> We were surprised because he did not mention these actions in his previous correspondence with us.
Painting a picture/creating a narrative, poor us, we're surprised.
> it was reasonable to believe that Wes was operating on behalf of Synack
Filling in affiliations, or using a company address during parts of communication could very well have been out of detailing legitimacy as well as convenience. You can not, and should not infer a researcher operates on behalf of their company when reporting a bug, and as a CSO and someone who acts as a security researcher you KNOW that we always distance ourselves from our workplace when reporting or talking about security.
> Wes to set a precedent that anybody can exfiltrate unnecessary amounts of data
Logging in, grabbing keys but not touching user data is most certainly not breaking your ToS. Yet you paint it as unethical here. Where do you draw the line? Internal network names? Internal IP's, passwd files?
> one of my engineers involved in this issue once found a great (and in his case, original) RCE
Really, "and in his case, original"? Come on, act professional you're presenting one of the largest companies in the world.
> we have no evidence that Wes or anybody else accessed any user data
DING! DING! DING! Yet using terms like "intentional exfiltration of data" to draw grey areas that convenience you.
They've definitely screwed the pooch on this one.