Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

221–230 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#221

Just rang my bank to cancel my debit card. Hate doing that. Now I have a week or two of failing payments, bills, etc to look forward to. I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic…

There's nothing wrong with ColdFusion, especially if you've had it around for a while. It's not as glitzy as Rails, but it works and it's still supported and modern. Besides, this isn't ColdFusion's fault. Leave because Linode violated your trust, but not because of the programming language they wrote their site in.

Re: Linode hacked, CCs and passwords leaked

#222
post #70

I had a VPS on linode. I think that Linode did a big mistake here. Let's wait for a formal communication. But this is the moment to support them. Yes, maybe sounds crazy. When you host on any third party datacenter, you take risks that something like this could happen. So, deal with it. Check your credit card, if your receive something wrong, call to your card and that's all. But we need to support also the good work…

Well said. It's a fact of life that companies get hacked. So it's no surprise that it eventually happened to Linode. If you flee somewhere else, all you're doing is hoping that the other company you run to won't get hacked rather than using any logical thought. I can think of two good reasons why you should flee Linode. It remains to be seen if either are actually true, and until indications say yes, then panic is un…

> 2. If Linode grossly mishandles the situation. There have been a couple of allegations to that effect so far, but nothing substantial. I don't see any reason to claim that they've done this yet.

Linode's handling of the Bitcoin incident last year was sub-optimal. This too has been sub-optimal, given that credit cards were exposed but all we heard on Friday was to change our passwords, and even that was claimed to just be a super-careful precaution.

Linode needs to start giving us some frank talk ASAP. They've already burned through a very generous helping of benefit-of-the-doubt.

Re: Linode hacked, CCs and passwords leaked

#223

Earlier quoted context omitted.

dd if=/dev/sda bs=1M | ssh root@ dd of=/dev/sda bs=1M let SSH handle compression for you instead.

That is one (good) way to handle the encryption. You don't want to leave out the compression or block size however, so add those back in. Most WAN links are low bandwidth enough that compression will not slow things down (this is usually true even on 1 GBE LAN links for pigz ) and in my experience the speed-up is substantial. pigz is much faster than using ssh compression as it is multicore. apt-get it or http://zlib…

the compression is unnecessary here, you're moving a max of less than a couple of hundred GB of data.

Re: Linode hacked, CCs and passwords leaked

#224
post #112

Earlier quoted context omitted.

Quite. I like the company and their servers are good - but we need a detailed response, and we need one now.

I'd say support tickets or posting on their forum[1] may help try to get a response. But based one one of the support ticket responses posted in the comments in this HN story already, it sounds like Linode isn't allowed to release that kind of information yet. They may be waiting on the police and/or their lawyers to allow them to talk publicly about it. And if that isn't the gating factor, they are probably trying t…

They may be waiting on the police and/or their lawyers to allow them to talk publicly about it.

Waiting for their own lawyers would be a particularly weak excuse. This is a priority, and they are responsible from conveying that urgency to their lawyers.

Re: Linode hacked, CCs and passwords leaked

#225

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

The portuguese ATM network operator provides this for free (its called mbnet btw). You can even set expiry times and value limit, it's the best thing to use when paying for stuff online. Want to buy a 9€ game? Just create a 10€ card and use it.

Re: Linode hacked, CCs and passwords leaked

#226

Earlier quoted context omitted.

> Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? You really really don't have to. Any payment processor that isn't horribly incompetent does the unique token authorization scheme. Storing CC #s for recurring payments is solely the domain of incompetents who have no business accepting payments from anyone.

What if you want to change processors? If you weren't storing the CC details, wouldn't you have to have customers enter all their details again? I imagine this could cause a drop in revenues due to people either forgetting, procrastinating, or just not bothering. It's never cool to be actually- or quasi-locked into a vendor.

Said processors allow you to export credit card data to another processor without having to store it yourself.

Re: Linode hacked, CCs and passwords leaked

#227

I wonder if they've deleted CC details of previous clients. Is Linode going to contact all relevant customers? Seems like the right thing to do. Not everyone reads HN.

I was just told by a customer service rep at linode that I "shouldn't trust everything I read on the internet" when I inquired about the possibility of deleting my personal information from their server. This seems like an extremely inappropriate way to handle this situation...

Re: Linode hacked, CCs and passwords leaked

#228

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

Bank of America provides this [1], as does Citibank [2] and likely others. Paypal at one time provided this service as well, but it doesn't seem to anymore [3] 1: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... 2: https://www.citibank.com/us/cards/gen-content/messages/van/i... 3: https://www.paypal.com/va/webapps/mpp/security/general-freet...

Crazy, thanks for sharing. I use BofA and am interested, but here is the issue:

> Set your Valid through date for up to 1 year in the future

I'd really like it to be up to the expiration date of my card. It's probably worth doing anyway, I suppose. Thanks for the heads up. Given the zero-liability status, I'm surprised that banks don't promote this feature more visibly.

Re: Linode hacked, CCs and passwords leaked

#229

Really off-topic, but still sad: This is a link to slashdot, but it's on HN's frontpage before it's on slashdot's front-page (if it'll ever get there). (And IMHO that's sad, because /. used to be top notch). I've noticed before that stuff from the HN frontpage appears on /. one to three days after, but I've never seen it for links to slashdot :-)

I rather wish this was a link instead to the original thread rather than to Slashdot. It isn't a big deal, but it certainly would have saved an extra click.

Also off-topic: I've noticed that as well with Slashdot, which is why I lurk HN pretty regularly now. Plus, some of the front page material on /. does more to insight angry discussion, and the community has become increasingly more vitriolic.

At least here, even if someone's brash, they're fairly honest about it (in general). I've even seen a number of disagreements that have been respectful and cordial. It's sad to say, but that's a rare thing these days.

Post reply on HN