> I wish I enjoyed the luxury of having defects detected in the field for free by testers willing to push the boundaries of a programmer's efforts to improve the source
There's a difference between detecting a bug and telling the programmer so they can fix it and detecting a bug and exploiting it and letting the programmer find out on his/her own that there's a bug when they realize their code has already been exploited.