Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

181–190 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#181
post #3

So, a customer service interface was compromised via stolen credentials and used to access various Linode instances. A couple questions that immediately come to mind: 1. Can this interface be accessed from anywhere on the Internet? If so, why? If not, does that mean other systems owned by Linode were compromised as well? 2. Why can customer service representatives access and update servers without the client being no…

Reading the ticket slush posted it shows no password change logs, if linode was compromised either the whole infrastructure was compromised (unlikely) or a rouge admin or a admin comprimised account accessed the vps and stole the $, as per the bitcoin forums. Total stolen is roughly $16,000 USD

> if linode was compromised either the whole infrastructure was compromised (unlikely)

That's funny. I know from experience in the script kiddie part of the Internet that it was sometimes exceptionally easier to hack entire datacenters (even ones worth millions of dollars) just to get into a few of their customers, especially if those customers secured themselves.

Hosting companies have very sophisticated websites sometimes, meaning that they're almost always vulnerable to something.

I know of an SQL injection in an very large U.S. datacenter's administration panel which has been there for at least six years. Six years and it has not been fixed, and maybe a dozen people have independently discovered it. The deeper you delve, the more you realize that at least a handful of people also have access to important upstreams/backbones.

It's a lot bigger of a mess than anybody realizes. A bit of advice: if you say you're secure, you're either lying or colocating.

Re: Compromised Linode, thousands of BitCoins stolen

#182

Bitcoinica just reported losing 10K BTC (worth $50K USD) in this same incident. - http://bitcointalk.org/index.php?topic=66961.msg778254#msg77...

Saw that too. In past discussions on HN, Zhoutong said he hosted it at Heroku, but apparently they keep the 'hot wallet' alone on Linode instead for some reason, and use that to enable instant withdrawals.

At least Bitcoinica is eating the loss, it's not client money that was directly stolen.

Re: Compromised Linode, thousands of BitCoins stolen

#183
post #99
post #75

Earlier quoted context omitted.

This is why insurance exists. I wonder if there are any insurance providers who'd be willing to provider coverage for this sort of event.

Insurance won't insure for what they don't understand and build a risk model for. I can assure they won't understand something like this for a very long time.

I'm not sure they need to understand bitcoin specifically to build a risk model, wouldn't they just need general data on losses suffered by various internet hosts due to hacking attacks? Doesn't really matter exactly what is stolen as long as they have a corpus of data on the value of everything that is stolen in this manner. Bitcoin wallets probably fit somewhere in the payoff curve for that.

Re: Compromised Linode, thousands of BitCoins stolen

#184

Earlier quoted context omitted.

"it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider." Really? (I'm reading that as saying you think it _is_ a reasonable thing to store $13k worth of effectively-cash-value in a $19.95/month vps account?) Does anyone know what regulations like HIPPA or PCI have to say about the security of data stored on managed-by-3rd-party servers like VPS…

First of all, yes, I think it's reasonable. Second, where are you getting $19.95/month from, anyway? I haven't seen the plan in question mentioned, and even if this particular VPS happened to be Linode's lowest-end, the last time I looked (a while back, granted), slush had multiple large VPSs with Linode. Third, really, what does the price of the VPS have to do with it? You think as the cost of the VPS goes down, we'…

Interesting.

I'll freely admit I've only been thinking about this since reading this article, so I'm both not-fully-informed and I'm thinking about it as a response to some guy losing ~$13k, but to me it's _not_ reasonable.

(And my $19.95 number is perhaps hyperbolically chosen from their least expensive vps offering - but my assumption would be that the management/hypervisor back end would be shared across their entire infrastructure, so I think my argument holds, in that I'd expect the higher priced offerings to "only" have the employee-reliability-assurance of the cheapest vps…)

Re: Compromised Linode, thousands of BitCoins stolen

#185
post #165

Earlier quoted context omitted.

What would you recommend? Would you say the same thing if he'd been colocating and a data center employee had stolen his bitcoins? Because that seems far more analogous than any restaurant analogy, and I don't see any reasonable way for somebody who's not a huge corporation to avoid this kind of risk. You have to trust somebody at some point unless you're keeping the server locked in your own closet. It seems really…

Then he should Colo with a hosting provider with a contract provision that specifically holds them liable for any losses related to problems caused by the host, and enumerates those possible losses beforehand.

Does such a thing even exist?

Re: Compromised Linode, thousands of BitCoins stolen

#186

> Although passwords are stored using SHA1 with a salt, Where's the bcrypt/scrypt/whatever police in this comments thread?

Trying to find some official information to figure out the status of our own 'nodes. :-(

official announcement: http://status.linode.com/2012/03/manager-security-incident.h...

Re: Compromised Linode, thousands of BitCoins stolen

#187
Could this have been a vulnerability in Lish, which can be run from a browser using Linode's AJAX console?

http://library.linode.com/troubleshooting/using-lish-the-lin...

I've completely ruined networking and disabled root logins on a Linode VPS, but could still access that same VPS as root using Lish.

Re: Compromised Linode, thousands of BitCoins stolen

#188

Earlier quoted context omitted.

In an actual court case, the reasonableness of everyone's actions would be evaluated, but it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider. That doesn't mean Linode has any legal liability in this case, just that your analogy is off the mark.

"it's hard to imagine a court finding it unreasonable that someone placed data worth $13,000 to them on a respected VPS provider." Really? (I'm reading that as saying you think it _is_ a reasonable thing to store $13k worth of effectively-cash-value in a $19.95/month vps account?) Does anyone know what regulations like HIPPA or PCI have to say about the security of data stored on managed-by-3rd-party servers like VPS…

IANAL (or QSA)

PCI doesn't specifically say anything about usage of a VPS. It does however speak about access to data.

If you have encrypted credit card information, you'll be asked to list those that have access to the encrypted information, they encryption key, and the key encrypting key. Then you'll be asked to justify their access.

I'm sure I could come up with with several other major violations, but this alone is severe enough that I can't envision a way that you'd pass a PCI audit.

Re: Compromised Linode, thousands of BitCoins stolen

#189

Earlier quoted context omitted.

> The last time I looked, you needed to be able to ensure secure access to the facility, enumerate who has physical access to the hardware and when, and things of that effect. And you need to be able prove all that in the event you're ever compromised. None of that should be particularly difficult for a VPS provider as large as Linode.

> you needed to be able to ensure secure access to the facility This part isn't doable if you don't own the datacenter. Slicehost has a problem with this because they never owned the datacenters they used.

You don't need to own the datacenter, but you do need your own, secured space in a datacenter.

Re: Compromised Linode, thousands of BitCoins stolen

#190

Earlier quoted context omitted.

First of all, yes, I think it's reasonable. Second, where are you getting $19.95/month from, anyway? I haven't seen the plan in question mentioned, and even if this particular VPS happened to be Linode's lowest-end, the last time I looked (a while back, granted), slush had multiple large VPSs with Linode. Third, really, what does the price of the VPS have to do with it? You think as the cost of the VPS goes down, we'…

Interesting. I'll freely admit I've only been thinking about this since reading this article, so I'm both not-fully-informed and I'm thinking about it as a response to some guy losing ~$13k, but to me it's _not_ reasonable. (And my $19.95 number is perhaps hyperbolically chosen from their least expensive vps offering - but my assumption would be that the management/hypervisor back end would be shared across their ent…

Why are you looking at it as "X has the same assurance as Y" instead of "Y has the same assurance as X"?

If you've got a vault that holds a massive diamond, and a little gold ring, do you become concerned because the diamond "only" has the protection of a little gold ring?

Post reply on HN