If companies keep treating white hats this way then I’m afraid they’ll basically be forcing a lot of them into the dark side
> found preauth RCEs in popular framework
> company be like: "send as an email, do not use github security"
> reported via email, including details and weaponized exploits
> ... not even an ack in 9 days ...
> open a generic issue on github to ask wtf
> "Please do not discuss security stuff here. You will receive a response in due time."