5 ms·
in case you have issues with your AWS keys. RKearny's email: ryan@ryankearney.com https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb2861503ab1?size=70&
by smeagol 14y ago
in case you have issues with your AWS keys. RKearny's email:
ryan@ryankearney.com
https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb2861503ab1?size=70&default=https://cdn.uservoice.com/images/admin/icons/user_70.png https://secure.gravatar.com/avatar/f7d7b021fb488fe6a67ddb286...
- RKearney 14y agoenginerd@wepay.com https://si0.twimg.com/profile_images/2550813276/qnltv3bylbd6lkhiz5gp.jpeg https://si0.twimg.com/profile_images/2550813276/qnltv3bylbd6... I can search for email addresses too! Don't direct users to me because you failed to secure your web application. It's nice to know someone who works at a company that handles credit card and bank payments would just post someones email address and photo. Granted this is all public since I posted on the Uservoice post, it was still unnecessary.
- smeagol 14y agoWePay is in no way related to IceBox. they're terrific guys; don't trash on their reputation. i left WePay ages ago. also, our info is publicly displayed here: http://www.iceboxpro.com/about/team http://www.iceboxpro.com/about/team we're not a company. we're two nerds.
- citricsquid 14y agothen you may wish to remove that email from your profile.
- jarek 14y ago> we're not a company. we're two nerds. Oh, so if you get sued for mishandling personal data or PII it'll be your personal responsibility rather than a company's?
- bdcravens 14y agoIf you were a company, you'd have insulation against lawsuits. Two nerds mean you and your family's assets are at risk; launching an app with such a spectacular security hole seriously puts the two of you and your families in danger.
- deleted 14y ago[deleted]
- movingahead 14y agoThe only thing you are right about is that WePay is terrific and I am glad you are not associated with them. How difficult it is to owe up to your mistakes instead of shooting the messenger?
- alinajaf 14y agoYou are clearly not very good at being nerds.
- Evbn 14y agoI think you misspelled www.iceboxamateur.com then?
- zunky 14y ago@smeagol. First of all you fucked up. So stop acting so high and mighty and apologize to rkearney and everyone else who even thought about signing up for your product. Secondly, if this was just meant for you and your friends, don't go public with it and post it on HN. I highly recommend another hobby in a different field because clearly this one doesn't agree with you. Lastly, please stop calling yourself a nerd.
- jspthrowaway 14y agoThat's your response to someone (admittedly, poorly) discovering and reporting a security vulnerability in your application? Telling him to "be nice" then dropping his e-mail and face as some kind of stick-waving, threatening gesture? Congratulations on demonstrating to me and countless others why I shouldn't use any product that you EVER touch. You don't get a pass because you're just two nerds. You have a form with a submit button -- that's where your responsibility as a founder and custodianship of user data begins. Day 1, you're already a liability. I realize this is a pretty direct attack but I'm appalled and staggered by your behavior in this thread. You launched a service on the public Internet. There is no grace period, there is no "friendly fire"; you fucked up and you disclosed AWS credentials. Not users' favorite colors. AWS KEYS. Tied to credit cards, running servers, S3 backups, God knows what. You don't get to tell people to be nice to you when you're acting as the steward of AWS credentials; you protect them and act like you care when someone tells you that you fucked up doing so. Your behavior here is just foreboding for the future, and you need to realize that before launching your next endeavor (this one is probably done, after that little mess).
- TallboyOne 14y agoYes. This the entire way. Fuck everything about this situation, christ. Thank god I didn't sign up.
- Dave9k 14y agoThis wasn't some exotic exploit either. Public, numbered (1,2,3...) accounts, all of them editable - it's almost funny. Can you imagine what other security problems exist in the code.
- JoeCortopassi 14y agoEDIT: Guys, don't downvote smeagle's comments. If anything, we should be upvoting them as much as possible so that others can see this blatant disregard for their users --------- You are quickly making the case for having one of the worst responses I've ever seen, to a huge security flaw. Trying to wipe things under the rug when your users information is clearly exposed is an easy way to destroy trust. I seriously can't fathom the ineptitude it takes to direct people to someones email like that over your glaring mistake.
- AVTizzle 14y agoClassless. Come on Khang - everyone here wants to root for their fellow entrepreneurs, creators, and (self-proclaimed) "nerds". RKearny pointed out a very real, very important issue that will help you make your service better, and help you deliver even more value for your users. And he did it for free! You should be thanking him and asking him for more feedback, not deflecting responsibility like this.
- smeagol 14y agoryan's info is public. he put it on our feedback forum. i wanted to make sure everyone was aware of his public info since we (as well as others) were very concerned with his course of action and questionable statement "Still managed to get a few dozen AWS keys though." i'm not sure why thanking him is in order... ? 5 people emailed me privately about the security issue. we fixed it promptly, and followed up with instructions to everyone exposed (~20) on how to protect their credentials. i haven't yet heard a complaint from our actual users.
- bdcravens 14y agoGreat example of why building an app != a startup. You should email all users, and post a public apology on your site or blog.
- deleted 14y ago[deleted]
- mittermayr 14y agoyou and i know that saying "~20" is a random number since you had nothing in place to track it. i'd love to hear how you know it's 20. seriously. tell us.
- aw3c2 14y agoCould be http server access logs but if I made glaring mistakes like that I surely would not trust my own server logs anymore.
- 14y ago
- jaxonrice 14y agoWould you mind posting a list of any other projects you guys have worked on or are currently working on so I know what to avoid like the plague?
- soAsian 14y agoThat's a dick move. You should own up to your mistake.
- Evbn 14y agoThe best part of this whole catastrophe is that this app isn't just embarrassing for smeagol, but it is playing out HN, YC's main advertising venue, and it undermines the whole concept of these MVP summer vacation startup companies, showing that 2 guys a garage can't launch a minimally provisioned website.