That's quite possible. It's also quite possible that we still wouldn't have released it yet, as we'd be doing that work to make it generally usable this week. Therefore, the critical failure - that we weren't protecting the CRT values - might not have been known yet.
Sadly, the multiverse doesn't yet let me monitor its A/B tests.
We are, in fact, evaluating those other claims, and testing them in our labs. We are also evaluating claims made by other researchers, both publicly and privately; and we hope to end up with both a better library out of this, as well as a better understanding of the hazards we do and don't provide safeties against.
Validating his first claim was sufficient to undermine our belief in key safety; the others are therefore only relevant for protection against future attacks. In that light, it was important to advise our customers and the community at large.
Willem,
Thanks for the well-reasoned set of claims for us to evaluate. We are still looking at them, but a critical one is accurate: our own implementation of the secure memory area did not include the CRT values.
Sadly, the multiverse doesn't yet let me monitor its A/B tests.