Earlier quoted context omitted.
Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…
These guys are looking totally incompetent at this point. If you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email? "You are of course free to take any steps you deem prudent or necessary to ensure the integrity…
Linode hacked, CCs and passwords leaked
151–160 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#152So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.
Re: Linode hacked, CCs and passwords leaked
#153That may explains the seclist hack too... http://seclists.org/nmap-dev/2013/q2/3
Re: Linode hacked, CCs and passwords leaked
#154Earlier quoted context omitted.
Storing credit card info just helps make you a bigger target. If your a small company, better let someone else store card info, let them be the target. Also you're fined by the credit card companies if you lose card information. I believe it's a per card fine, so it get expensive really quickly. Actually I don't get why any company would choose to store credit card information, when most payment providers will do it…
Stripe is amazing... I trust them, someone hacks me, awesome, you got password hashes and stripe customer keys, all worthless.
But yes, significantly better than other situations.
Re: Linode hacked, CCs and passwords leaked
#155Well I'll wait for a response from linode, but it certainly looks like they were very dishonest. I think I will close my account.
So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…
Re: Linode hacked, CCs and passwords leaked
#156Re: Linode hacked, CCs and passwords leaked
#157Earlier quoted context omitted.
Using a processor who stores the card number outside of your infrastructure (ie. Stripe) can also be helpful.
Even better to use someone that isn't your payment processor, so that should you need to change payment processors you don't also have to re-acquire all the billing info from your customers. You can use Stripe today, PayPal tomorrow, and Braintree the next if that's what works best for your business. Card vaulting as a service: https://spreedly.com/ ($10/mo for up to 5000 cards)
Re: Linode hacked, CCs and passwords leaked
#158Re: Linode hacked, CCs and passwords leaked
#159So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.
Re: Linode hacked, CCs and passwords leaked
#160Earlier quoted context omitted.
Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.
Debit cards have less protection. Wouldn't hurt just to ask your bank to re-authorise it anyway? It will change the three digits on the back.