Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

51–60 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#52
post #36
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

Well the steps I would like to take regarding linode aren't exactly legal. Satisfying yes, but not legal.

But I just checked and my credit card haven't been used anywhere I didn't use it.

Re: Linode hacked, CCs and passwords leaked

#53

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not only that, it also makes me wonder about the free RAM upgrade from almost a week ago. Some people are reporting their Linode credit cards being used for fraudulent purchases as far as a week ago, so this might have been a move to gain some pre-emptive goodwill. I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.

I tend to think the timing is just a coincidence. They also upgraded CPU and bandwidth over the last month and there were rumors of upgraded RAM for a while too.

Re: Linode hacked, CCs and passwords leaked

#54

Well I'll wait for a response from linode, but it certainly looks like they were very dishonest. I think I will close my account.

So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?)

A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared.

Not the end of the world. The CC industry is set up well to handle this kind of thing.

Re: Linode hacked, CCs and passwords leaked

#55

Earlier quoted context omitted.

Using a processor who stores the card number outside of your infrastructure (ie. Stripe) can also be helpful.

Until they have a security breach.

Yes

But if that happens, it's not your responsibility (at least not 100%), it's theirs

Re: Linode hacked, CCs and passwords leaked

#56

If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…

Two alternatives often mentioned on here are DigitalOcean and RamNode.

I've only used DigitalOcean. My anecdotal experience from running a Chef Server on a 1GB instance has been pretty mixed. The price is good, but network and CPU performance feels very variable to me. A month ago their Amsterdam servers were unable to be resized, and there was nothing about it on their status page. I tweeted and was told they'd be working "some time later today". Doesn't fill me with much confidence in general.

I'd still choose Linode for anything of importance - their long reputation is well earned in my opinion. But, if this breach is true, I hope they handle it well.

Re: Linode hacked, CCs and passwords leaked

#57

Earlier quoted context omitted.

Until they have a security breach.

Better rely on someone who's sole job is securing that info than doing it yourself.

Storing credit card info just helps make you a bigger target. If your a small company, better let someone else store card info, let them be the target.

Also you're fined by the credit card companies if you lose card information. I believe it's a per card fine, so it get expensive really quickly.

Actually I don't get why any company would choose to store credit card information, when most payment providers will do it for you.

Re: Linode hacked, CCs and passwords leaked

#59

Is there any confirmation on this? [edit] Just looked at twitter, this tweet doesn't look good: https://twitter.com/Jamiesingleton/status/322730588459114500 But it may just be random coincidence. [edit again] Links from slashdot article: IRC chat: http://turtle.dereferenced.org/~nenolod/linode/linode-abridg... Link in IRC chat (i think it is of linode.com's web directory): https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc

Putting aside any opinions on his morals or maturity-level displayed in the chat, it's a fun read. I love how ryan keeps reconnecting after each attempt to kick him out. He must have a pre-verified list of proxies/compromised-boxes he can connect from so he's just burning through them as he gets banned. I found that amusing.

Re: Linode hacked, CCs and passwords leaked

#60

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not only that, it also makes me wonder about the free RAM upgrade from almost a week ago. Some people are reporting their Linode credit cards being used for fraudulent purchases as far as a week ago, so this might have been a move to gain some pre-emptive goodwill. I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.

"Someone hacked us and stole customer details... quick, give everyone more RAM!"

Doesn't sound very plausible to me.

Post reply on HN