Ryan McGeehan of our security team has posted an official response at the bottom of this page:
https://hackerone.com/reports/5200