6 ms·
sorry about that. like i said before, we accidentally "launched" today. be nice? if anyone's concerned about your AWS key, just destroy your IAM user and cre
by smeagol 14y ago
sorry about that. like i said before, we accidentally "launched" today. be nice?
if anyone's concerned about your AWS key, just destroy your IAM user and create a new one. that's what it was designed for.
- dfc 14y agoYou should think about sending an email to all of your users. I realize its a tough call pointing out a problem so early but it might also be a good way to garner user's trust.
- smeagol 14y agogood idea. actually, we'll just wipe them and force new ones.
- zacharyvoase 14y agoBut you still should let your users know that their old keys have been compromised.
- adgar2 14y agoDude... this guy clearly doesn't understand security. I'm glad you're trying to help him out... but your time will be better spent elsewhere.
- interg12 14y agoWell that's not a very helpful attitude. People should be instructive rather than discourage someone from pursuing a reasonable project.
- adgar2 14y agoIt's not helpful, it's realistic. My exact wording was "your time will be better spent elsewhere." We each have 24 hours in a day. I spend 8-9 of mine sleeping, 9-10 at work. That doesn't leave much leftover for me. If zacharyvoase wants to spend his precious free time educating people who haven't done any due diligence to learn how to build a secure web app, that's his prerogative. But I don't see it as a good use of his time - there's already tons of resources out there that will do a better job than zachary. Is HN supposed to be a newbie education destination?
- jspthrowaway 14y ago"Whoops, we disclosed everybody's AWS credentials. I know! Rather than tell our users, I'll wipe the database and remove all evidence of it ever happening."
- ainsleyb 14y agoLegally you must disclose any sort of security breach to your users: http://en.wikipedia.org/wiki/Security_breach_notification_laws http://en.wikipedia.org/wiki/Security_breach_notification_la...
- RKearney 14y agoMany of these keys aren't IAM keys, or they were made with full access to the users AWS account.
- Zombieball 14y agoLuckily you can rotate keys even for the root level accounts.
- smeagol 14y agoin case you have issues with your AWS keys. RKearny's email: ryan@ryankearney.com https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb2861503ab1?size=70&default=https://cdn.uservoice.com/images/admin/icons/user_70.png https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb286...
- RKearney 14y agoenginerd@wepay.com https://si0.twimg.com/profile_images/2550813276/qnltv3bylbd6lkhiz5gp.jpeg https://si0.twimg.com/profile_images/2550813276/qnltv3bylbd6... I can search for email addresses too! Don't direct users to me because you failed to secure your web application. It's nice to know someone who works at a company that handles credit card and bank payments would just post someones email address and photo. Granted this is all public since I posted on the Uservoice post, it was still unnecessary.
- smeagol 14y agoWePay is in no way related to IceBox. they're terrific guys; don't trash on their reputation. i left WePay ages ago. also, our info is publicly displayed here: http://www.iceboxpro.com/about/team http://www.iceboxpro.com/about/team we're not a company. we're two nerds.
- citricsquid 14y agothen you may wish to remove that email from your profile.
- jarek 14y ago> we're not a company. we're two nerds. Oh, so if you get sued for mishandling personal data or PII it'll be your personal responsibility rather than a company's?
- bdcravens 14y agoIf you were a company, you'd have insulation against lawsuits. Two nerds mean you and your family's assets are at risk; launching an app with such a spectacular security hole seriously puts the two of you and your families in danger.