It used to be for all, but I agree, only the hack author, co-authors, and obviously staff, can see the list...
This could also be useful, because even if users do not reply, or accept hack updates via email, you could still contact them via PM or another method or alert a staff member that "User x" has a serious vulnerability with their site (after checking it out), and you could get the hole patched
Satan