Earlier quoted context omitted.
https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... They try to downplay it pretty hard.
Thanks for this link. Although it talks about: database accessed using old forum credentials So I'm not sure "anonymous login" would be an entirely accurate description.
Security Notification and Linode Manager Password Reset
101–110 of 173 posts
Re: Security Notification and Linode Manager Password Reset
#102Earlier quoted context omitted.
V interesting. Do any of the other VPS providers strike you as more secure alternatives?
I'd avoid VPS providers in general, but AWS is on a whole different level than linode. They actually understand what they're doing well enough to do live xen patching etc. But yeah, people get hacked through their hosts all the time. Best approach is colo with minimum access for the dc staff.
Re: Security Notification and Linode Manager Password Reset
#103With Linode's extended DDoS I have not been able to get into the Manager for a couple weeks. I'd really like to cancel my account with them (and they do keep billing) but I don't appear to have any tools short of a chargeback. Anyone else in the same boat?
Re: Security Notification and Linode Manager Password Reset
#104Earlier quoted context omitted.
https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... They try to downplay it pretty hard.
Thanks for this link. Although it talks about: database accessed using old forum credentials So I'm not sure "anonymous login" would be an entirely accurate description.
Re: Security Notification and Linode Manager Password Reset
#105Earlier quoted context omitted.
This only works if the input password has low entropy. You would think that people using Linode are savvy enough to be using long, randomly generated passwords.
> This only works if the input password has low entropy. If you're generating every single possible password up to e.g. 8 characters the password's quality doesn't matter, only the length does.
Re: Security Notification and Linode Manager Password Reset
#106Re: Security Notification and Linode Manager Password Reset
#107Earlier quoted context omitted.
At this point I'm starting to wonder whether this isn't a competitor putting their investors money to work. It's otherwise utterly bizzare that someone would be so obsessive in damaging Linode. I really hope they make the details of the investigation public...
It makes more sense than you might imagine... Linode, Github, Stackoverflow, Imgur, they've all been targeted. But what do they have in common? In a word: popularity. The core reason these sites are targeted is because it is impressive to others. The source of this is typically two fold: - For the lolz. Someone with a botnet just wants to show off, taking down something known gives them more notoriety. - For a sales…
Re: Security Notification and Linode Manager Password Reset
#108I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…
Re: Security Notification and Linode Manager Password Reset
#109Re: Security Notification and Linode Manager Password Reset
#110With Linode's extended DDoS I have not been able to get into the Manager for a couple weeks. I'd really like to cancel my account with them (and they do keep billing) but I don't appear to have any tools short of a chargeback. Anyone else in the same boat?