Maybe if there was a service promised but not rendered, could you place full blame on the developer(s).
On one hand we all want to move quickly, get users, add new features, etc etc.
On the other, security issues like this are just so vital that nothing else really matter if your data is not secure. It's especially true for a BACKUP SERVICE that promises ridiculous stuff like "99.999999999%" uptime on the frontpage.
honestly, this was all accidental. it was a pet project we started to toy with Glacier and a week later i accidentally hit the Like button sending a ping to my friends on FB. bless my friends for being so influential i guess. shame on us for using Rails carelessly.
if you have any experience with startups, you'll know that 99% of the things you launch go nowhere--this project was no different. we honestly thought our site was of absolutely no consequence. we're truly thankful so many people found it useful, but trust me we're sorry there was a hole.
however, just to be clear:
- about 20 accounts were exposed, including me and my buddy - i emailed all of them, and wiped out the credentials - they quickly responded (i saw the updates come in)
thankfully, AWS is designed for such situations. with a few clicks, people deactivated their credentials (both IAM and main account) and regenerated new credentials. the fact that all the early signups were techies who know their way around AWS really saved us.
one more thing: the correct quote is:
"Glacier is built for durability of 99.999999999%"
also: i agree with ryan--don't trust 10-minute old startups :-)
You have a long way to go in my mind, in terms of fixing the initial response. You probably have help now, which is great, but your initial kneejerk demonstrates underlying trouble to me which you need to fix.
You're in a tough spot, too, because you can't delete those godawful comments without looking suspicious.
I'd like you to apologize not only for the disclosure, but also to the reporter for how you treated him in the other thread. The entire other thread of your responses is disgusting, and you don't get to write it off because of your gender, quantity, or employment status. Own your comments and stop excusing them with that bullshit line.
I have to admit that I would also be pleased if your service disappeared until you're working with somebody who has a little more experience with secure Web applications; this mistake betrays your experience. Since we all started somewhere, though, I can only hope you fix this on your own.
Also, can you explain what "Glacier is built for durability of 99.999999999%" actually means, if not uptime?
If I got my math right, this means that they expect to lose on average about 10 bytes per stored terabyte per year. (Of course these losses, should they occur, would probably be not uniformely distributed).
"Pushing it to a public server" is really minor. Mozilla had this issue, too, when they had a new filename technically available on a server and someone jumped the gun and told the whole world that the new version was ready. Well, it wasn't. A bunch of kids whined that it was all Mozilla's fault for having a file available on their public server, but while it's arguable that a service that is reachable by URL has no expectation of privacy, it's a hell of a lot harder to argue that having a service reachable by URL implies a warranty that it is safe to use.
Friends in the 90's would run telnet and web servers with "Username:" "Password:" "Credit Card Number:" prompts. It was funny to watch that some people would type in apparently real data, although we never verified.