I agree that he could have handled it better and just said "Thank you for notifying me of the problem. I have devised a fix and will implement it as soon as I fly home and can access the SMB code base." However, he did say that he was aware of the problem and that it wasn't a significant problem to him because he had the database backups. Facepunch took this as 'Oh he doesn't care' instead of 'He is aware of the issue and has backups to restore it if someone does mess with it.' - Since the data can be recovered, it's not the end all if someone gets in right this minute.
He knew the issue was there, and he didn't blow off attempts to notify. He didn't have his code with him and couldn't release a patch, and it was right around a holiday. What is he supposed to do, drop his entire life, fly home, fix the code on a holiday and release a patch and then fly back out? The issue had been there for months, another 3 or 4 days wouldn't have hurt.
Wasn't the conversation on Twitter public? That makes those days much more important since the public knew about the flaw.