Which is kind of hilarious.
Security Notification and Linode Manager Password Reset
111–120 of 173 posts
Re: Security Notification and Linode Manager Password Reset
#112I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…
Saw your tweet ( https://twitter.com/theckman/status/684484772316360705 ) that linked to this post. Did a quick search to get your technical background and your LinkedIn profile states you used to work for Linode? I think it's important to share that info when you're telling your side of the incident. Your past relationship, if you left on bad terms, could play a role in your motivation to post.
I worked at Linode for just under three years, and worked on quite a few different things there. I started on support and moved on to a development role (including writing ColdFusion). I left Linode on good terms. California is much more enticing than NJ, so I wanted to relocate. Plus I was interested in doing more of an Ops role, instead of working including customer-facing web applications. I'm still enjoying it. :)
I think there are lessons that can be learned whenever a company has some sort of security incident. This is especially true if they are willing to publicly disclose details of the incident. We've wanted to provide what limited information we had, but wanted to wait until we had confirmation that Linode was the vector.
While there is some relief in finally determining what we believe to be the vector of our attack, it's very unfortunate that Linode engineers are dealing with the fallout right now.
Re: Security Notification and Linode Manager Password Reset
#113Wow, these guys can't get a break.
Its part of why they hired someone in July to rebuild it in python.
Re: Security Notification and Linode Manager Password Reset
#114Why the hell have they not emailed their customers about this! This is not the kind of thing I want to learn from HN.
Concerning since I had to reset my password and regen my 2fa using only my old password...
Re: Security Notification and Linode Manager Password Reset
#115With Linode's extended DDoS I have not been able to get into the Manager for a couple weeks. I'd really like to cancel my account with them (and they do keep billing) but I don't appear to have any tools short of a chargeback. Anyone else in the same boat?
You don't mention contacting support. Shouldn't that be your second avenue after trying to access the account dashboard?
Re: Security Notification and Linode Manager Password Reset
#116Earlier quoted context omitted.
I can't speak for the other folks that were compromised this way, but we decided to just cut our losses and move on at PagerDuty and spent the 30 days after the compromise migrating everything that was running there over to Azure. No point in putting pressure on a company that stonewalls you.
That's a good point. Not worth your time for a company like Linode that doesn't really care about its customers. I think people mistake the quick support responses to basic questions as them caring, but when it really comes down to the important things like security and communication during a crisis, it's clear that there is a huge lapse from the leadership level down. Someone in this post wrote about how they stoppe…
Re: Security Notification and Linode Manager Password Reset
#117The actual answer is much more sinister than that. Which is kind of hilarious.
Re: Security Notification and Linode Manager Password Reset
#118Wow, these guys can't get a break.
You make your own luck. If they can't be bothered to invest in their tools and processes then this is the sort of thing that happens.
Re: Security Notification and Linode Manager Password Reset
#119Wow, these guys can't get a break.
They've been using a CF stack that is fundamentally broken from the foundation up for years and was aware of it. Its part of why they hired someone in July to rebuild it in python.
Re: Security Notification and Linode Manager Password Reset
#120Don't use Linode.