Security Notification and Linode Manager Password Reset
91–100 of 173 posts
Re: Security Notification and Linode Manager Password Reset
#92Sure wish they had sent out an email notification to users instead of a slashdotted blog post. Now the question is how long can Linode stand in the face of these sorts of hacks and network attacks in the face of stiff VPS competition.
(Linode Employee) Already got it covered, we are sending out an email to everyone in batches, but pushed out the blog first since it can be seen by everyone right away.
Re: Security Notification and Linode Manager Password Reset
#93Earlier quoted context omitted.
I think since multiple customers were hit by this and are presumably all putting pressure on them about it, their hand may have been forced.
Could be, but the timing still seems really weird to me. If they did an investigation like they said they did, I just don't see why you would come out with it right now. Because from Pager Duty post it seems that no one could do anything to make them disclose it sooner.
Re: Security Notification and Linode Manager Password Reset
#94Earlier quoted context omitted.
> We would've appealed but there was no point as the sentence was essentially nothing. But you do end up with a record, which is not 'essentially nothing'.
Since I'm not really planning to look for a job, my main worry was potential visa issues. But I haven't had any troubles visiting the few countries I do need a visa for.
Re: Security Notification and Linode Manager Password Reset
#95Earlier quoted context omitted.
MySQL server that allowed anonymous logins Has anyone got more information on this? Various Google searches keep pointing me at the other four hacks.
https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... They try to downplay it pretty hard.
database accessed using old forum credentials
So I'm not sure "anonymous login" would be an entirely accurate description.Re: Security Notification and Linode Manager Password Reset
#96So, outside of the major cloud providers, what are the good alternatives?
Vultr, Ramnode, Wable, iWStack
Or, depending on the number of VPS's you have, you might like:
- Aliyun, the cloud service from Alibaba
- A dedicated server from OVH, or their mid-tier brand, SoYouStart. This is my personal favorite. They have real DDOS protection, Data centers in North America and Europe, reasonable web interfaces, lots of available IPV4 space, and DIRT CHEAP prices. Run proxmox as the distro, and you get a decent interface to create and manage VPS instances.
The most important piece would be to try and split instances across at least two of these providers so that you have some fast recourse if something goes wrong. For the things I'm running, doing a nightly rsync of the data from one provider to another suffices as reasonable insurance.
Re: Security Notification and Linode Manager Password Reset
#97Earlier quoted context omitted.
This only works if the input password has low entropy. You would think that people using Linode are savvy enough to be using long, randomly generated passwords.
> This only works if the input password has low entropy. If you're generating every single possible password up to e.g. 8 characters the password's quality doesn't matter, only the length does.
I wouldn't consider an 8 char password secure, no matter what the entropy is.
Re: Security Notification and Linode Manager Password Reset
#98Earlier quoted context omitted.
I think since multiple customers were hit by this and are presumably all putting pressure on them about it, their hand may have been forced.
Could be, but the timing still seems really weird to me. If they did an investigation like they said they did, I just don't see why you would come out with it right now. Because from Pager Duty post it seems that no one could do anything to make them disclose it sooner.
Re: Security Notification and Linode Manager Password Reset
#99Earlier quoted context omitted.
Could be, but the timing still seems really weird to me. If they did an investigation like they said they did, I just don't see why you would come out with it right now. Because from Pager Duty post it seems that no one could do anything to make them disclose it sooner.
I can't speak for the other folks that were compromised this way, but we decided to just cut our losses and move on at PagerDuty and spent the 30 days after the compromise migrating everything that was running there over to Azure. No point in putting pressure on a company that stonewalls you.
Re: Security Notification and Linode Manager Password Reset
#100Earlier quoted context omitted.
Since I'm not really planning to look for a job, my main worry was potential visa issues. But I haven't had any troubles visiting the few countries I do need a visa for.
How are you in a position where looking for a job in the future is not really necessary?