Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

121–130 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#121

Earlier quoted context omitted.

Sadly I trust them as far as I can throw them, and we moved everything important from them to AWS a few years back. We had left a few static sites there but after the shenanigans over the holidays, we're moving our remaining stuff. Sad. We spent >$10k/month with them for a while, before their shit started falling apart. They didn't appear to care at all when we left, so I suppose they have an awful lot of large custo…

We've been watching the unfolding situation closely as well and have decided to migrate/duplicate on AWS. Glad it worked our for you. At what point should Linode start thinking damage control? DDoS, breaches, lack of transparency...

It's ironic how most of the "yeah me too" posts end up being AWS related.

Re: Security Notification and Linode Manager Password Reset

#122

Earlier quoted context omitted.

I can't speak for the other folks that were compromised this way, but we decided to just cut our losses and move on at PagerDuty and spent the 30 days after the compromise migrating everything that was running there over to Azure. No point in putting pressure on a company that stonewalls you.

That's a good point. Not worth your time for a company like Linode that doesn't really care about its customers. I think people mistake the quick support responses to basic questions as them caring, but when it really comes down to the important things like security and communication during a crisis, it's clear that there is a huge lapse from the leadership level down. Someone in this post wrote about how they stoppe…

They were expecting to do $60m in 2014 - http://www.sramanamitra.com/2014/07/11/bootstrapping-a-web-h....

I know we left them 4 years ago because how they implement bandwidth caps on private IPs, which a few years later another company also had the same problem with and nicely wrote it up on their blog: https://docraptor.com/blog/gone-in-60-seconds-how-we-moved-f...

Linode's attempt to keep us (spending $5k a month at the time, but we've grown substantially with AWS now. Linode were at $22m in 2011, so we'd have been 0.3% of their total revenue): "We will certainly be sorry to see you go."

That may just be because they were fed up of us after we opened 27 support tickets about the same networking issue over the course of 11 months though.

Re: Security Notification and Linode Manager Password Reset

#123

The actual answer is much more sinister than that. Which is kind of hilarious.

What is the actual answer?

Last I heard, compromising Bitcoin exchanges for lulz and mad profit. Allegedly.

So if the rumor is true, he wasn't technically lying.

Re: Security Notification and Linode Manager Password Reset

#124
post #92

Earlier quoted context omitted.

(Linode Employee) Already got it covered, we are sending out an email to everyone in batches, but pushed out the blog first since it can be seen by everyone right away.

I'm still waiting for mine (6 hours since this was posted to HN).

I'm still waiting on an email too.

Re: Security Notification and Linode Manager Password Reset

#125

Earlier quoted context omitted.

You make your own luck. If they can't be bothered to invest in their tools and processes then this is the sort of thing that happens.

Yeah it's not like ColdFusion powered web sites enabling billions of dollars in commerce and what with all other web development tools being free of security vulnerabilities and all.

The merits of ColdFusion are irrelevant. The fact of the matter is that their software has continuously been breached.

Re: Security Notification and Linode Manager Password Reset

#127

Earlier quoted context omitted.

Saw your tweet ( https://twitter.com/theckman/status/684484772316360705 ) that linked to this post. Did a quick search to get your technical background and your LinkedIn profile states you used to work for Linode? I think it's important to share that info when you're telling your side of the incident. Your past relationship, if you left on bad terms, could play a role in your motivation to post.

I can absolutely understand your concern. I originally had it in my post, but removed it because I was worried it would detract from the details of our compromise at PagerDuty. I worked at Linode for just under three years, and worked on quite a few different things there. I started on support and moved on to a development role (including writing ColdFusion). I left Linode on good terms. California is much more entic…

so you're saying you wrote the code that was responsible for the breach(es)? It also sounds like you knew about these issues before you left Linode but didn't point them out while you were there?

Re: Security Notification and Linode Manager Password Reset

#128

Not the first time they poorly handled a security issue: https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-...

There are also a number of reviews on Glassdoor where supposed Linode employees say they were asked by management to lie to customers about security breaches.

Re: Security Notification and Linode Manager Password Reset

#129

Earlier quoted context omitted.

I can absolutely understand your concern. I originally had it in my post, but removed it because I was worried it would detract from the details of our compromise at PagerDuty. I worked at Linode for just under three years, and worked on quite a few different things there. I started on support and moved on to a development role (including writing ColdFusion). I left Linode on good terms. California is much more entic…

so you're saying you wrote the code that was responsible for the breach(es)? It also sounds like you knew about these issues before you left Linode but didn't point them out while you were there?

Where are you reading this? When he says he was writing ColdFusion, he's referring to the framework/programming language. He's not saying he wrote every single line of Linode's management interface.

Re: Security Notification and Linode Manager Password Reset

#130

Glad they posted it. I just logged into one of my linode boxes that I don't use for very much but keep around, and it was rooted... doh.

Could be just a coincidence if you keep SSH open on standard port. SSH bots don't sleep.

The host was only accessible via private key or Linode's LISH shell. That's what seems most suspicious.

There is some minor evidence remaining in the .bash_history that is curious.

Post reply on HN