That's a fine security page (except that it needs to be clear that you're holding on to gmail passwords). But, please remember: if you don't have a security response page, which tells people how to contact you if they find a horrible security problem in your application, they are within our cultural norms to write a very unpleasant blog post about you.
Comments
That's a fine security page (except that it needs to be clear that you're holding on to gmail passwords). But, please remember: if you don't have a security response page, which tells people how to contact you if they find a horrible security problem in your application, they are within our cultural norms to write a very unpleasant blog post about you.
good feedback, we will take care of this.
This was the beginning of a similar episode with 37signals (of which tptacek was a vocal contributor): http://news.ycombinator.com/item?id=803899