Just rang my bank to cancel my debit card. Hate doing that. Now I have a week or two of failing payments, bills, etc to look forward to. I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic…
Linode hacked, CCs and passwords leaked
221–230 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#222I had a VPS on linode. I think that Linode did a big mistake here. Let's wait for a formal communication. But this is the moment to support them. Yes, maybe sounds crazy. When you host on any third party datacenter, you take risks that something like this could happen. So, deal with it. Check your credit card, if your receive something wrong, call to your card and that's all. But we need to support also the good work…
Well said. It's a fact of life that companies get hacked. So it's no surprise that it eventually happened to Linode. If you flee somewhere else, all you're doing is hoping that the other company you run to won't get hacked rather than using any logical thought. I can think of two good reasons why you should flee Linode. It remains to be seen if either are actually true, and until indications say yes, then panic is un…
Linode's handling of the Bitcoin incident last year was sub-optimal. This too has been sub-optimal, given that credit cards were exposed but all we heard on Friday was to change our passwords, and even that was claimed to just be a super-careful precaution.
Linode needs to start giving us some frank talk ASAP. They've already burned through a very generous helping of benefit-of-the-doubt.
Re: Linode hacked, CCs and passwords leaked
#223Earlier quoted context omitted.
dd if=/dev/sda bs=1M | ssh root@ dd of=/dev/sda bs=1M let SSH handle compression for you instead.
That is one (good) way to handle the encryption. You don't want to leave out the compression or block size however, so add those back in. Most WAN links are low bandwidth enough that compression will not slow things down (this is usually true even on 1 GBE LAN links for pigz ) and in my experience the speed-up is substantial. pigz is much faster than using ssh compression as it is multicore. apt-get it or http://zlib…
Re: Linode hacked, CCs and passwords leaked
#224Earlier quoted context omitted.
Quite. I like the company and their servers are good - but we need a detailed response, and we need one now.
I'd say support tickets or posting on their forum[1] may help try to get a response. But based one one of the support ticket responses posted in the comments in this HN story already, it sounds like Linode isn't allowed to release that kind of information yet. They may be waiting on the police and/or their lawyers to allow them to talk publicly about it. And if that isn't the gating factor, they are probably trying t…
Waiting for their own lawyers would be a particularly weak excuse. This is a priority, and they are responsible from conveying that urgency to their lawyers.
Re: Linode hacked, CCs and passwords leaked
#225Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.
Re: Linode hacked, CCs and passwords leaked
#226Earlier quoted context omitted.
> Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? You really really don't have to. Any payment processor that isn't horribly incompetent does the unique token authorization scheme. Storing CC #s for recurring payments is solely the domain of incompetents who have no business accepting payments from anyone.
What if you want to change processors? If you weren't storing the CC details, wouldn't you have to have customers enter all their details again? I imagine this could cause a drop in revenues due to people either forgetting, procrastinating, or just not bothering. It's never cool to be actually- or quasi-locked into a vendor.
Re: Linode hacked, CCs and passwords leaked
#227I wonder if they've deleted CC details of previous clients. Is Linode going to contact all relevant customers? Seems like the right thing to do. Not everyone reads HN.
Re: Linode hacked, CCs and passwords leaked
#228Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.
Bank of America provides this [1], as does Citibank [2] and likely others. Paypal at one time provided this service as well, but it doesn't seem to anymore [3] 1: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... 2: https://www.citibank.com/us/cards/gen-content/messages/van/i... 3: https://www.paypal.com/va/webapps/mpp/security/general-freet...
> Set your Valid through date for up to 1 year in the future
I'd really like it to be up to the expiration date of my card. It's probably worth doing anyway, I suppose. Thanks for the heads up. Given the zero-liability status, I'm surprised that banks don't promote this feature more visibly.
Re: Linode hacked, CCs and passwords leaked
#229Really off-topic, but still sad: This is a link to slashdot, but it's on HN's frontpage before it's on slashdot's front-page (if it'll ever get there). (And IMHO that's sad, because /. used to be top notch). I've noticed before that stuff from the HN frontpage appears on /. one to three days after, but I've never seen it for links to slashdot :-)
Also off-topic: I've noticed that as well with Slashdot, which is why I lurk HN pretty regularly now. Plus, some of the front page material on /. does more to insight angry discussion, and the community has become increasingly more vitriolic.
At least here, even if someone's brash, they're fairly honest about it (in general). I've even seen a number of disagreements that have been respectful and cordial. It's sad to say, but that's a rare thing these days.
Re: Linode hacked, CCs and passwords leaked
#230http://linode.com/googledebcc14d3c9f777a.html and http://linode.com/y_key_57284cb2de704e02.html
If not, it seems likely that he did have read access to the main website filesystem at least