Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

81–90 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#83
Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co. responds by replying back with authorization and an ID unique to that vendor that says "Use this number for charging this customer again, but it will only work coming from you, so if you lose it, it can't be used elsewhere". The vendor then discards your real CC number.

Re: Linode hacked, CCs and passwords leaked

#85

Well I'll wait for a response from linode, but it certainly looks like they were very dishonest. I think I will close my account.

So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…

To dismiss this breach seems odd to me. The tech community in general has placed a lot of trust and faith in Linode over the years. The shareowners at Linode have surely been great beneficiaries to that. Part of that "unspoken agreement", if you will, is that Linode be competent at what they do and that means keeping your data and information secure.

If even an iota of what I read in the abridged IRC log is true, Linode doesn't seem to care much about security or protecting Linode customer data. I mean, storing "encrypted" card numbers alongside private/public keys? Really.

Re: Linode hacked, CCs and passwords leaked

#86

So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.

I think we should really wait to hear from Linode until we completely dismiss them, at least.

Re: Linode hacked, CCs and passwords leaked

#87
Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers.

I've been living comfortably on Linode servers for over three years. This is like suddenly being evicted and having to pack my stuff up and find another apartment.

I have to wait for some sort of verification for this but if true then I have to leave Linode. I have client sites hosted here - not for cost reasons, just because I like Linode.

For the sake of $5 a month I can't even take the slightest risk of being criticised for using Linode. And this lack of transparency could be a nail in the coffin here.

I don't want to waste a couple of days on this but that's what's going to be involved if this is true.

Re: Linode hacked, CCs and passwords leaked

#88

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Nothing on my UK Mastercard.

Re: Linode hacked, CCs and passwords leaked

#89
post #36
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

These guys are looking totally incompetent at this point.

If you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email?

"You are of course free to take any steps you deem prudent or necessary to ensure the integrity of your online presence."

Unbelievable.

Edit: not to mention they "made a deal" with the hacker not to tell anyone? What the hell?

Re: Linode hacked, CCs and passwords leaked

#90

So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.

That's pretty much how trust works.

I'd give another trust vote to Linode, anyway this could happen to anyone.
Post reply on HN