Earlier quoted context omitted.
It's tough. I'm our public security reporting email list. We get a lot of things that boil down to "When I go to your website, I am able to see the content of your html files!" ... yes, reporter. That is what a web server does. It gives you HTML files. Congrats that you have figure out the dev console on your browser, but you're not a hacker. I'm trying to go with Hanlon's razor here and assume this is inexperienced…
> Sometimes having a place for responsible disclosure just opens yourself up to doing more paperwork 100% this. And it bites harder when you’re a scrappy time constrained startup, or just offering a public service. I maintain a public API that returns public information- observable facts about the world. As such, the API doesn’t have any authn/z. Anyone can use it as little or as much as they want, free of charge. Of…
It's possible "security isn't a concern" because they are dismissing the report, not the security.