Live data from Hacker News

Linode Security Advisory

blog.linode.com

21–30 of 119 posts

Re: Linode Security Advisory

#21
post #18
post #6

Update: also, read this comment right away. https://news.ycombinator.com/item?id=11136948 I find this update very hard to follow. Can someone tell me if I'm misreading it? I'm going to quote it twice, and then attempt to summarize: After examining the image from our July investigation, we discovered software capable of generating TOTP codes if provided a TOTP key. We found software implementing the decryption method…

It sounds they have an idea how it could have happened — the Lish vulnerability — but they don't know if that's how it actually did happen or if there's another undiscovered vulnerability lurking.

Ok, now help me understand how that can be true given this quote from the advisory:

The findings of our security partner’s investigation concluded there was no evidence of abuse or misuse of Linode’s infrastructure that would have resulted in the disclosure of customer credentials. Furthermore, the security partner’s assessment of our infrastructure and applications did not yield a vector that would have provided this level of access.

Did they get compromised or not?

Re: Linode Security Advisory

#22
I've been a happy Linode customer for a long, long time. With that I have to say the fact that they released this late on a Friday afternoon leaves a bad taste in my mouth. That in turn leaves me with doubts about the veracity of their statements. I'll probably be looking at alternatives now.

Re: Linode Security Advisory

#23
Hey There,

I'm a PagerDuty employee and am the same individual who made this post on the last HN thread:

* https://news.ycombinator.com/item?id=10845985

Unfortunately, there are some facts in Linode's post that are not correct.

>On July 9 a customer notified us of unauthorized access into their Linode account. The customer learned that an intruder had obtained access to their account after receiving an email notification confirming a root password reset for one of their Linodes. Our initial investigation showed the unauthorized login was successful on the first attempt and resembled normal activity.

This is almost correct. Someone got in to our account on the first try. They knew the password and a valid TOTP token. Although, Linode's email isn't what notified is, it was our intrusion detection system.

>On July 12, in anticipation of law enforcement’s involvement, the customer followed up with a preservation request for a Linode corresponding to an IP address believed to be involved in the unauthorized access. We honored the request and asked the customer to provide us with any additional evidence (e.g., log files) that would support the Linode being the source of malicious activity. Neither the customer nor law enforcement followed up and, because we do not examine customer data without probable cause, we did not analyze the preserved image.

This is partially correct. We informed Linode that we saw suspicious activity within their network, and reached out to them to inform them. We provided any and all logs we had. We also informed them that we passed the info on to law enforcement, in case they wanted to proactively preserve the data. The knew we had no further information, and as such didn't ask for anything additional.

>On the same day, the customer reported that the user whose account was accessed had lost a mobile device several weeks earlier containing the 2FA credentials required to access the account, and explained that the owner attempted to remotely wipe the device some time later. In addition, this user employed a weak password. In light of this information, and with no evidence to support that the credentials were obtained from Linode, we did not investigate further.

The story behind the mobile device is totally incorrect. The user did not lose their device, the device had been restored (intentionally wiped) 9 months prior to the compromise. The user got a new device, and never set up MFA on their new phone after wiping the old one. The device was, and still is, in the user's possession. The device has not been powered on in a long while.

The user who was compromised was no longer in possession of their MFA secret. They deleted it, intentionally, with no backups existing.

If anyone here is going to be at Velocity 2016 in Santa Clara, or at Monitorama PDX 2016, I'll be giving talks on how PagerDuty was compromised back in July. This includes full details of how this happened, including the details of the mobile device referenced above. There are some details in my talk that don't line up with the blog post provided by Linode. :)

Re: Linode Security Advisory

#24
post #8

I'm just going to leave this glassdoor review here: https://i.imgur.com/sJd56AT.png

I left a Glassdoor review about Linode that was removed because I mentioned an employee (anonymously) who rubbed his genitals on coworkers' keyboards as a joke. This was reported to and covered up by management because the employee was essential. Anyway, Glassdoor responded to ostensibly a Linode complaint by removing my review several weeks after I left it. So they do watch it.

There's a lot more to the story, for sure. It's the worst of the bro culture, or at least it was when I left. At my next employer they looked over Linode employees as recruiting opportunities after hiring me, and came to ask me about potential candidates, and the only one they were interested in was genital rubber. I laughed and said I'd quit.

Re: Linode Security Advisory

#25
post #21
post #18

Earlier quoted context omitted.

It sounds they have an idea how it could have happened — the Lish vulnerability — but they don't know if that's how it actually did happen or if there's another undiscovered vulnerability lurking.

Ok, now help me understand how that can be true given this quote from the advisory: The findings of our security partner’s investigation concluded there was no evidence of abuse or misuse of Linode’s infrastructure that would have resulted in the disclosure of customer credentials. Furthermore, the security partner’s assessment of our infrastructure and applications did not yield a vector that would have provided thi…

[deleted]

Re: Linode Security Advisory

#26
Two things in their "What We’re Doing About it" section really surprised me because they are things I would have expected a company of their size and sophistication to have done long ago:

> we are taking advantage of our payment processor’s tokenization feature to remove the risk associated with storing credit card information

> we are hiring a senior-level security expert

Re: Linode Security Advisory

#27
post #21
post #18

Earlier quoted context omitted.

It sounds they have an idea how it could have happened — the Lish vulnerability — but they don't know if that's how it actually did happen or if there's another undiscovered vulnerability lurking.

Ok, now help me understand how that can be true given this quote from the advisory: The findings of our security partner’s investigation concluded there was no evidence of abuse or misuse of Linode’s infrastructure that would have resulted in the disclosure of customer credentials. Furthermore, the security partner’s assessment of our infrastructure and applications did not yield a vector that would have provided thi…

"no evidence" or insufficient logging. The wording is spun to their favor throughout the entire advisory. Like "Security Investigation Retrospective" making it sound like they have the whole thing wrapped up. Also that everyone will be fine once their passwords are reset, when it sounds like they still don't really have any solid idea if they fixed the problem or not.

Re: Linode Security Advisory

#28

Hey There, I'm a PagerDuty employee and am the same individual who made this post on the last HN thread: * https://news.ycombinator.com/item?id=10845985 Unfortunately, there are some facts in Linode's post that are not correct. >On July 9 a customer notified us of unauthorized access into their Linode account. The customer learned that an intruder had obtained access to their account after receiving an email notifica…

Wow.

Re: Linode Security Advisory

#29

Hey There, I'm a PagerDuty employee and am the same individual who made this post on the last HN thread: * https://news.ycombinator.com/item?id=10845985 Unfortunately, there are some facts in Linode's post that are not correct. >On July 9 a customer notified us of unauthorized access into their Linode account. The customer learned that an intruder had obtained access to their account after receiving an email notifica…

Linode dropping the ball with PagerDuty is huge.

I can't even begin to imagine how much money your customers could lose if PagerDuty infrastructure went down.

Re: Linode Security Advisory

#30
post #7

It seems like the post creates more questions than it answers, but it's great that they are sort of transparent. I guess it's due to ongoing investigation. But it is quite surprising that someone was able to acquire the key for the token generation and they seem to have no explaination for it. And wow, they only started tokenizing credit cards now? And SHA-2 for password hashes? THB, after reading this post my confid…

> SHA-2 for password hashes

They're moving on from them, but they're going to leave SHA-2s sitting there and wait until everyone logs in to upgrade to bcrypt hashes at rest.

Not getting a super competent vibe off of these folks.

Post reply on HN