Live data from Hacker News

Akamai to Acquire Linode

akamai.com

201–210 of 336 posts

Re: Akamai to Acquire Linode

#201

Earlier quoted context omitted.

A 2012 Bitcoin hack victim was none other than a lead developer of Bitcoin. Back then, they ran a Bitcoin faucet on it that gave out a paltry 0.25 Bitcoin at a time. I never bothered to jump through those hoops for like a dollar (now about US$10k): http://gavintech.blogspot.com/2012/03/bitcoin-faucet-hacked.... He only lost 5 bitcoin (like $20 then or $200k today), but another lost 3100, or around… $124 million today…

Wow, that some major root level compromise at linode. It's interesting how quiet they kept these things in those days.

Linode reported it the same day:

Manager Security Incident

Ensuring the security of our platform is our top priority. We maintain a strong security policy and aim to communicate openly should it ever be compromised. Thus, we are posting to describe a recent incident affecting the Linode Manager.

Here are the facts:

This morning, an intruder accessed a web-based Linode customer service portal. Suspicious events prompted an immediate investigation and the compromised credentials used by this intruder were then restricted. All activity via the web portal is logged, and an exhaustive audit has provided the following:

All activity by the intruder was limited to a total of eight customers, all of which had references to "bitcoin". The intruder proceeded to compromise those Linode Manager accounts, with the apparent goal of finding and transferring any bitcoins. Those customers affected have been notified. If you have not received a notification then your account is unaffected. Again, only eight accounts were affected.

The portal does not have access to credit card information or Linode Manager user passwords. Only those eight accounts were viewed or manipulated -- no other accounts were viewed or accessed.

Security is our number one priority and has been for over eight years. We depend on and value the trust our customers have placed in us. Now, more than ever, we remain committed to ensuring the safety and security of our customers' accounts, and will be reviewing our policies and procedures to prevent this from ever recurring.

---

I won't argue Linode is blameless here, but seems like the only reason it had such an outsized impact was because the 8 customers who were targeted evidently didn't do much to protect their assets from someone gaining unauthorized access to their servers--which is always a possibility with any publicly exposed server with or without a breach of the service provider being involved.

Re: Akamai to Acquire Linode

#202
post #101

I had a sour taste from what I remember being misleading communication around very serious control plane hacks of linode. A lot of bitcoin theft in 2012 (maybe by their own staff?) 2013 some kind of cold fusion / HTP hack Another CF / HTP hack here. 2014 brought the MySQL server no password stuff. 2015 ish some kind of total root compromise? You can get a feel for all this here including the denials / lack of notific…

Look, we are random internet people, and it's a "me vs. you" scenario, but as someone who worked at Linode in 2012, we were a small company, that all worked out of one office, with like 3 admins at the time. Yes, there were various hacks. Yes, there were silly vulns, but positing that one of the employees at that time stole bitcoin is something that I won't stand for. Could it have happened, sure. Do I think that it…

I can't edit my comment.

As I noted elsewhere, there's an opportunity to do the right thing when someone comes to you and says look, someone is coming in on the control plane and resetting my server passwords.

And yes, that includes looking at your staff especially when bitcoin is in the mix as its less traceable to a person.

For some reason, for year after year, there was this pattern. No problem, we have good security, oh wait, we've been rooted for months. Or someone is coming in on the staff admin plane and taking all sorts of action.

It could be outside hackers sure. But linode never seemed that interested in sorting things out.

The takeaway I had was that you might not notice if a staff person OR hacker was messing around.

Re: Akamai to Acquire Linode

#203

Earlier quoted context omitted.

Wow, that some major root level compromise at linode. It's interesting how quiet they kept these things in those days.

Linode reported it the same day: Manager Security Incident Ensuring the security of our platform is our top priority. We maintain a strong security policy and aim to communicate openly should it ever be compromised. Thus, we are posting to describe a recent incident affecting the Linode Manager. Here are the facts: This morning, an intruder accessed a web-based Linode customer service portal. Suspicious events prompt…

Take a look at this link re: pagerduty and how linode handled things there.

https://news.ycombinator.com/item?id=10845985

Doesn't it seem kind of crazy that folks get full root control plane on linode so frequently?

Re: Akamai to Acquire Linode

#204
post #90

Earlier quoted context omitted.

Looking from the end user end it seems nice, but will soon be weaponized in all possible mannar, sloppily executed, and too much data to ingest. For reference there is mandatory disclosure of (serious) data breaches in the GPDR and it's very uncommon that the disclosure actually occurs.

Target should have had difficulty surviving as a company as a result of penalties-if-not-prison for their 2013 breach, but we see what happened there.

Should that same existential penalty be applied to every company who had Log4J running in prod a few months back? That was a much more widespread root compromise...

Re: Akamai to Acquire Linode

#205

Earlier quoted context omitted.

Where are you gonna go if you leave Linode? Do you know yet? Digital Ocean is the most similar, but after getting burned hard by them I will never put myself in that vulnerable position again. I've been pretty happy with OVH thus far, but at least last time I checked the US presence was minimal and that's important to my customers.

