A bug like heartbleed was not found because no got the idea of how to exploit it. Plenty of people and researches have read that code without seeing the bug. This case with VW, was to my knowledge not a bug, it was deliberately code to work that way. That is quite different from a subtle bug where you need to apply advanced statistical attacks to perform the exploit. Or a random generator bug that simply reduce the randomness.
I'm absolutely positive that there is some enthusiasts, that would read and dissect every single line. But even if that wasn't the case, I'm even more certain that multiple competitors would, and this would be reported as fast as you can set up a meeting with the relevant authority.
I'm absolutely positive that there is some enthusiasts, that would read and dissect every single line. But even if that wasn't the case, I'm even more certain that multiple competitors would, and this would be reported as fast as you can set up a meeting with the relevant authority.