We tackle a hotly contested debate as old as cybersecurity itself: does releasing exploit code do more harm than good?