Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

91–100 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#91
This is Yet Another Reminder to use unique, unguessable, unmemorable passwords for all online services. It's a question of when, not if, any particular password database will be compromised. While 'password1' and 'this is my long unguessable password' and 'm4r1g0ld' and 'false lemur capacitor paperclip' will all eventually be guessed, 'sF0PSQMwK85fe9xanqJRm9nty9cJGHJsVmti' will never, ever be.

Re: Security Notification and Linode Manager Password Reset

#92
post #5

Sure wish they had sent out an email notification to users instead of a slashdotted blog post. Now the question is how long can Linode stand in the face of these sorts of hacks and network attacks in the face of stiff VPS competition.

(Linode Employee) Already got it covered, we are sending out an email to everyone in batches, but pushed out the blog first since it can be seen by everyone right away.

I'm still waiting for mine (6 hours since this was posted to HN).

Re: Security Notification and Linode Manager Password Reset

#93

Earlier quoted context omitted.

I think since multiple customers were hit by this and are presumably all putting pressure on them about it, their hand may have been forced.

Could be, but the timing still seems really weird to me. If they did an investigation like they said they did, I just don't see why you would come out with it right now. Because from Pager Duty post it seems that no one could do anything to make them disclose it sooner.

I can't speak for the other folks that were compromised this way, but we decided to just cut our losses and move on at PagerDuty and spent the 30 days after the compromise migrating everything that was running there over to Azure. No point in putting pressure on a company that stonewalls you.

Re: Security Notification and Linode Manager Password Reset

#94
post #80

Earlier quoted context omitted.

> We would've appealed but there was no point as the sentence was essentially nothing. But you do end up with a record, which is not 'essentially nothing'.

Since I'm not really planning to look for a job, my main worry was potential visa issues. But I haven't had any troubles visiting the few countries I do need a visa for.

How are you in a position where looking for a job in the future is not really necessary?

Re: Security Notification and Linode Manager Password Reset

#95
post #67

Earlier quoted context omitted.

MySQL server that allowed anonymous logins Has anyone got more information on this? Various Google searches keep pointing me at the other four hacks.

https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... They try to downplay it pretty hard.

Thanks for this link. Although it talks about:

    database accessed using old forum credentials
So I'm not sure "anonymous login" would be an entirely accurate description.

Re: Security Notification and Linode Manager Password Reset

#96
post #88

So, outside of the major cloud providers, what are the good alternatives?

VPS providers that are typically pitched as Linode Alternatives. Not 1:1 equivalents, but may work depending on your needs.

Vultr, Ramnode, Wable, iWStack

Or, depending on the number of VPS's you have, you might like:

- Aliyun, the cloud service from Alibaba

- A dedicated server from OVH, or their mid-tier brand, SoYouStart. This is my personal favorite. They have real DDOS protection, Data centers in North America and Europe, reasonable web interfaces, lots of available IPV4 space, and DIRT CHEAP prices. Run proxmox as the distro, and you get a decent interface to create and manage VPS instances.

The most important piece would be to try and split instances across at least two of these providers so that you have some fast recourse if something goes wrong. For the things I'm running, doing a nightly rsync of the data from one provider to another suffices as reasonable insurance.

Re: Security Notification and Linode Manager Password Reset

#97

Earlier quoted context omitted.

This only works if the input password has low entropy. You would think that people using Linode are savvy enough to be using long, randomly generated passwords.

> This only works if the input password has low entropy. If you're generating every single possible password up to e.g. 8 characters the password's quality doesn't matter, only the length does.

12 character random strings are an absolute minimum for a secure password, because brute forcing and tabling start to become impractical. Longer strings are even better.

I wouldn't consider an 8 char password secure, no matter what the entropy is.

Re: Security Notification and Linode Manager Password Reset

#98

Earlier quoted context omitted.

I think since multiple customers were hit by this and are presumably all putting pressure on them about it, their hand may have been forced.

Could be, but the timing still seems really weird to me. If they did an investigation like they said they did, I just don't see why you would come out with it right now. Because from Pager Duty post it seems that no one could do anything to make them disclose it sooner.

[deleted]

Re: Security Notification and Linode Manager Password Reset

#99

Earlier quoted context omitted.

Could be, but the timing still seems really weird to me. If they did an investigation like they said they did, I just don't see why you would come out with it right now. Because from Pager Duty post it seems that no one could do anything to make them disclose it sooner.

I can't speak for the other folks that were compromised this way, but we decided to just cut our losses and move on at PagerDuty and spent the 30 days after the compromise migrating everything that was running there over to Azure. No point in putting pressure on a company that stonewalls you.

That's a good point. Not worth your time for a company like Linode that doesn't really care about its customers. I think people mistake the quick support responses to basic questions as them caring, but when it really comes down to the important things like security and communication during a crisis, it's clear that there is a huge lapse from the leadership level down. Someone in this post wrote about how they stopped $10k worth of Linode service a month and no one tried to get them back or retain them. That was very odd to read, especially for a business of Linode's size ($22 million in revenue isn't that big where you can shrug off $120k/year.) Par for the course it seems, and everything is starting to make sense. Thanks for sharing your story and sorry that happened to your team.

Re: Security Notification and Linode Manager Password Reset

#100
post #80

Earlier quoted context omitted.

Since I'm not really planning to look for a job, my main worry was potential visa issues. But I haven't had any troubles visiting the few countries I do need a visa for.

How are you in a position where looking for a job in the future is not really necessary?

Bitcoin.
Post reply on HN