I've seen people publish exploits anonymously, and on the other hand I've read stories of people like Cody Brocious [1] or Alexey Borodin [2] publicly explaining their exploits. On the other hand Billy Hoffman [3] got a gag order when he tried to reveal his work. Does the type of exploit matter? Are there protections on hackers publishing research? Why is it that people aren't arrested en masse at Defon?
[1]: http://www.forbes.com/sites/andygreenberg/2012/07/23/hacker-will-expose-potential-security-flaw-in-more-than-four-million-hotel-room-keycard-locks/
[2]: http://www.forbes.com/sites/adriankingsleyhughes/2012/07/21/ios-in-app-purchase-hack-extended-to-include-mac-app-store-apps/
[3]: http://en.wikipedia.org/wiki/Billy_Hoffman