Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I was disturbed by that statement as well. It's pure PR spin based on turning a blind eye.

They could detect mass malicious activity if a single IP was resetting thousands of accounts. But I'm skeptical they even checked based on the horrible initial flaw and specious response.



saying they are working on the disclosure system is good especially because it seems unprompted.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: