one need only read Slashdot to see that. There are many in our industry who believe that instant disclosure with live exploits is the only form of responsible disclosure, because it enforces corporate responsibility.
There are others who take the other side - that no exploits should ever be posted publicly. They believe that this is the reason that security holes are exploited. Many governments and law enforcement agencies take this position.
While I'm loathe to talk about my personal position, I will say that I don't agree with either exreme - I think that we need to find a way to walk the middle road.
However, the beauty of having a forum like this is that we can encourage the microcosm that we are to enable discussion in the real world. Because these discussions need to be had, and people need to come to real answers and realizations beyond their opinions.
That only happens if we have real discussions about it.