Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

101–110 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#101

Is there any confirmation on this? [edit] Just looked at twitter, this tweet doesn't look good: https://twitter.com/Jamiesingleton/status/322730588459114500 But it may just be random coincidence. [edit again] Links from slashdot article: IRC chat: http://turtle.dereferenced.org/~nenolod/linode/linode-abridg... Link in IRC chat (i think it is of linode.com's web directory): https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc

There's URLs in the leak that could never have been guessed, like http://www.linode.com/y_key_57284cb2de704e02.html (mentioned by Tomdarkness above).

Re: Linode hacked, CCs and passwords leaked

#102

Earlier quoted context omitted.

Until they have a security breach.

Better rely on someone who's sole job is securing that info than doing it yourself.

But you still might need to consider data residency issues and making your customers aware of where their data is being stored.

Re: Linode hacked, CCs and passwords leaked

#103

Earlier quoted context omitted.

That's totally shit. Its also why we invoice and take wire payments rather than storing CC details. There's just so much to go wrong. Also PKI is shit for this sort of thing. As demonstrated, the moment that public key is gone, then the whole system falls like a house of cards. For the non believers of this fact, why else would there be a certificate revocation list and root CA updates for windows periodically...

Using a processor who stores the card number outside of your infrastructure (ie. Stripe) can also be helpful.

Even better to use someone that isn't your payment processor, so that should you need to change payment processors you don't also have to re-acquire all the billing info from your customers. You can use Stripe today, PayPal tomorrow, and Braintree the next if that's what works best for your business.

Card vaulting as a service: https://spreedly.com/ ($10/mo for up to 5000 cards)

Re: Linode hacked, CCs and passwords leaked

#104
post #62

Earlier quoted context omitted.

You missed the step where you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process! Kind of sucks to have to spend hours doing that for someone else's oversight. It's not the end of the world, but it paints a clear picture about where a company's priorities…

Maybe I'm weird, but I know exactly which binding credit agreements I'm in and how they're paid, and definitely none of them get paid using another binding credit agreement. :)

I mean, I know all that I'm in, but I can definitely see myself missing one or two if asked on the spot to recall all of them. Phone, cable, AWS, gym, power, garbage/etc, insurance,... I'm sure there are one or two others. Even if there aren't, I'd feel compelled to go through everything to make sure there aren't more.

Even just dealing with all of those is going to be a pain in the ass though. I'd probably end up spending hours all together just on hold with some of those people.

Edit: Netflix. I forgot Netflix.

Re: Linode hacked, CCs and passwords leaked

#105
post #58

To those of you who have claimed that your CCs have been abused -- I checked mine (which I used to pay for Linode) and it hasn't been used to do anything funny.

I checked mine and nothing untoward has taken place. All the same, I put it on hold. Everyone should assume their CC is compromised.

Re: Linode hacked, CCs and passwords leaked

#106

Earlier quoted context omitted.

Don't be so logical please. This can happend to anyone in the industry.

"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.

What are they supppose to say?

Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked???

It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COMPANY for all we know and looking to scare people off Linode) should be taken with a grain of salt.

Re: Linode hacked, CCs and passwords leaked

#107
post #74

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

I'm pretty sure that depends on who issued your card.

Visa has a zero liability program for debit card - http://usa.visa.com/personal/security/visa_security_program/...

These are the FTC's rules [1], I'm not sure if Visa or Mastercard can make them 'better' (give you a larger window). They have an interesting tidbit below their chart -

>If someone makes unauthorized transactions with your debit card number, but your card is not lost, you are not liable for those transactions if you report them within 60 days of your statement being sent to you.

Isn't it free to get a new card? That'd be the easier way than worrying.

[1] http://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cre...

Re: Linode hacked, CCs and passwords leaked

#108

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not only that, it also makes me wonder about the free RAM upgrade from almost a week ago. Some people are reporting their Linode credit cards being used for fraudulent purchases as far as a week ago, so this might have been a move to gain some pre-emptive goodwill. I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.

I believe that to be a coincidence. They have been performing upgrades for a while now. (Increased hard drive space, increased CPU, and finally increased ram.)

I think it was just an unfortunately timed third phase of their upgrade plan.

Re: Linode hacked, CCs and passwords leaked

#109

Really off-topic, but still sad: This is a link to slashdot, but it's on HN's frontpage before it's on slashdot's front-page (if it'll ever get there). (And IMHO that's sad, because /. used to be top notch). I've noticed before that stuff from the HN frontpage appears on /. one to three days after, but I've never seen it for links to slashdot :-)

I've noticed the same thing for almost every tech-related subreddit, especially /r/startups and /r/programming. A consistent 2-3 day lag.

Re: Linode hacked, CCs and passwords leaked

#110
post #83

Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…

Depends on what part of the chain you are. Most gateways/processors offer some sort of token that the end user uses.

You then put your trust in the gateway/processor to store the credit card. Which I assume is most likely behind the best possible security stuff money can afford. Since that's their entire business. One screw up and their gone.

Post reply on HN