Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

161–170 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#161
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

What about for people who did not use a credit card to pay for linode but instead relied on PayPal. Should they follow the same steps? What about other cautious steps?

I don't think they allow paypal as a payment method

Re: Linode hacked, CCs and passwords leaked

#162

Earlier quoted context omitted.

"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.

What are they supppose to say? Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked??? It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COM…

If the information he offered is accurate (e.g. the public and private keys were stored together on the webserver), that wouldn't take a long time to confirm.

Re: Linode hacked, CCs and passwords leaked

#163
post #129
post #96

Earlier quoted context omitted.

That's what Stripe do.

But isn't that just between Stripe and the company requesting payment? e.g: Acme, Inc. sends Stripe your CC#, Stripe sends them some unique token, and they store that; correct? So Stripe still has your CC#, and is at risk. So this is really just risk mitigation; what I think TP is suggesting we need is unique authorizations at the banking level. Something on the order of virtual credit cards, or temporary tokens, whi…

No. Customer sends Stripe their CC number, via AJAX in the browser. Acme, Inc. never has it even transiently. Stripe return a token to the browser, which is sent in a POST to Acme, Inc., then they verify it server side with a private API key.

Edit: yes Stripe has your number, but since their sole business is about securing that information, they probably do a better job of it than your typical online merchant.

Re: Linode hacked, CCs and passwords leaked

#164
post #58

To those of you who have claimed that your CCs have been abused -- I checked mine (which I used to pay for Linode) and it hasn't been used to do anything funny.

I checked mine and nothing untoward has taken place. All the same, I put it on hold. Everyone should assume their CC is compromised.

Why? It is a major waste of time to insert it into all the places that I have used it and should it be abused, then I just dispute the charges.

Re: Linode hacked, CCs and passwords leaked

#165

Earlier quoted context omitted.

Even better to use someone that isn't your payment processor, so that should you need to change payment processors you don't also have to re-acquire all the billing info from your customers. You can use Stripe today, PayPal tomorrow, and Braintree the next if that's what works best for your business. Card vaulting as a service: https://spreedly.com/ ($10/mo for up to 5000 cards)

Isn't that just adding one more point of failure? I don't trust myself, I barely trust Stripe or Paypal, and I've not even heard of spreedly.

There's always going to be single points of failure, but which is more likely: you want or have to change payment processors (you've been terminated, your fees have gone up, you want to switch to a lower cost provider) or you want to change flat-rate vaulting services? Plus, Spreedly will give you your data if you leave, whereas there is no way to get stored billing info out of most payment processors.

Re: Linode hacked, CCs and passwords leaked

#166

Earlier quoted context omitted.

So you're unfortunate enough to be a customer who had their CC leaked. So you spend 5 minutes changing your password (you use unique, non-formulaic passwords, right?) and 15 minutes on the phone to CC company to ask for a new card. Then you use your backup card for 2 weeks (you have a backup card, right?) A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared. Not the end o…

To dismiss this breach seems odd to me. The tech community in general has placed a lot of trust and faith in Linode over the years. The shareowners at Linode have surely been great beneficiaries to that. Part of that "unspoken agreement", if you will, is that Linode be competent at what they do and that means keeping your data and information secure. If even an iota of what I read in the abridged IRC log is true, Lin…

Sigh, really? Ok, you typed your credit card number into a web browser at some point. If your sole reason for doing so was "I absolutely trust the people on the other end of this socket not to do what 99% of all people handling credit card data do whether they pretend otherwise or not", instead of something like "hmm that reminds me, I haven't scanned last month's statement yet", then the problem lies squarely with you, the uninformed consumer.

I will happily dismiss this breach, not because they didn't make some amateur crypto mistake, or because they weren't using freaking ColdFusion, or because they were storing data in some nice compartmentalized form, I reject because this happens every single day and has done for decades, and there is an entire sub-industry built around its after-effects. If you don't understand this you shouldn't own a credit card.

If you type a credit card number in online not expecting to recuperate any damage caused from your card company, call them up now for clarification or cancel the damn card. That's equivalent to stuffing cash in an envelope and posting it to Nigeria because some prince promises he'll keep it in a safe for you. It's 90% the reason you should be using credit cards in the first place. Think.

Linode should not be rubbished here. They've got one of the largest VPS installs around, so they most likely know their shit. They make an ultra-common CC mistake that has happened daily for almost 20 years now, by companies large and small, got pwned due to a bug in someone else's software, and you think I'm going to play along with the righteous indignation bullshit here? GTFO.

Let he without sin cast the first stone. Despite 20+ years' experience I still cannot cast that first stone. I make bullshit mistakes like this every day, and despite your grandiose delusions you probably do too.

As for whiners complaining about their data suddenly being insecure, well, data security 101: you're making the same bullshit mistake Linode are making, and despite that you're complaining about it. If you care about data security in the "cloud", hosting it on a freaking VPS is not the way to do things.

Re: Linode hacked, CCs and passwords leaked

#167

Earlier quoted context omitted.

I'm pretty sure that depends on who issued your card. Visa has a zero liability program for debit card - http://usa.visa.com/personal/security/visa_security_program/... These are the FTC's rules [1], I'm not sure if Visa or Mastercard can make them 'better' (give you a larger window). They have an interesting tidbit below their chart - >If someone makes unauthorized transactions with your debit card number, but your…

Generally these days they are, but the problem is the money is removed is from your account by the time the charge appears, (at least a period of time), whereas on a credit card you have 30 days to review charges. This could cause overdrafts, etc. depending on timing and amount. Those too can generally be reversed, but the whole thing becomes more of a headache. I never use debit cards for any kind of recurring charg…

The same is possible with a credit card - you can have your card maxed, get nailed with overage charges, declined transactions, etc. It's still a headache, but when I've had it happen to me I think I had the money restored within a few minutes of making the call.

Re: Linode hacked, CCs and passwords leaked

#168

Earlier quoted context omitted.

Despite what the other replies here are saying, this seems like a perfectly acceptable response to me. This comes off to me not as they're refusing to talk about it, but they _can't_ talk about it, presumably because of an ongoing investigation. I'm not sure what else people here are expecting them to say.

Then why not say that?

They did.

> We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation.

Re: Linode hacked, CCs and passwords leaked

#169
post #70

I had a VPS on linode. I think that Linode did a big mistake here. Let's wait for a formal communication. But this is the moment to support them. Yes, maybe sounds crazy. When you host on any third party datacenter, you take risks that something like this could happen. So, deal with it. Check your credit card, if your receive something wrong, call to your card and that's all. But we need to support also the good work…

Well said. It's a fact of life that companies get hacked. So it's no surprise that it eventually happened to Linode. If you flee somewhere else, all you're doing is hoping that the other company you run to won't get hacked rather than using any logical thought. I can think of two good reasons why you should flee Linode. It remains to be seen if either are actually true, and until indications say yes, then panic is un…

Linode has already grossly mishandled the situation by not coming out with a complete statement about what exactly happened. I only read this news because it was posed here -- no email notification, no update on their homepage, no twitter, no nothing.

The alleged hacker has made serious and specific claims, and Linode has done jack shit; without more information, how should I proceed? I don't want to call my bank and waste time getting a new credit card (not to mention replacing a million and two services) without a confirmation and I can't get a confirmation because Linodes people are having a circle jerk (or whatever the hell they do).

Post reply on HN