Big companies need to get serious about security. If a few (likely) college students can break your website it's not nearly good enough.
What LS are doing is wrong, but they're making a good point. Better them than real criminals who go undetected and don't announce leaks. And the publicity of it all should cause these companies to act much more than just mailing them the vulnerability and a description.







