Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

131–140 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#131

This is a perfect poster child for decentralized authentication. Centralized stores of passwords and secrets are just asking for trouble. When will we learn?

so... I completely agree that shared secret authentication is a bad idea, and I use public key authentication wherever I can (password auth is disabled for ssh on every server I control; I do everything with ssh public keys.)

However, I've yet to set a public key authentication scheme that users would find acceptable for web applications. Do you really expect all users to setup x.509 auth in the browser?

What is your public key solution to authenticate the web-applications that customers demand?

Re: Security Notification and Linode Manager Password Reset

#132
I enabled two factor on my Linode account recently and saw this worrying copy:

> If you lose your token and get locked out of the Linode Manager, email support@linode.com to regain access to your account.

> Should you need us to disable your Two-Factor Authentication, the following information is required:

> An image of the front and back of the payment card on file, which clearly shows both the last 6 digits and owner of the card. > An image of the front and back of the matching government-issued photo ID.

There doesn't seem to be a way to say "I have my big boy pants on, don't let anyone in under any circumstances". This is the first 2FA setup I've seen that still allows bypass by contacting support.

EDIT: I also find it odd that you have to manually generate a scratch code, and they don't automatically generate it for you. Again, all of the other 2FA setups I've gone through have done this.

Re: Security Notification and Linode Manager Password Reset

#133
post #55

Earlier quoted context omitted.

Difficult question to answer. There was a complete lack of "technical" evidence against me (e.g .bash_history files, wiretaps). The only evidence the prosecution had against me were a list of compromised sites and several coldfusion 0days I had in my possession. They could never prove that I generated the list of compromised sites, but the judges felt that the possession of said list was enough evidence to convict me…

> We would've appealed but there was no point as the sentence was essentially nothing. But you do end up with a record, which is not 'essentially nothing'.

The other side to that is that if you appeal, and lose, you can come off worse. So even though a criminal record is "something", depending where the lawyers feel your chances are, it may be best going along with it.

Re: Security Notification and Linode Manager Password Reset

#134
post #29
post #23

Looks like the reason their blog is down is because... it's now being targeted by a DoS: http://status.linode.com/incidents/kldhjpjnfnkj Attacking a blog talking about the hack? It sure seems that someone has a grudge against Linode. :-/

At this point I'm starting to wonder whether this isn't a competitor putting their investors money to work. It's otherwise utterly bizzare that someone would be so obsessive in damaging Linode. I really hope they make the details of the investigation public...

Based on the number of negative reviews on glassdoor, it could also be a former employee.

Re: Security Notification and Linode Manager Password Reset

#136

I enabled two factor on my Linode account recently and saw this worrying copy: > If you lose your token and get locked out of the Linode Manager, email support@linode.com to regain access to your account. > Should you need us to disable your Two-Factor Authentication, the following information is required: > An image of the front and back of the payment card on file, which clearly shows both the last 6 digits and own…

> There doesn't seem to be a way to say "I have my big boy pants on, don't let anyone in under any circumstances". This is the first 2FA setup I've seen that still allows bypass by contacting support.

Sadly, this is quite common, especially with organizations that provide phone support[1].

[1]: http://krebsonsecurity.com/2015/12/2016-reality-lazy-authent...

Re: Security Notification and Linode Manager Password Reset

#138

Earlier quoted context omitted.

They've been using a CF stack that is fundamentally broken from the foundation up for years and was aware of it. Its part of why they hired someone in July to rebuild it in python.

You signed an NDA and have done a full analysis of their code? Cool.

Go look through how often CF has zero days compared to competing platforms.

Re: Security Notification and Linode Manager Password Reset

#139

Earlier quoted context omitted.

What is the actual answer?

Last I heard, compromising Bitcoin exchanges for lulz and mad profit. Allegedly. So if the rumor is true, he wasn't technically lying.

I don't think that if all you have is 'allegedly' it is up to you to make such accusations here in public.

Re: Security Notification and Linode Manager Password Reset

#140

The actual answer is much more sinister than that. Which is kind of hilarious.

That crosses into personal attack, which is not ok, even if it's just insinuated.

We detached this subthread from https://news.ycombinator.com/item?id=10847715 and marked it off-topic.

Post reply on HN