Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

91–100 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#91
post #74

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

Debit cards have less protection.

Wouldn't hurt just to ask your bank to re-authorise it anyway? It will change the three digits on the back.

Re: Linode hacked, CCs and passwords leaked

#93

I'm looking forward to seeing an official response from Linode on this. Hopefully they are fast and honest about it. I've been a happy customer for quite a while, but this is definitely a concern.

They weren't exactly fast and honest the last time a break-in happened. In fact even to this day nobody is quite sure what went down aside from tons of Bitcoins going missing!

Re: Linode hacked, CCs and passwords leaked

#94

Well I'll wait for a response from linode, but it certainly looks like they were very dishonest. I think I will close my account.

So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…

The fact of the matter is that OP shouldn't have to deal with any of that. No matter how much an inconvenience, it's still an inconvenience.

Re: Linode hacked, CCs and passwords leaked

#95

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Quite. I like the company and their servers are good - but we need a detailed response, and we need one now.

Re: Linode hacked, CCs and passwords leaked

#96
post #83

Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…

That's what Stripe do.

Re: Linode hacked, CCs and passwords leaked

#97
post #18
post #13

Earlier quoted context omitted.

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

Extensive PCI audits. Heh.

That compliance web form I absentmindedly clicked through sure had a lot of buttons.

Re: Linode hacked, CCs and passwords leaked

#98
Is this why Linode doubled the RAM? To bribe us and make us stay. I'm pretty pissed off about this and will be exploring other options. I'm not pissed off they got hacked, I'm pissed off they are hiding and not being forth coming about it. A simple, "We fucked up, we are going to take steps 1, 2 3 to fix it and reduce the likely hood of this ever happening again" will make me happy. I understand that any server can be hacked. I'm stunned that they are storing CC details on the servers, there are ways to go about this without storing them if you want recurring billing.

Re: Linode hacked, CCs and passwords leaked

#100
post #36
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

That is not the way to handle this issue. I've found my one problem with Linode is they are arrogant. It comes off pretty strong if you ever ask them questions in chat.
Post reply on HN