The problem is that they are formulated in a way that it is super easy to have your software being possible "dual use" and that a judge has to decide if its fine or not. Making it worse it also states your "intention" which well is impossible to proof - if the judge says he doesn't believe your intentions are only good, you can literally get massively sued.
So ye i could move to another country and than publish it - apart from that i can let it rot on my hdd (which is prolly what will happen).
Edit: Additionally mentioned, it is not just the publishing in germany, even the facilitating already which is why i don't even have an article about it (any more).
But sure location itself also plays a role no question.
Also asked the lawyer in consulted about it... i would be a heavy gamble
I'm asking cuz I started devloping a c2+agent+BOF kind of thing with custom bytecode vm for the lulz (to learn how stuff works nowadays) and it's on tangled and github :/
In German: https://ht-strafrecht.de/blog/strafrecht/it-sicherheitslueck...
Yes, there was one German pentester that got sued, because he reported a BASE64 encoded, hardcoded authentication token in an application. Not that I would wish him anything like that and am ashamed by the outcome, I also recall that he might have tried to put pressure on the vendor by doing an interview with a blogger or so?
On the other hand, I do not know of any cases regarding publication of dual-use tools as OSS.