Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

131–140 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#131
post #74

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

They are. Protections are exactly the same (in the US at least.) You have protection from the moment that you learn of the problem, not when it happens.

Not that having your account drained doesn't suck, but your worst case scenario there isn't terrible unless you fail to check stuff and be responsible.

Re: Linode hacked, CCs and passwords leaked

#132

If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…

Two alternatives often mentioned on here are DigitalOcean and RamNode. I've only used DigitalOcean. My anecdotal experience from running a Chef Server on a 1GB instance has been pretty mixed. The price is good, but network and CPU performance feels very variable to me. A month ago their Amsterdam servers were unable to be resized, and there was nothing about it on their status page. I tweeted and was told they'd be w…

>But, if this breach is true, I hope they handle it well.

That is unfortunately the problem though. If this is true, they have already handled it terribly as it has already been 2 weeks since the attack.

Re: Linode hacked, CCs and passwords leaked

#133
post #111

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

What about for people who did not use a credit card to pay for linode but instead relied on PayPal. Should they follow the same steps? What about other cautious steps?

Re: Linode hacked, CCs and passwords leaked

#134
post #36
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

Despite what the other replies here are saying, this seems like a perfectly acceptable response to me. This comes off to me not as they're refusing to talk about it, but they _can't_ talk about it, presumably because of an ongoing investigation. I'm not sure what else people here are expecting them to say.

Re: Linode hacked, CCs and passwords leaked

#135
post #83

Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…

> Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments?

You really really don't have to. Any payment processor that isn't horribly incompetent does the unique token authorization scheme.

Storing CC #s for recurring payments is solely the domain of incompetents who have no business accepting payments from anyone.

Re: Linode hacked, CCs and passwords leaked

#136

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Anyone know of any good way to export linode images to other VPS providers? Seems like I'll have to be doing it manually.

Re: Linode hacked, CCs and passwords leaked

#137

If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…

I've been using digitalocean for a hobby project, and am planning on launching a more serious project with them. For the past two months I've used them (so, not much experience, but some) I haven't had any issues, and they are very reasonably priced.

Re: Linode hacked, CCs and passwords leaked

#138

Earlier quoted context omitted.

"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.

What are they supppose to say? Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked??? It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COM…

They could say "We have hired matasano security to help us investigate the breach."

Re: Linode hacked, CCs and passwords leaked

#139

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Anyone know of any good way to export linode images to other VPS providers? Seems like I'll have to be doing it manually.

Generally speaking, this is one example where having a good deployment system starts to look extremely valuable (along with tested backups and restores for non-deployed data).

Re: Linode hacked, CCs and passwords leaked

#140

Hmmm, Linode claims they emailed their customers about the password reset, but I never got an email (nor in my spam folder)

Saturday morning:

    From: "Linode" 
    Date: Sat, 13 Apr 2013 00:11:09 -0000
    Precedence: bulk
    Return-Path: 6723614.1706014@e2ma.net
    Message-ID: 
    List-Unsubscribe: 
    X-Test-Mailing: no

    Dear Linode customer,

    Linode administrators have discovered and blocked suspicious activity on th=
    e Linode network.=C2=A0 This activity appears to have been a coordinated at=
    tempt to access the account of one of our customers.=C2=A0 This customer is=
     aware of this activity and we have determined its extent and impact.=C2=A0=
     We have found no evidence that any Linode data of any other customer was a=
    ccessed.=C2=A0 In addition, we have found no evidence that payment informat=
    ion of any customer was accessed.

    We have been advised that law enforcement officials are aware of the intrus=
    ion into this customer=E2=80=99s systems. We have implemented all appropria=
    te measures to provide the maximum amount of protection to our customers. O=
    ut of an abundance of caution, however, we have decided to implement a Lino=
    de Manager password reset. In so doing, we have immediately expired all cur=
    rent passwords. You will be prompted to create a new password the next time=
     that you log into the Linode Manager. We also recommend changing your LISH=
     passwords and, if applicable, regenerating your API key.

    The following represent best practices in creating new passwords:
    -- Avoid using simple passwords based on dictionary words
    -- Never use the same password on multiple sites or services
    -- Never click on 'reset password' requests in unsolicited emails - instead=
     go directly to the service

    We apologize for the inconvenience. If you have any questions, please do no=
    t hesitate to contact our support team at support@linode.com.
Post reply on HN