I run a gaming site, pretty much overrun by stupidity. The other admin is a bit more laid back, but tihngs tend to get out of control quite quickly unless we put our foot (feet?) down. Of course it depends on the community.
Considering this is a business site, and not really a public discussion board, they have a public image to maintain. Having hacks here with security holes could hurt thousands of customers, so they treat it with the highest priority to 1) remove the hack, and 2) notify the customers at risk. 3) is a lower priority, and that's notifying the creator of the hack for it to be dealt with.
Sure it may hurt the creators reputation, but in all honesty that is the least of their worries. It's not like their own stuff hasn't had security holes - it's the fact that they are dealt with and fixed ASAP that is important.
edit,
Oops I said I would stay out of this one. Too late >.<
|