Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

201–210 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#201
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.

No weird activity here (no declined transactions or anything)

Mine is not a CC or a debit card, it's a 'prepayed card' so liability is limited.

Still, I'm considering calling the lost/stolen line of the card.

Re: Linode hacked, CCs and passwords leaked

#202

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

Either this, or a assignable CVV codes. Something like that would be awesome.

Re: Linode hacked, CCs and passwords leaked

#203

Earlier quoted context omitted.

Switched to https://www.digitalocean.com/ last week. Excellent service and pricing.

Until they're hacked, too...

Or until they let other customers see all the data on VMs that you've shut down. Oh wait, that already happened: http://www.wired.com/wiredenterprise/2013/04/digitalocean/

Re: Linode hacked, CCs and passwords leaked

#205
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.

[deleted]

Re: Linode hacked, CCs and passwords leaked

#206
post #199

FYI, I just learned from Linode support that accounts have both a default LISH password AND a default API key, which means that even if you've never set a LISH password or generated an API key before , you still should still go and reset them. This is not what I would consider expected or desirable behavior.

Hacker News, wherein I find further motivation to immediately get my off-site services off of Linode...

Re: Linode hacked, CCs and passwords leaked

#207

Earlier quoted context omitted.

To dismiss this breach seems odd to me. The tech community in general has placed a lot of trust and faith in Linode over the years. The shareowners at Linode have surely been great beneficiaries to that. Part of that "unspoken agreement", if you will, is that Linode be competent at what they do and that means keeping your data and information secure. If even an iota of what I read in the abridged IRC log is true, Lin…

Sigh, really? Ok, you typed your credit card number into a web browser at some point. If your sole reason for doing so was "I absolutely trust the people on the other end of this socket not to do what 99% of all people handling credit card data do whether they pretend otherwise or not", instead of something like "hmm that reminds me, I haven't scanned last month's statement yet", then the problem lies squarely with y…

So because companies A through X are irresponsible with data, customers should regard that as acceptable and give company Y a free pass to do the same? I don't understand how a reasonable analysis of the situation can come to that conclusion.

Re: Linode hacked, CCs and passwords leaked

#208

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

Visa have this (probably others too) that you can generate and either set a time or value limit on. Don't think you can set a monthly limit though unfortunately. They call it e-cards (in sweden at least).

Re: Linode hacked, CCs and passwords leaked

#209

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

Bank of America provides this [1], as does Citibank [2] and likely others.

Paypal at one time provided this service as well, but it doesn't seem to anymore [3]

1: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...

2: https://www.citibank.com/us/cards/gen-content/messages/van/i...

3: https://www.paypal.com/va/webapps/mpp/security/general-freet...

Re: Linode hacked, CCs and passwords leaked

#210

The chatlog does provide some evidence that it is indeed the hacker, but does little to convince me that he got CC info and Linode is not telling us the whole truth. The evidence he provides is just simple source code snips and the directory listing, which would be expected based on what Linode has told us. This could very well be the hackers own submission to /. trying to get more attention for his hack by claiming…

Except Linode didn't tell us that. Linode said it was a downstream customer's info that was compromised. Nothing about Linode itself.
Post reply on HN