Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

151–160 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#151
post #89
post #36

Earlier quoted context omitted.

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

These guys are looking totally incompetent at this point. If you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email? "You are of course free to take any steps you deem prudent or necessary to ensure the integrity…

Regarding the "made a deal" assertion, I wouldn't take the IRC log hook-line-and-sinker. There's probably a mixture of truth and lies.

Re: Linode hacked, CCs and passwords leaked

#152

So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.

Seems like it usually takes an event like this for a company to really crack down on their security practices. I would wager that Linode will be one of the most secure providers in the coming months. Whether or not people will trust them is another story.

Re: Linode hacked, CCs and passwords leaked

#154

Earlier quoted context omitted.

Storing credit card info just helps make you a bigger target. If your a small company, better let someone else store card info, let them be the target. Also you're fined by the credit card companies if you lose card information. I believe it's a per card fine, so it get expensive really quickly. Actually I don't get why any company would choose to store credit card information, when most payment providers will do it…

Stripe is amazing... I trust them, someone hacks me, awesome, you got password hashes and stripe customer keys, all worthless.

Not exactly worthless, depending on the hack someone could still charge an awful lot to your customers and make you have a bad day.

But yes, significantly better than other situations.

Re: Linode hacked, CCs and passwords leaked

#155

Well I'll wait for a response from linode, but it certainly looks like they were very dishonest. I think I will close my account.

So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…

In the real world our time matters, sadly wasting it is not something you can sue over.

Re: Linode hacked, CCs and passwords leaked

#157

Earlier quoted context omitted.

Using a processor who stores the card number outside of your infrastructure (ie. Stripe) can also be helpful.

Even better to use someone that isn't your payment processor, so that should you need to change payment processors you don't also have to re-acquire all the billing info from your customers. You can use Stripe today, PayPal tomorrow, and Braintree the next if that's what works best for your business. Card vaulting as a service: https://spreedly.com/ ($10/mo for up to 5000 cards)

Isn't that just adding one more point of failure? I don't trust myself, I barely trust Stripe or Paypal, and I've not even heard of spreedly.

Re: Linode hacked, CCs and passwords leaked

#159

So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.

[Warning: imperfect analogy follows.] It's one thing if Linode is like someone who gets drunk and crashes their vehicle. That's 100% their fault and they've burned any goodwill. In this case, however, Linode is like someone who was carjacked. Perhaps Linode shouldn't have been driving that type of vehicle in an area known to have people attempting to carjack every single vehicle that drives by. Perhaps they should have installed thicker bullet-proof glass. Or even have taken measures not to trust any locks that the manufacturer insists are secure but have zero-day exploits. Regardless, Linode is still the victim of unscrupulous criminals. Maybe they could and should have done more but the bigger question is now that they've been carjacked, what are they doing to ensure that the carjackers haven't installed anything malicious that still remains in the vehicle?

Re: Linode hacked, CCs and passwords leaked

#160
post #74

Earlier quoted context omitted.

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

Debit cards have less protection. Wouldn't hurt just to ask your bank to re-authorise it anyway? It will change the three digits on the back.

They don't, protections are exactly the same.
Post reply on HN