He said that some users might leave as a form of virtue signaling, not that all who leave will be virtue signaling.
Have there been cases of community notes being ineffective or wrong? I assume that community notes probably have some kind of system that can be abused, but I haven’t seen it happen.
That password reset looked to be like step four of something. So it’s a business logic bypass. Still awful of course but slightly more understandable given other ways this vulnerability could have been introduced. The cool part was detecting all the steps completely blackbox because everything was in the Javascript.
There is no excuse for issuing a valid token before mfa succeeds though. That is negligent.