I'm curious, did you let them know that this vulnerability exists before you wrote an article and posted it to HN? If you let them know and they ignored you, then I understand that you'd want to write an article and spread it around. It's important that customers know when a company doesn't value their security. At that point, the proper way for them to handle it is to quietly fix it, and then let all their affected…
Never Give Your Information To 10 Minute Old Startups
31–40 of 185 posts
Re: Never Give Your Information To 10 Minute Old Startups
#32Re: Never Give Your Information To 10 Minute Old Startups
#33I'm curious, did you let them know that this vulnerability exists before you wrote an article and posted it to HN? If you let them know and they ignored you, then I understand that you'd want to write an article and spread it around. It's important that customers know when a company doesn't value their security. At that point, the proper way for them to handle it is to quietly fix it, and then let all their affected…
They already knew and it was fixed before I posted this.
Re: Never Give Your Information To 10 Minute Old Startups
#34To be fair, the guy who owns that site did mention that it wasn't meant to be picked up by HN and was still in the early stages of development.
I have mixed feeling about this. On one hand we all want to move quickly, get users, add new features, etc etc. On the other, security issues like this are just so vital that nothing else really matter if your data is not secure. It's especially true for a BACKUP SERVICE that promises ridiculous stuff like "99.999999999%" uptime on the frontpage.
honestly, this was all accidental. it was a pet project we started to toy with Glacier and a week later i accidentally hit the Like button sending a ping to my friends on FB. bless my friends for being so influential i guess. shame on us for using Rails carelessly.
if you have any experience with startups, you'll know that 99% of the things you launch go nowhere--this project was no different. we honestly thought our site was of absolutely no consequence. we're truly thankful so many people found it useful, but trust me we're sorry there was a hole.
however, just to be clear:
- about 20 accounts were exposed, including me and my buddy - i emailed all of them, and wiped out the credentials - they quickly responded (i saw the updates come in)
thankfully, AWS is designed for such situations. with a few clicks, people deactivated their credentials (both IAM and main account) and regenerated new credentials. the fact that all the early signups were techies who know their way around AWS really saved us.
one more thing: the correct quote is:
"Glacier is built for durability of 99.999999999%"
also: i agree with ryan--don't trust 10-minute old startups :-)
Re: Never Give Your Information To 10 Minute Old Startups
#35Mirror? I can't read download.gz files.
Re: Never Give Your Information To 10 Minute Old Startups
#36Re: Never Give Your Information To 10 Minute Old Startups
#37Re: Never Give Your Information To 10 Minute Old Startups
#38Many folks in the security community might suggest a) An oblique warning publicly like "There exists a security problem with this; I have mailed the devs" b) actually mailing the devs c) waiting for confirmation of fix or a reasonable time and only then d) tar-and-feather. The term-of-art for this is "responsible disclosure." This incentivizes people to fix things quickly and preserves the reputational value of break…
Re: Never Give Your Information To 10 Minute Old Startups
#39Earlier quoted context omitted.
They already knew and it was fixed before I posted this.
And did you let them know privately before you posted this comment? http://news.ycombinator.com/item?id=4619411
Re: Never Give Your Information To 10 Minute Old Startups
#40----
"if anyone's concerned about your AWS key, just destroy your IAM user and create a new one. that's what it was designed for."
----
In response to advice saying they should notify users by email:
"good idea. actually, we'll just wipe them and force new ones."
----
In response to RKearney warning people about just what exactly is exposed:
"in case you have issues with your AWS keys. RKearny's email: ryan@ryankearney.com https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb286....