Earlier quoted context omitted.
We should understand that a startup doesn't have the resources of a fully fledged company. That said, Uber has literally billions in resources, they should have done better.
This is bullshit. If your organisation can't protect their customers data, it shouldn't exist. Enough of this "I need special treatment because I'm just two dropouts working from a Starbucks'.
Obviously, this doesn't mean one should disregard security concerns. It's important to engage in good practices, to cultivate a combination of paranoia and attention to detail, to scrutinize suspicious behavior. But even if you do all of these things, modern computer systems have tons of surface area outside of your control. These days, it's unrealistic to demand perfect security from anyone, let alone small businesses.
Instead of being so uncompromising, I think it's better to ask businesses to explain their security policies and practices. Are administrators required to use multi-factor auth? Are backups encrypted, and if so, how? How are passwords hashed? Is data encrypted in transmission, and if so, how? Are server logs shipped to prevent tampering? Answering these questions (and others like them) can give security-conscious customers an idea of the business's expertise, and allow people to use products (or not) accordingly.
1. http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...