Since Oracle was so nice as to remind everyone what software security is really like with closed-source software, I wanted to remind people how finding and reporting security issues works in PostgreSQL: Feel free to "reverse engineer" the code. In fact, here it is on github if you want to scrutinize it. We generally credit security researchers who find real security holes (with limitations for du