Sadly, Egor (who found this vulnerability) mentioned he's moving away from exclusively white-hat security since he "[tried to do] responsible disclosures but it gave me 0 profit. So now i will play with “gray” methods and see if it’s reasonable."
It's sad to see a researcher so talented and committed be pushed to the dark side simply because companies decide their bugs aren't "worth it"
Original post (now edited): http://egorhomakov.com/post/72088934127/year-2013