That's all perfectly reasonable, and I'm not without sympathy for StavrosK on this.
I'm also not sanguine about the idea of using a service which is meant to handle information of such gravity as this, and which has also had an extremely well understood, trivially fixed, and enormously compromising information disclosure vulnerability go unfixed for a year or more. The reason why that situation has obtained is not interesting to me; that that situation has obtained is enormously so.
This one I agree with. I wouldn't use the service personally until the issue is fixed. But it is so counterproductive to find a security problem the average user wouldn't notice, and then not tell the author about it.
I wouldn't use the service even afterward. The dev didn't think about CSRF for a year. What else didn't he think about?
Don't get me wrong - I think very highly of what 'StavrosK is trying to do here, and I agree that it's counterproductive not to report an issue once found in a case like this. (There's a certain degree of nuance made necessary by the fact that kill-the-messenger reflexes make vulnerability reporting so fraught in general. But that doesn't seem likely to obtain in this case, so I'd report, probably not even anonymously.) But at this point that trust just isn't coming back.
I'm also not sanguine about the idea of using a service which is meant to handle information of such gravity as this, and which has also had an extremely well understood, trivially fixed, and enormously compromising information disclosure vulnerability go unfixed for a year or more. The reason why that situation has obtained is not interesting to me; that that situation has obtained is enormously so.