Live data from Hacker News

Linode Security Advisory

blog.linode.com

11–20 of 119 posts

Re: Linode Security Advisory

#11
post #9
post #7

It seems like the post creates more questions than it answers, but it's great that they are sort of transparent. I guess it's due to ongoing investigation. But it is quite surprising that someone was able to acquire the key for the token generation and they seem to have no explaination for it. And wow, they only started tokenizing credit cards now? And SHA-2 for password hashes? THB, after reading this post my confid…

>completely transparent How so? Either they're 100% clueless or they aren't being transparent.

Agree, edited.

It feels like they have no clue at all how it happened, but want to fix some issues nevertheless.

I'm not sure if they thought this would bring confidence back. Because if so, they failed hard.

Re: Linode Security Advisory

#12

> We have been working with federal authorities on these matters and their criminal investigations are ongoing. I cringe when I see companies say this. As if we're supposed to feel like the "hack" was somehow more sophisticated than spearfishing or social engineering because there's feds on the case. There's a hole in your security. Diligently look for that hole. If it's a mistake own up to it fully and apologize. Ma…

Disclaimer: Linode employee

Regardless of the severity of the means, the fact is that this sort of attack is entirely illegal and involving law enforcement is a clear requirement.

Re: Linode Security Advisory

#13
post #8

I'm just going to leave this glassdoor review here: https://i.imgur.com/sJd56AT.png

I interviewed at Linode. They are really nice guys, but they are located in a really odd area of New Jersey.

This is fine, but no remote jobs. I actually would have taken the job if they offered remote employment.

I've also only ready bad things about the executive level management. I asked the interviewer about it, they did seem to confirm my suspicions in this regard, but he did say that they had some great new technical leadership that will be driving the company forward.

Seems they really have very flippant executives, or it's just their CEO.

Re: Linode Security Advisory

#14

Not sure what to think about Linode anymore, on the one hand from a pure reliability point of view they have been bullet proof, had a few issues during the DDoS in December and I've always found their support to be good (the few times I've used them in 7 years). On the other hand they've had security issues fairly regularly and their response to the DDoS was pretty poor. That said if I was a cynic I'd say they probab…

I feel DO's level of service is on-bar. I've gotten multiple discounts from DO for "annoyances" I wasn't even annoyed by.

Re: Linode Security Advisory

#15

> We have been working with federal authorities on these matters and their criminal investigations are ongoing. I cringe when I see companies say this. As if we're supposed to feel like the "hack" was somehow more sophisticated than spearfishing or social engineering because there's feds on the case. There's a hole in your security. Diligently look for that hole. If it's a mistake own up to it fully and apologize. Ma…

Disclaimer: Linode employee Regardless of the severity of the means, the fact is that this sort of attack is entirely illegal and involving law enforcement is a clear requirement.

That's fine, but I think the parent is implying (probably correctly) that involving law enforcement isn't really doing anything for the customers of the service. Sure, what happened was a crime, and if the attackers are really unlikely they could end up getting arrested in a couple years. "And?"

Re: Linode Security Advisory

#17
post #6

Update: also, read this comment right away. https://news.ycombinator.com/item?id=11136948 I find this update very hard to follow. Can someone tell me if I'm misreading it? I'm going to quote it twice, and then attempt to summarize: After examining the image from our July investigation, we discovered software capable of generating TOTP codes if provided a TOTP key. We found software implementing the decryption method…

[deleted]

Re: Linode Security Advisory

#18
post #6

Update: also, read this comment right away. https://news.ycombinator.com/item?id=11136948 I find this update very hard to follow. Can someone tell me if I'm misreading it? I'm going to quote it twice, and then attempt to summarize: After examining the image from our July investigation, we discovered software capable of generating TOTP codes if provided a TOTP key. We found software implementing the decryption method…

It sounds they have an idea how it could have happened — the Lish vulnerability — but they don't know if that's how it actually did happen or if there's another undiscovered vulnerability lurking.

Re: Linode Security Advisory

#19
post #6

Update: also, read this comment right away. https://news.ycombinator.com/item?id=11136948 I find this update very hard to follow. Can someone tell me if I'm misreading it? I'm going to quote it twice, and then attempt to summarize: After examining the image from our July investigation, we discovered software capable of generating TOTP codes if provided a TOTP key. We found software implementing the decryption method…

Yeah, they really gloss over the fact they have no idea how the TOTP secret key was compromised, which worries me the most.

Re: Linode Security Advisory

#20

Not sure what to think about Linode anymore, on the one hand from a pure reliability point of view they have been bullet proof, had a few issues during the DDoS in December and I've always found their support to be good (the few times I've used them in 7 years). On the other hand they've had security issues fairly regularly and their response to the DDoS was pretty poor. That said if I was a cynic I'd say they probab…

I feel DO's level of service is on-bar. I've gotten multiple discounts from DO for "annoyances" I wasn't even annoyed by.

DO has raised enough cash to be able to do this to keep clients (good for LTV).
Post reply on HN