How else is the CEO supposed to respond? He's in the tough position where he can't prove a negative; the burden of proof is on the original tweeter. So the CEO needs the "hacker" to either prove it or admit they were mistaken, and bug bounties are exactly how companies do this. (Also, I feel like it's implied that "an account that isn't yours" doesn't mean "mess with any of our customers you want." He's clarifying th…
> you'd be shocked how many people try to claim bug bounties from us because they "hacked" their own account using their own credentials. Wait ...what? Like, seriously?
For example, they'll inspect traffic and nab a session cookie. Then they'll use that session cookie on another internal API request to change a setting, and claim they were able to modify a setting by reverse engineering things.
They seem really scary at first, and then you dig into it and you're like "oh...".