Live data from Hacker News

Never Give Your Information To 10 Minute Old Startups

blog.ryankearney.com

31–40 of 185 posts

Re: Never Give Your Information To 10 Minute Old Startups

#31

I'm curious, did you let them know that this vulnerability exists before you wrote an article and posted it to HN? If you let them know and they ignored you, then I understand that you'd want to write an article and spread it around. It's important that customers know when a company doesn't value their security. At that point, the proper way for them to handle it is to quietly fix it, and then let all their affected…

They already knew and it was fixed before I posted this.

Re: Never Give Your Information To 10 Minute Old Startups

#33

I'm curious, did you let them know that this vulnerability exists before you wrote an article and posted it to HN? If you let them know and they ignored you, then I understand that you'd want to write an article and spread it around. It's important that customers know when a company doesn't value their security. At that point, the proper way for them to handle it is to quietly fix it, and then let all their affected…

They already knew and it was fixed before I posted this.

And did you let them know privately before you posted this comment? http://news.ycombinator.com/item?id=4619411

Re: Never Give Your Information To 10 Minute Old Startups

#34
post #7

To be fair, the guy who owns that site did mention that it wasn't meant to be picked up by HN and was still in the early stages of development.

I have mixed feeling about this. On one hand we all want to move quickly, get users, add new features, etc etc. On the other, security issues like this are just so vital that nothing else really matter if your data is not secure. It's especially true for a BACKUP SERVICE that promises ridiculous stuff like "99.999999999%" uptime on the frontpage.

we're incredibly sorry about all of this.

honestly, this was all accidental. it was a pet project we started to toy with Glacier and a week later i accidentally hit the Like button sending a ping to my friends on FB. bless my friends for being so influential i guess. shame on us for using Rails carelessly.

if you have any experience with startups, you'll know that 99% of the things you launch go nowhere--this project was no different. we honestly thought our site was of absolutely no consequence. we're truly thankful so many people found it useful, but trust me we're sorry there was a hole.

however, just to be clear:

- about 20 accounts were exposed, including me and my buddy - i emailed all of them, and wiped out the credentials - they quickly responded (i saw the updates come in)

thankfully, AWS is designed for such situations. with a few clicks, people deactivated their credentials (both IAM and main account) and regenerated new credentials. the fact that all the early signups were techies who know their way around AWS really saved us.

one more thing: the correct quote is:

"Glacier is built for durability of 99.999999999%"

also: i agree with ryan--don't trust 10-minute old startups :-)

Re: Never Give Your Information To 10 Minute Old Startups

#38
post #27

Many folks in the security community might suggest a) An oblique warning publicly like "There exists a security problem with this; I have mailed the devs" b) actually mailing the devs c) waiting for confirmation of fix or a reasonable time and only then d) tar-and-feather. The term-of-art for this is "responsible disclosure." This incentivizes people to fix things quickly and preserves the reputational value of break…

[deleted]

Re: Never Give Your Information To 10 Minute Old Startups

#39

Earlier quoted context omitted.

They already knew and it was fixed before I posted this.

And did you let them know privately before you posted this comment? http://news.ycombinator.com/item?id=4619411

Details of the vulnerability were not posted until it was patched, which was no more than 60 seconds after that initial post.

Re: Never Give Your Information To 10 Minute Old Startups

#40
Everyone here that is thinking of giving this company the benefit of the doubt needs to go read their (smeagle) responses to RKearney from the original thread. Here are some samples of the careless attitude behind this:

----

"if anyone's concerned about your AWS key, just destroy your IAM user and create a new one. that's what it was designed for."

----

In response to advice saying they should notify users by email:

"good idea. actually, we'll just wipe them and force new ones."

----

In response to RKearney warning people about just what exactly is exposed:

"in case you have issues with your AWS keys. RKearny's email: ryan@ryankearney.com https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb286....

Post reply on HN