Is it okay to disclose vulnerabilities found during unauthorised tests? If you find a hole, what are the risks of reporting it?