I was at a much smaller YC company when I found that AWS root credentials were checked into the repo, purely for S3 file uploads for logos. When other engineers and I brought it to the CEO (he required infrastructure stuff get brought up to him first), he handled it with zero urgency and didn't see why it was a big deal.
I explained to him how the EC2 instances would assume the role that already had the permission and it took so long to convince him.
Needless to say, we had to explain lots of basic security and networking concepts to him, which he wouldn't believe until given live demos of basic things like public versus private IP addresses in AWS.
So bad.
At these types of startups, developers will find themselves in some debate about the time complexity of a click handler (which is debounced anyway).
Meanwhile Joe CEO is like "HAY GUYS" -drops db-
"CAN U FIX IT BY MONDAY"