Live data from Hacker News

Linode Security Advisory

blog.linode.com

1–10 of 119 posts

Re: Linode Security Advisory

#2
>Linode’s security team did discover a vulnerability in Lish’s SSH gateway that potentially could have been used to obtain information discovered on December 17, although we have no evidence to support this supposition. We immediately fixed the vulnerability.

Yeah, LiSH was exploited like 3 years ago...

Unless it's been completely redesigned it's probably still got heaps of vulnerabilities, screen wasn't designed for untrusted input.

>CC Tokenization: Although our investigation yielded no evidence of credit card information being accessed, we are taking advantage of our payment processor’s tokenization feature to remove the risk associated with storing credit card information.

Nobody thought about doing this when every customers card plaintext card info was taken years ago?

Anyway, the entire blog post is bullshit. It completely fails to address their previous security track record. A single hack isn't that big of a deal, but this has happened to Linode countless of times.

Re: Linode Security Advisory

#3
post #2

>Linode’s security team did discover a vulnerability in Lish’s SSH gateway that potentially could have been used to obtain information discovered on December 17, although we have no evidence to support this supposition. We immediately fixed the vulnerability. Yeah, LiSH was exploited like 3 years ago... Unless it's been completely redesigned it's probably still got heaps of vulnerabilities, screen wasn't designed for…

Cool beans, herb.

Re: Linode Security Advisory

#4
The page's title "Security Investigation Retrospective" fits the content better than the current HN's "Linode Security Advisory": it is about last July's breach that caused January's password reset; what happened and what they've done about it.

Re: Linode Security Advisory

#5
Not sure what to think about Linode anymore, on the one hand from a pure reliability point of view they have been bullet proof, had a few issues during the DDoS in December and I've always found their support to be good (the few times I've used them in 7 years).

On the other hand they've had security issues fairly regularly and their response to the DDoS was pretty poor.

That said if I was a cynic I'd say they probably have one of the best setups for dealing with future attacks (old joke about never firing an employee who made an expensive mistake because he'll never make that mistake again) and finally seem to be taking security seriously, for me the list of changes all sound good (particulary open sourcing Linode Manager and tokenising CC's had to reset a card because of them once before).

We are slowly moving a lot of stuff back to a DC up the road but we still have some stuff with them.

Re: Linode Security Advisory

#6
Update: also, read this comment right away. https://news.ycombinator.com/item?id=11136948

I find this update very hard to follow. Can someone tell me if I'm misreading it? I'm going to quote it twice, and then attempt to summarize:

After examining the image from our July investigation, we discovered software capable of generating TOTP codes if provided a TOTP key. We found software implementing the decryption method we use to secure TOTP keys, along with the secret key we use to encrypt them. We also found commands in the bash history that successfully generated a one-time code. Though the credentials found were unrelated to any of the unauthorized Linode Manager logins made in December, the discovery of this information significantly changed the seriousness of our investigation.

and then:

The findings of our security partner’s investigation concluded there was no evidence of abuse or misuse of Linode’s infrastructure that would have resulted in the disclosure of customer credentials. Furthermore, the security partner’s assessment of our infrastructure and applications did not yield a vector that would have provided this level of access.

Linode’s security team did discover a vulnerability in Lish’s SSH gateway that potentially could have been used to obtain information discovered on December 17, although we have no evidence to support this supposition. We immediately fixed the vulnerability.

Here is my read of what this says; I'd like to know if I'm wrong.

"One of our customers got owned up in July, and gave us an attacker source address within Linode. We pickled up the attacker's host. In December, we examined the pickled host, and found secrets related to the way we store 2FA credentials, indicating that our credentials database may have been compromised. In conclusion: we have no idea how that could have happened."

Am I missing something else?

Re: Linode Security Advisory

#7
It seems like the post creates more questions than it answers, but it's great that they are sort of transparent. I guess it's due to ongoing investigation.

But it is quite surprising that someone was able to acquire the key for the token generation and they seem to have no explaination for it. And wow, they only started tokenizing credit cards now? And SHA-2 for password hashes?

THB, after reading this post my confidence in them hasn't really increased. It feel like: "We fucked up, but are not exactly sure why but will fix some issues nevertheless".

Re: Linode Security Advisory

#9
post #7

It seems like the post creates more questions than it answers, but it's great that they are sort of transparent. I guess it's due to ongoing investigation. But it is quite surprising that someone was able to acquire the key for the token generation and they seem to have no explaination for it. And wow, they only started tokenizing credit cards now? And SHA-2 for password hashes? THB, after reading this post my confid…

>completely transparent

How so? Either they're 100% clueless or they aren't being transparent.

Re: Linode Security Advisory

#10
> We have been working with federal authorities on these matters and their criminal investigations are ongoing.

I cringe when I see companies say this. As if we're supposed to feel like the "hack" was somehow more sophisticated than spearfishing or social engineering because there's feds on the case.

There's a hole in your security. Diligently look for that hole. If it's a mistake own up to it fully and apologize. Make your system robust. If you don't have the talent in your organization to do this, then hire more talented engineers. Compete with other companies for good people.

Post reply on HN