Comment Re:This is not how ethical people do security (Score 3, Informative) 141
Nope. "Security through obscurity" is when your initial system design fails to use good security practices, and you rely on "but nobody knows the protocol" or "nobody knows the port" or "nobody knows the password" as your design-level security implementation.
In this case, an unintentional security bug was discovered after release. It is still responsible to issue a patch, but it is also responsible to keep the details a secret to protect users until they can get the patch.
D-Link is refusing to issue a patch. I don't know all the details why so I can't judge. If the hardware was a recent purchase I would be pretty frustrated by that. But even still, keeping the details a secret just gives me more time to get the hardware replaced, so it is still the ethical response.