Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

81–90 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#82

I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…

I had almost exactly the same situation in 2013.

I honestly don't understand why anyone would be stupid enough to use Linode.

They continue to (a) have incidents and (b) fail to disclose them in a timely and transparent manner.

Re: Security Notification and Linode Manager Password Reset

#83
post #50

Why the hell have they not emailed their customers about this! This is not the kind of thing I want to learn from HN.

They're doing so as we speak. It takes a while to send 400,000 mails if you actually want them to be delivered to inboxes.

400k emails isn't that many though. :(

Re: Security Notification and Linode Manager Password Reset

#85
With Linode's extended DDoS I have not been able to get into the Manager for a couple weeks. I'd really like to cancel my account with them (and they do keep billing) but I don't appear to have any tools short of a chargeback. Anyone else in the same boat?

Re: Security Notification and Linode Manager Password Reset

#86

I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…

If the Linode Manager database only stores the hash, how would they know the password? How did you find out about the illicit login?

They don't need to know the password with db write access.

In fact, depending on how the sessions are managed the attacker might just need read access to log in without a password.

Post reply on HN