Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

101–110 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#101
post #67

Earlier quoted context omitted.

https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... They try to downplay it pretty hard.

Thanks for this link. Although it talks about: database accessed using old forum credentials So I'm not sure "anonymous login" would be an entirely accurate description.

The server would in fact accept any credentials as it had been started with --skip-grant-tables. Tested it myself.

Re: Security Notification and Linode Manager Password Reset

#102
post #79
post #73

Earlier quoted context omitted.

V interesting. Do any of the other VPS providers strike you as more secure alternatives?

I'd avoid VPS providers in general, but AWS is on a whole different level than linode. They actually understand what they're doing well enough to do live xen patching etc. But yeah, people get hacked through their hosts all the time. Best approach is colo with minimum access for the dc staff.

That's been my recommend for a long time. Plus, I liked obfuscating with unusual CPU choices and network guards (esp for protocol layers). Worked wonders with about no effort outside setting up guards. Opponents throw so much x86 shellcode at your Alpha, etc boxes while never quite getting stuff to run.

Re: Security Notification and Linode Manager Password Reset

#103

With Linode's extended DDoS I have not been able to get into the Manager for a couple weeks. I'd really like to cancel my account with them (and they do keep billing) but I don't appear to have any tools short of a chargeback. Anyone else in the same boat?

You don't mention contacting support. Shouldn't that be your second avenue after trying to access the account dashboard?

Re: Security Notification and Linode Manager Password Reset

#104
post #67

Earlier quoted context omitted.

https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... They try to downplay it pretty hard.

Thanks for this link. Although it talks about: database accessed using old forum credentials So I'm not sure "anonymous login" would be an entirely accurate description.

[deleted]

Re: Security Notification and Linode Manager Password Reset

#105

Earlier quoted context omitted.

This only works if the input password has low entropy. You would think that people using Linode are savvy enough to be using long, randomly generated passwords.

> This only works if the input password has low entropy. If you're generating every single possible password up to e.g. 8 characters the password's quality doesn't matter, only the length does.

Yes length matters. That's why pretty much all "randomly generated" passwords are long. Mine are 20 characters.

Re: Security Notification and Linode Manager Password Reset

#107
post #29

Earlier quoted context omitted.

At this point I'm starting to wonder whether this isn't a competitor putting their investors money to work. It's otherwise utterly bizzare that someone would be so obsessive in damaging Linode. I really hope they make the details of the investigation public...

It makes more sense than you might imagine... Linode, Github, Stackoverflow, Imgur, they've all been targeted. But what do they have in common? In a word: popularity. The core reason these sites are targeted is because it is impressive to others. The source of this is typically two fold: - For the lolz. Someone with a botnet just wants to show off, taking down something known gives them more notoriety. - For a sales…

Github was also targeted by China to try to get them to delete certain repos that were unfriendly to China. Some people also saw it as showing off their power.

Re: Security Notification and Linode Manager Password Reset

#108

I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…

Saw your tweet (https://twitter.com/theckman/status/684484772316360705) that linked to this post. Did a quick search to get your technical background and your LinkedIn profile states you used to work for Linode? I think it's important to share that info when you're telling your side of the incident. Your past relationship, if you left on bad terms, could play a role in your motivation to post.

Re: Security Notification and Linode Manager Password Reset

#109
Not to throw fuel on the fire but grumbling ex-employees aren't surprised. I've heard a few stories about not investing in infrastructure or even bug fixes. "They wont even look at bug fixes with major support costs." I know it's hard to triage what to do when running a company but when employees are proud of their product a breach like this isn't surprising.

Re: Security Notification and Linode Manager Password Reset

#110

With Linode's extended DDoS I have not been able to get into the Manager for a couple weeks. I'd really like to cancel my account with them (and they do keep billing) but I don't appear to have any tools short of a chargeback. Anyone else in the same boat?

Why not call them on the phone? They have a toll-free number for support.
Post reply on HN