From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…
Linode hacked, CCs and passwords leaked
71–80 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#72Earlier quoted context omitted.
So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…
You missed the step where you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process! Kind of sucks to have to spend hours doing that for someone else's oversight. It's not the end of the world, but it paints a clear picture about where a company's priorities…
Re: Linode hacked, CCs and passwords leaked
#73Re: Linode hacked, CCs and passwords leaked
#74My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…
Re: Linode hacked, CCs and passwords leaked
#75Re: Linode hacked, CCs and passwords leaked
#76Earlier quoted context omitted.
Actually, if you're processing cards directly, you do in fact need to have an PCI-qualified outside firm† (a QSA) audit you for PCI compliance. But those audits are notoriously superficial; PCI audits are a race-to-the-bottom affair. † We are not one of those.
Every one of these reviews that I've been involved in has been conducted by a couple of guys with laughable abilities.
Re: Linode hacked, CCs and passwords leaked
#77Earlier quoted context omitted.
I've done PCI "audits" for several companies I've worked for; it's a checklist you go down yourself . That's why its called a "pci self assessment".
Actually, if you're processing cards directly, you do in fact need to have an PCI-qualified outside firm† (a QSA) audit you for PCI compliance. But those audits are notoriously superficial; PCI audits are a race-to-the-bottom affair. † We are not one of those.
Re: Linode hacked, CCs and passwords leaked
#78I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915
Not sure how useful that reset was. All I had to do was type in my old password and then choose a new one. No email verification, no reset token, nothing. So if the password was indeed compromised, couldn't the attacker do the same?
Re: Linode hacked, CCs and passwords leaked
#79Re: Linode hacked, CCs and passwords leaked
#80Earlier quoted context omitted.
Better rely on someone who's sole job is securing that info than doing it yourself.
Storing credit card info just helps make you a bigger target. If your a small company, better let someone else store card info, let them be the target. Also you're fined by the credit card companies if you lose card information. I believe it's a per card fine, so it get expensive really quickly. Actually I don't get why any company would choose to store credit card information, when most payment providers will do it…