Live data from Hacker News

Linode Security Advisory

blog.linode.com

101–110 of 119 posts

Re: Linode Security Advisory

#101
post #89
post #74

Earlier quoted context omitted.

For me, because once you get beyond the $5 nano/free tier, things get expensive really quick. For example, I run about 10 different sites off one Linode, but only one of them gets any substantial traffic. Still, in order to run that site, which works just fine on a $20/mo 2GB/2core unit on Linode, I'll push out about 150GB in outbound bandwidth a month, and require around 15-20GB in storage. Pricing that out on AWS,…

If you're are paying double digits or more for cloud hosting, you'd probably get much better bang for your buck by getting a similarly priced dedicated hosting setup. The main value provided by cloud hosting is easy scalability, not cheap prices.

Do you have hosts you would suggest? There are so many hosts out there, it's hard to know wheat from chaff (to put it politely).

Re: Linode Security Advisory

#102
post #29

Earlier quoted context omitted.

Linode dropping the ball with PagerDuty is huge. I can't even begin to imagine how much money your customers could lose if PagerDuty infrastructure went down.

Which makes me wonder why they're even with Linode.

I watched PagerDuty leadership run out of the room when Amazon completely shit itself during a conference in 2011, and I heard a few months later that they'd signed up with Linode at some point after that. I could probably put two and two together there as a reliability strategy to back up against AWS failures.

Keep in mind Linode had a pretty good rep at the time. I wouldn't second guess them on the call, as I probably would have made it at the time, too. They didn't dig in or lock themselves in with debt, and bailed when the time was right, too.

Re: Linode Security Advisory

#103

Earlier quoted context omitted.

This is very helpful information. Can you say if you've moved to a different provider or if you're now racking your own machines? And if you do have a new provider, can you say who you are and how you evaluated them? I have been doing some research in my (limited) spare time to try to find a new provider, but I still have not made the switch from Linode.

We use AWS us-west-1, us-west-2 and Azure Fresno. Azure replaced Linode very quickly after the July incident.

> Azure replaced Linode very quickly after the July incident.

Bah. More virt. Throw down some cash on a cage and fire up AWS Direct Connect, man. It's bliss, you get more choices out here than I did with us-east-1, plus you guys can afford it now.

We plopped in physical gear for a couple parts of our AWS infra a few employers ago and cut our Amazon opex by like, two thirds. Not helpful for your using Azure as a reliability strategy, but worth thinking about for your write-heavy databases, for example.

Re: Linode Security Advisory

#104

Earlier quoted context omitted.

I have to be fair about Linode's performance. My Argon2 test suite averaged around 45 seconds on my Linode. I've relocated my VPS to AWS following these recent discussions around security, and the same test suite now runs between 5 and 20 minutes, presumably based on what my neighbours are doing at the time. It's a frustrating tradeoff.

That's not a particularly useful comparison without at least stating the instance types you were using on each provider.

Fair call. I had the entry level Linode with 1GB RAM and 1 vCPU, and moved to the t2.micro, also with 1GB RAM and 1 CPU. I'm aware that cost me SSD's, but nothing I do is IO relevant.

Re: Linode Security Advisory

#105
post #51

Earlier quoted context omitted.

http://oktawave.com and http://vultr.com are said to be good. I haven't used them though, I personally use baremetal servers at Hetzner.

I use vultr to host freebsd servers. Have no problems with it but it is young and it definitely shows. Good host provider to keep an eye on.

Same. I have been using it for a cheap freebsd website instance, for just over a year now. So far, I have needed very little interaction with support, so I can't speak to how good it is.

Re: Linode Security Advisory

#106

Earlier quoted context omitted.

Employee Disclaimer: It's not 2011 and Mike is not working at Linode anymore. You really don't get what it's like working at Linode TODAY. I'm sure everything your stating was terrible for you but it's not an accurate representation of what the company has become.

The same people are running the company who did then, who were responsible for setting the culture of the company, covering for employees who did unspeakable things (worse than what I've said here), and pretty much instructing employees to lie to customers. Also, all the people who quit Linode and ran to this coast after I left have kept me very apprised of what working at Linode is like TODAY. I still communicate wi…

> You know that. Don't be disingenuous.

> And you know it.

That's unduly personal. Please remain civil.

Re: Linode Security Advisory

#107
post #106

Earlier quoted context omitted.

The same people are running the company who did then, who were responsible for setting the culture of the company, covering for employees who did unspeakable things (worse than what I've said here), and pretty much instructing employees to lie to customers. Also, all the people who quit Linode and ran to this coast after I left have kept me very apprised of what working at Linode is like TODAY. I still communicate wi…

> You know that. Don't be disingenuous. > And you know it. That's unduly personal. Please remain civil.

I mean, I was responding to a personal comment that directly and personally told me I don't "get" things (and which included what can be reasonably interpreted as a veiled threat by mentioning my departure year from a throwaway account, to make clear that I'm a known quantity in the equation). I'm really trying, here, Dan. We've talked about this over e-mail, but it's getting really tough to contribute here with arbitrary boundaries that are inconsistently enforced, and that a penalty remains on my account for some comment I made in the past that doesn't even matter any more.

I bit my tongue on you detaching this subthread because I've learned that moderation is opaque and largely not welcome to outside opinion, but I agree with Ryan up there and suspect you detached the thread to hide where I went with it. I'm fine with that (honest). Just wish you'd say that.

I've edited, regardless. Is that better?

Re: Linode Security Advisory

#108
post #70

Earlier quoted context omitted.

This is very helpful information. Can you say if you've moved to a different provider or if you're now racking your own machines? And if you do have a new provider, can you say who you are and how you evaluated them? I have been doing some research in my (limited) spare time to try to find a new provider, but I still have not made the switch from Linode.

If you follow the link he posted, you'll see they switched away from Linode almost immediately after the July breach.

Indeed I did read it - my question wasn't "did you move" but "to whom did you move".

Re: Linode Security Advisory

#109
post #19

Earlier quoted context omitted.

Yeah, they really gloss over the fact they have no idea how the TOTP secret key was compromised, which worries me the most.

They changed the 2FA to use a microservice, so whatever the vulnerability was before, if the 2FA is now on an isolated server, that vulnerability shouldn't have access to the new 2FA key.

I think it's fairly important to note that they're NOT currently using the microservice for the 2FA, and they're NOT using bcrypt right now.

The blog post states they're "working towards" these changes, they're not currently in place. It's fairly unlikely that they're using the same secret key as the one they found on the server, but it's fair to assume that they are still using salted SHA-2 for your passwords and the same 2FA setup right now.

They likely won't roll out the major changes until they roll out the "new and improved" Linode dashboard they're coming up with.

Re: Linode Security Advisory

#110
post #106

Earlier quoted context omitted.

> You know that. Don't be disingenuous. > And you know it. That's unduly personal. Please remain civil.

I mean, I was responding to a personal comment that directly and personally told me I don't "get" things (and which included what can be reasonably interpreted as a veiled threat by mentioning my departure year from a throwaway account, to make clear that I'm a known quantity in the equation). I'm really trying, here, Dan. We've talked about this over e-mail, but it's getting really tough to contribute here with arbi…

Yes, that's much better. You took out the personal attack, which was all that was needed.

I don't have the least opinion about Linode or "where [you] went with it". My concern is with civility on Hacker News. That's not an arbitrary line, though I'd never claim we make every call correctly.

The GP seemed to me merely to be saying that the company had changed since you left. That doesn't seem personal, nor a threat, but perhaps there are subtleties I'm missing.

Post reply on HN