Compromised Linode, thousands of BitCoins stolen
111–120 of 249 posts
Re: Compromised Linode, thousands of BitCoins stolen
#112Earlier quoted context omitted.
Actually not. Just use a loopback cypto FS to store the sensitive stuff. The reason they had to reboot the machine is that they just had access to the HDD where they could change the password, as opposed to having live root access.
where do you keep the key to the crypto fs?
Re: Compromised Linode, thousands of BitCoins stolen
#113Re: Compromised Linode, thousands of BitCoins stolen
#114Earlier quoted context omitted.
Actually not. Just use a loopback cypto FS to store the sensitive stuff. The reason they had to reboot the machine is that they just had access to the HDD where they could change the password, as opposed to having live root access.
where do you keep the key to the crypto fs?
If you can memorize it, it is a bad password.
Re: Compromised Linode, thousands of BitCoins stolen
#115Re: Compromised Linode, thousands of BitCoins stolen
#116Hmm, for a customer of a cloud provider, this sort of thing will be very hard to defend against. Maybe if the customer service system had had two-factor security, this might have been avoided (i.e., customer service can access your account only if you read them your hardware token's code). Requiring SSL/SSH client certificates even for intranet accesses might have deterred this attack. I hope other cloud providers ta…
> customer service can access your account only if you read them your hardware token's code At the very least, I'd hope Linode implements two-factor authentication for their own logins. A customer-provided OTP would be great but you'd need a customer service reset tool for that when people forget, which would put you back where you started...
Re: Compromised Linode, thousands of BitCoins stolen
#117The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscri…
This is why insurance exists. I wonder if there are any insurance providers who'd be willing to provider coverage for this sort of event.
Re: Compromised Linode, thousands of BitCoins stolen
#118The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscri…
Re: Compromised Linode, thousands of BitCoins stolen
#119Earlier quoted context omitted.
Are you sure? I think that you may be mistaken. The bar is just set higher in a "virtualized environment"... "In a public cloud environment, additional controls must be implemented to compensate for the inherent risks and lack of visibility into the public cloud architecture. A public cloud environment could, for example, host hostile out-of-scope workloads on the same virtualization infrastructure as a cardholder da…
Amazon getting a PCI compliance pass was a big deal. The last time I looked, you needed to be able to ensure secure access to the facility, enumerate who has physical access to the hardware and when, and things of that effect. And you need to be able prove all that in the event you're ever compromised.
Re: Compromised Linode, thousands of BitCoins stolen
#120Because sh*t happens...... whether we like it or not. Even if the technical requirements are light and it runs fine on a tiny linode, that might not be the right place from a security or integrity point of view, depending on the value of the app.
(for me, a digital wallet worth that much, I'd want at my home..... where I can control it)