I currently have most of my stuff split between Digital Ocean and Linode. So if I had to move quickly, it'd be Digital Ocean. I'm going to be kicking the tires on Hetzner and Vultr soon, because DO is not a super satisfying backup plan for me. I've used Azure enough to get spun up quickly there, but that would be an unhappy upward adjustment on my budget or an unhappy downward adjustment on the performance I expect.

Hetzner is good but I’ve found that their connection from EU to US is weak, apparently in Level 3 somewhere.

Re: Akamai to Acquire Linode

#206
post #107

Earlier quoted context omitted.

You may have convinced me to move over to Vultr.

That doesn't include a ip4 address and you can't point a domain to it. I have two grandfathered 2.50 packages with an ip (no domain pointing).. no issues ever but it's a playground not a production box for me.

How can you have an ip that can’t be pointed to by a domain?

Re: Akamai to Acquire Linode

#207

I had a sour taste from what I remember being misleading communication around very serious control plane hacks of linode. A lot of bitcoin theft in 2012 (maybe by their own staff?) 2013 some kind of cold fusion / HTP hack Another CF / HTP hack here. 2014 brought the MySQL server no password stuff. 2015 ish some kind of total root compromise? You can get a feel for all this here including the denials / lack of notific…

The January 2016 thing was them finally acknowledging the attack that had happened many months prior, after WPEngine gave Linode the opportunity to announce they were hacked after they were also compromised using the same vector that hit PagerDuty. If Linode had declined, WPEngine was going to do it on their behalf. I couldn't convince the powers that be to make the same demand months prior, even though I was confident, so if WPEngine hadn't pushed the issue I don't know that Linode would have ever disclosed.

But that doesn't matter anymore. This was nearly a generation ago in tech companies, and they are now part of a bigger one.

Re: Akamai to Acquire Linode

#208
post #101

I had a sour taste from what I remember being misleading communication around very serious control plane hacks of linode. A lot of bitcoin theft in 2012 (maybe by their own staff?) 2013 some kind of cold fusion / HTP hack Another CF / HTP hack here. 2014 brought the MySQL server no password stuff. 2015 ish some kind of total root compromise? You can get a feel for all this here including the denials / lack of notific…

Look, we are random internet people, and it's a "me vs. you" scenario, but as someone who worked at Linode in 2012, we were a small company, that all worked out of one office, with like 3 admins at the time. Yes, there were various hacks. Yes, there were silly vulns, but positing that one of the employees at that time stole bitcoin is something that I won't stand for. Could it have happened, sure. Do I think that it…

As someone who commented on Linode hacks earlier, I can vouch for lbotos having worked there and feel the same way as they do. I don't believe any of the attacks were an inside job, because I don't believe anyone would have done that and if they did they knew how not to leave a trail behind.

Also hey lbotos, hope you're doing well!

Re: Akamai to Acquire Linode

#209
post #122

Earlier quoted context omitted.

I think in 2012 the tech community's sentiment was actually that Bitcoin was really cool and definitely useful, since it was new and did things in a practical application that we hadn't seen before. It's interesting that hindsight clouds that, it has been viewed negatively for years now but it's not that old yet. (Either way, your main point stands of course.)

> I think in 2012 the tech community's sentiment was actually that Bitcoin was really cool and definitely useful I don't think there was ever really a consensus on this. Lots of people (myself included, but also quite a few friends) always thought Bitcoin was just kinda useless. It's just that in 2012 there were comparatively low stakes (i.e. no massive energy use, not yet massive amounts of people pouring money in i…

I find this exceedingly hard to believe. Around 2009-2010, btc was definitelynot an "asset" (like the bafoons try to treat it now). It *was a currency*.

Many still believe in the idea that (certain, less well know) crypto can be used as a real currency, but unfortunately the public severely tainted it with ideas of 'being an asset'.

This comment reads as someone who is more aligned with the public's (HN) perception of modern crypto, rather than the use of it pre-2010.

Re: Akamai to Acquire Linode

#210
post #101

Earlier quoted context omitted.

Look, we are random internet people, and it's a "me vs. you" scenario, but as someone who worked at Linode in 2012, we were a small company, that all worked out of one office, with like 3 admins at the time. Yes, there were various hacks. Yes, there were silly vulns, but positing that one of the employees at that time stole bitcoin is something that I won't stand for. Could it have happened, sure. Do I think that it…

I can't edit my comment. As I noted elsewhere, there's an opportunity to do the right thing when someone comes to you and says look, someone is coming in on the control plane and resetting my server passwords. And yes, that includes looking at your staff especially when bitcoin is in the mix as its less traceable to a person. For some reason, for year after year, there was this pattern. No problem, we have good secur…

I’m really struggling to see how “the company’s response to security breaches was inappropriate” logically leads to “staff might be stealing Bitcoin.”

It’s a baseless and unfair attack and I think you should consider deleting your original comment.

Post reply on HN