Earlier quoted context omitted.
Some of the comments by DO on that GitHub thread, are really surprising, and disappointing to say the least...
I wrote those comments, fog wasn't using the API as he would have liked, and then this guy starts a bunch of trouble on HN stating that there was a vun on DigitalOcean, and conflated someone using the API incorrectly with us having a security vun. Two things I was trying to (admittedly not very well) say was: if DO did have a security issue, posting it on HN ("DigitalOcean leaks customer data between VMs" huh?) inste…
There is precisely zero circumstance where it is ok to give private customer data to another customer.
The fact that you think it had anything to do with an API or how it is used is all anyone needs to know about it.
The idea that warning your customers of your vulnerabilities is "irresponsible" is only true if you care more about revenues than your customers' security.