He submitted this article after the vulnerability was already fixed. (I grant that the initial comment came before.) I'd be inclined to agree with you, overall, save for a couple mitigating factors in this case:
1) The founder's behavior in the other thread, including refusing to notify affected parties.
2) Such a simple mistake worries me about what else might be vulnerable in the application which is built to handle users' backup data, and for that reason alone, I think this article is extremely important right now.