That's an option, the NWS is the United States is good and I suspect other countries have similar organizations.
HN user
GuardLlama
Dark Sky had no issues charging a fair subscription fee for their app, and it got the acquired by Apple.
XMPP doesn't "work", but on the other hand, the alternatives probably worse:
1. Don't run your own server? A co-worker once operated a fairly popular "public" XMPP server with a decent number of typically active users, a couple hundred. Some eastern European "darkweb" drug sellers had an account on the server, so their competitors thought it worthwhile to threaten the XMPP operator with very directed violence. If you don't host your own, who is running your XMPP server? What will they do when the government/yourThreatActor threatens them?
2. If you do (or don't!) run your own server, how do the end users find a halfway decent application on their fancy iPhone 18 Pro++ that supports push notifications? Their Windows 10 desktop? Ubuntu Linux?
3. If you run your own server, what do you do in the unlikely event of spam?
4. Crypto? OTR sucks for multi-device, OMEMO isn't extensively supported.
XMPP obviously doesn't work, but I can't suggest anything that's better.
I wouldn't worry.
You just did exactly what you needed to do! Post to HN and hope the thread gets enough upvotes to reach the frontpage to find a human at Google.
Meta takeaway, probably:
A popular PetaPixel post that gets coverage on additional social platforms is your only form of recourse against Amazon.
The "Penetration Test" document is here:
https://files.catbox.moe/fxn9r2.pdf
Some comments:
The beginning of the document says "Inspecting the file and testing my findings with initial hand‑crafted POST requests, I discovered that this script allows clients to specify a custom filename which is susceptible to path traversal. To make matters worse, the script does not protect against overwriting existing files": Great, you have path traversal and upload on an old-school PHP platform. You've already won! Report it and move to a bug bounty that actually pays.
Next, "Using this vulnerability, I uploaded a custom .htaccess file (with Options +Indexes ) into the /media directory": This is going too far.
Next, "Further leveraging the insecure upload script, I managed to deploy a custom index.php into an exiting /media subfolder": This is going to far.
Next, "To expedite further testing, I uploaded a copy of the p0wny‑shell. (Note that I slightly modified the file to circumvent common anti‑malware signatures.)": This is going to far.
"Knowing SlickWraps' website was powered by Magento 1.8, I located and decrypted the local configuration file. In here, I found MySQL and Redis credentials, and thus had full access to their entire database... Investigating the complete 17 GB MySQL dump gave me access to the following": Ah, so you knowingly breached real customer data. I think even you know you've gone way too far by now.
I could continue to the next steps in the exploitation chain, but won't. Per their initial Medium writeup, they didn't report it to Slick Wraps until they had walked past a not-so-thin line half a dozen times and extracted the full database content.
This behavior isn't even remotely grey-hat.