Not really a fair representation of what happened to call that "blocking journalists". They basically blocked the IP that was brute-forcing them, which every normal security team would do. That real point of critique is that it took them a few hours to do so instead of doing that in an automated way after some number of guessing attempts.
I would believe that if they unblocked the IP address once they found out the "attack" was done by journalists.
Unless these endpoints are under constant attacks and can't figure out which IP addresses belonged to the journalists, but then they shouldn't trivialise the impact of this thread in their response.
Comments
Not really a fair representation of what happened to call that "blocking journalists". They basically blocked the IP that was brute-forcing them, which every normal security team would do. That real point of critique is that it took them a few hours to do so instead of doing that in an automated way after some number of guessing attempts.
I would believe that if they unblocked the IP address once they found out the "attack" was done by journalists.
Unless these endpoints are under constant attacks and can't figure out which IP addresses belonged to the journalists, but then they shouldn't trivialise the impact of this thread in their response.