> Finally, for those of you who do security research: when you find a security or privacy issue, please consider notifying the maintainer/vendor before publishing your findings
How to report a bug or vulnerability
... we (currently) have no bug bounty program ... send an email to [email protected]
https://mullvad.net/en/help/how-report-bug-or-vulnerability / https://archive.vn/BeHhrNot having a bug bounty or dedicated email address does not make it OK to go public immediately
Are you seriously suggesting people shouldn't operate with a bit of common decency unless they're going to get some money out of it?