Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

41–50 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#41
post #29
post #23

Looks like the reason their blog is down is because... it's now being targeted by a DoS: http://status.linode.com/incidents/kldhjpjnfnkj Attacking a blog talking about the hack? It sure seems that someone has a grudge against Linode. :-/

At this point I'm starting to wonder whether this isn't a competitor putting their investors money to work. It's otherwise utterly bizzare that someone would be so obsessive in damaging Linode. I really hope they make the details of the investigation public...

It makes more sense than you might imagine...

Linode, Github, Stackoverflow, Imgur, they've all been targeted. But what do they have in common? In a word: popularity. The core reason these sites are targeted is because it is impressive to others.

The source of this is typically two fold:

- For the lolz. Someone with a botnet just wants to show off, taking down something known gives them more notoriety.

- For a sales pitch. Someone has botnet capacity that they want to sell, and "I took down Linode" is a great way of demoing that to potential buyers.

The first one is more common when someone finds a new method of traffic multiplication and just wants to show it off (i.e. they trick a third party into DoS/DDoSing a target). The second one is legitimate criminal enterprises.

Re: Security Notification and Linode Manager Password Reset

#42
I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here.

Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to gain root access. We were alerted to this activity and fully revoked the attacker's access within 60 minutes of the first node being compromised. Working with Linode support, we discovered which user account was being used and completely deactivated the user. We also isolated the VMs, and performed forensics on read-only copies of their disk images.

In our situation the attacker knew one of our user's passwords and MFA secret. This allowed them to provide valid authentication credentials for an account in the Linode Manager. It's worth noting that all of our active user accounts had two-factor authentication enabled. An interesting data point was that the user who had their account compromised was no longer in possession of the MFA secret themselves. Their cell phone had been reset (thus deleting all data) 8 months prior. The user could not log in to the Linode Manager if they wanted, so it was our determination that the key could not have been obtained from the user and was more likely on Linode's side.

We also have evidence from access logs provided by Linode that the attackers tried to authenticate as an ex-employee, whose username ONLY existed in the Linode database. It was absolutely unique and was not used elsewhere by the employee making the username an accidental honeypot. This was another piece of data supporting that Linode was the source of our compromise.

We immediately reached out to them not only to inform them of their compromise, but to assist them in investigating it. We were confident that the Linode database had been breached, and that the secret key used to encrypt information in the database had been compromised as well.

In addition to reaching out to Linode, we also worked with a third-party security firm to audit our work done during the incident. Likewise, around the same time we reached out to law enforcement to assist in investigating the attack. I believe our public disclosure includes this information[1]. This was in the middle of July 2015.

We did not get confirmation in July that there was a breach of the Linode Manager or any associated credentials.

In the end, we migrated away from Linode because of this breach (even before it was publicly disclosed) in Aug 2015. We also never were able to confidently disclose that Linode was the vector due to lack of confirmation from their end. While all of us who responded to the incident were confident they were the source, we now thankfully have the data to confirm it.

[1] https://www.pagerduty.com/blog/july-2015-security-announceme...

Re: Security Notification and Linode Manager Password Reset

#43
post #40

I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…

Interestingly, while I know for a fact that you're correct. When someone asked about this on #linode the ops immediate reaction was to deny it (as it was every other time they got hacked). alexf: any legitimacy to this https://news.ycombinator.com/item?id=10845619 ? naqod: again I'm not in ops so I don't have the deets, but my gut reaction is to say No effing Way You'd imagine that by now they wouldn't be so quick to…

As a former Linode employee, I find all of your comments very interesting. But if it's true that you're being prosecuted, why are you incriminating yourself here?

Re: Security Notification and Linode Manager Password Reset

#44

I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…

This was my post from SomethingAwful, it was copied/pasted here. No idea who copied/pasted it.

Rather than writing up a huge reply with more info, I'll link to another reply with more details on this same thread since someone else already did the writing: https://news.ycombinator.com/item?id=10845985

Re: Security Notification and Linode Manager Password Reset

#46
post #43
post #40

Earlier quoted context omitted.

Interestingly, while I know for a fact that you're correct. When someone asked about this on #linode the ops immediate reaction was to deny it (as it was every other time they got hacked). alexf: any legitimacy to this https://news.ycombinator.com/item?id=10845619 ? naqod: again I'm not in ops so I don't have the deets, but my gut reaction is to say No effing Way You'd imagine that by now they wouldn't be so quick to…

As a former Linode employee, I find all of your comments very interesting. But if it's true that you're being prosecuted, why are you incriminating yourself here?

All of the people involved have been very open about their identities and what they've been up to. It's sort of their MO. Pure speculation on my part, but I imagine it's basically a giant middle finger to everyone else.

Re: Security Notification and Linode Manager Password Reset

#47
post #43
post #40

Earlier quoted context omitted.

Interestingly, while I know for a fact that you're correct. When someone asked about this on #linode the ops immediate reaction was to deny it (as it was every other time they got hacked). alexf: any legitimacy to this https://news.ycombinator.com/item?id=10845619 ? naqod: again I'm not in ops so I don't have the deets, but my gut reaction is to say No effing Way You'd imagine that by now they wouldn't be so quick to…

As a former Linode employee, I find all of your comments very interesting. But if it's true that you're being prosecuted, why are you incriminating yourself here?

Double jeopardy, I was previously convicted of 50700 counts of unauthorized access to various coldfusion sites. Among those was linode.

Re: Security Notification and Linode Manager Password Reset

#48
post #47
post #43

Earlier quoted context omitted.

As a former Linode employee, I find all of your comments very interesting. But if it's true that you're being prosecuted, why are you incriminating yourself here?

Double jeopardy, I was previously convicted of 50700 counts of unauthorized access to various coldfusion sites. Among those was linode.

This one?

http://www.upi.com/Top_News/World-News/2015/07/08/Finnish-te...

Re: Security Notification and Linode Manager Password Reset

#49
post #47

Earlier quoted context omitted.

Double jeopardy, I was previously convicted of 50700 counts of unauthorized access to various coldfusion sites. Among those was linode.

This one? http://www.upi.com/Top_News/World-News/2015/07/08/Finnish-te...

Yeah.
Post reply on HN