Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

71–80 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#71
post #36
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

This is ridiculously unprofessional.

Re: Linode hacked, CCs and passwords leaked

#72
post #62

Earlier quoted context omitted.

So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…

You missed the step where you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process! Kind of sucks to have to spend hours doing that for someone else's oversight. It's not the end of the world, but it paints a clear picture about where a company's priorities…

Maybe I'm weird, but I know exactly which binding credit agreements I'm in and how they're paid, and definitely none of them get paid using another binding credit agreement. :)

Re: Linode hacked, CCs and passwords leaked

#74

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

Re: Linode hacked, CCs and passwords leaked

#75
post #18
post #13

Earlier quoted context omitted.

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

Extensive PCI audits. Heh.

Like the "scan" that said our linux boxes were running an out-of-date version of IIS.

Re: Linode hacked, CCs and passwords leaked

#76
post #44

Earlier quoted context omitted.

Actually, if you're processing cards directly, you do in fact need to have an PCI-qualified outside firm† (a QSA) audit you for PCI compliance. But those audits are notoriously superficial; PCI audits are a race-to-the-bottom affair. † We are not one of those.

Every one of these reviews that I've been involved in has been conducted by a couple of guys with laughable abilities.

The quality of PCI security audits is a continual aggravation to everyone I routinely talk to in my industry. I've told more than one client: if you need a QSA audit, get the cheapest one you can. If you need a software security assessment, don't use a QSA firm.

Re: Linode hacked, CCs and passwords leaked

#77
post #44

Earlier quoted context omitted.

I've done PCI "audits" for several companies I've worked for; it's a checklist you go down yourself . That's why its called a "pci self assessment".

Actually, if you're processing cards directly, you do in fact need to have an PCI-qualified outside firm† (a QSA) audit you for PCI compliance. But those audits are notoriously superficial; PCI audits are a race-to-the-bottom affair. † We are not one of those.

Note that you hire those firms yourself, and they work for you. They want you to pass the audit and will work to make that happen.

Re: Linode hacked, CCs and passwords leaked

#78
post #42

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not sure how useful that reset was. All I had to do was type in my old password and then choose a new one. No email verification, no reset token, nothing. So if the password was indeed compromised, couldn't the attacker do the same?

It addresses the "attacker has a list of hashes that'll take him a while to compute matches for" aspect of things.

Re: Linode hacked, CCs and passwords leaked

#79
post #61

Earlier quoted context omitted.

Switched to https://www.digitalocean.com/ last week. Excellent service and pricing.

Yeah, a week sounds like plenty of time to assess a hosting provider.

Oh, and the years of Linode assessment were adequate?

Re: Linode hacked, CCs and passwords leaked

#80

Earlier quoted context omitted.

Better rely on someone who's sole job is securing that info than doing it yourself.

Storing credit card info just helps make you a bigger target. If your a small company, better let someone else store card info, let them be the target. Also you're fined by the credit card companies if you lose card information. I believe it's a per card fine, so it get expensive really quickly. Actually I don't get why any company would choose to store credit card information, when most payment providers will do it…

Stripe is amazing... I trust them, someone hacks me, awesome, you got password hashes and stripe customer keys, all worthless.
Post reply on HN