Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

231–240 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#231

Earlier quoted context omitted.

If your using lvm you can create a snapshot to do this while online, if not just read from your disk (assuming sda here): 1. (offline) Boot new and old VM servers from live CD 2. old server: dd if=/dev/sda bs=8M | pbzip2 -c | netcat 3. new server: netcat -l | pbzip2 -cd | dd of=/dev/sda bs=8M Compression: You can use something besides pbzip2, maybe pigz of if you only have a single core use bzip2 or gzip. Security: Y…

There's very nice utility called Ghost 4 Unix that makes the whole thing even easier: http://www.feyrer.de/g4u/

Looks like overkill for a simple one time task that can easily be handled the UNIX way. Worth looking into if you need to do this alot-

Re: Linode hacked, CCs and passwords leaked

#233
post #159

So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.

[Warning: imperfect analogy follows.] It's one thing if Linode is like someone who gets drunk and crashes their vehicle. That's 100% their fault and they've burned any goodwill. In this case, however, Linode is like someone who was carjacked. Perhaps Linode shouldn't have been driving that type of vehicle in an area known to have people attempting to carjack every single vehicle that drives by. Perhaps they should ha…

I think a more accurate analogy is to say that Linode is moving your important files from one location to another in their moving van. They park at a 7-11 to run inside and grab a snack, leaving the van unlocked. An intruder comes along, opens the unlocked doors, makes a few copies of your files and leaves. Linode gets back in the van, notices the intrusion, does nothing except tell you that "you have nothing to worry about, but you may as well change your locks" and then when the truth comes to light, they basically stop returning your phone calls.

"No comment."

Re: Linode hacked, CCs and passwords leaked

#234

I'm looking forward to seeing an official response from Linode on this. Hopefully they are fast and honest about it. I've been a happy customer for quite a while, but this is definitely a concern.

They are already way overdue. Their support staff is pretty damn fast, so I'm sure they could have commented on this if they wanted to.

Alas, they have not.

I just blocked my credit card, and Linode will not get anymore of my money. Too bad, i enjoyed my stay very much, but no matter what their response will be, I doubt I will be able to believe them. =/

Re: Linode hacked, CCs and passwords leaked

#235

Earlier quoted context omitted.

> Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? You really really don't have to. Any payment processor that isn't horribly incompetent does the unique token authorization scheme. Storing CC #s for recurring payments is solely the domain of incompetents who have no business accepting payments from anyone.

What if you want to change processors? If you weren't storing the CC details, wouldn't you have to have customers enter all their details again? I imagine this could cause a drop in revenues due to people either forgetting, procrastinating, or just not bothering. It's never cool to be actually- or quasi-locked into a vendor.

Some will let you export the data, but it's a hassle. They burn it to a DVD and ship it to you and you have to sign tons of stuff freeing them of any liability.

Otherwise you just ask customers to re-authenticate. Often you have a few months headway for a switch like that.

Re: Linode hacked, CCs and passwords leaked

#236
post #130
post #83

Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…

This is basically what Stripe does. The "CC Company" basically doesn't offer more than a simple yes/no API -- "approved w/ #" or "declined". It'd be great if they could do more, but that's where the opportunity for folks like Stripe lies.

Well, you can get AVS checks back too. But in general the entire system is so far behind the times. It really needs to be overhauled with security as the focal point.

Re: Linode hacked, CCs and passwords leaked

#237

Earlier quoted context omitted.

Debit cards have less protection. Wouldn't hurt just to ask your bank to re-authorise it anyway? It will change the three digits on the back.

They don't, protections are exactly the same.

They really aren't.

I know someone who got their debit card cloned. While the bank eventually repaid him, that did nothing to repay him the additional fees he owned his normal debtors (e.g. rent, utilities, etc).

With a credit card you aren't losing "actual" money. You are losing the bank's borrowed money which the bank pays back. With a debit card you're losing cash which you won't be able to replace yourself and which the bank might take days to weeks to replace.

Even if you NEED to borrow while your credit card is out of commission you can either use the overdraft facility on your debit card or other quick sources of credit. Hard to get quick cash without going to a pawn shop.

Re: Linode hacked, CCs and passwords leaked

#238
post #145

Earlier quoted context omitted.

I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.

There's baseless speculation and then there's I have some information speculation. I'm operating on heuristics which rely on information that is handily available. Yes, in the end you're right, I'm just speculating. But hey, it's better to err on the side of caution.

If it is indeed true that credit card numbers were compromised, it would behove Linode to tell their customers quickly so they can take the proper action.

With this lack of transparency, I feel like I had no choice but to block my card.

Re: Linode hacked, CCs and passwords leaked

#239
post #99

That may explains the seclist hack too... http://seclists.org/nmap-dev/2013/q2/3

If that's the same one, then that link implies Linode already fixed the issue on or around the 13th. So, I'm wondering if the silence that has some folks here up in arms is indeed because they've been instructed by law enforcement to keep quiet pending the investigation.

Now if we could only stay the torches and pitchforks for a while before this gets sorted out...

Re: Linode hacked, CCs and passwords leaked

#240

Earlier quoted context omitted.

Sigh, really? Ok, you typed your credit card number into a web browser at some point. If your sole reason for doing so was "I absolutely trust the people on the other end of this socket not to do what 99% of all people handling credit card data do whether they pretend otherwise or not", instead of something like "hmm that reminds me, I haven't scanned last month's statement yet", then the problem lies squarely with y…

So because companies A through X are irresponsible with data, customers should regard that as acceptable and give company Y a free pass to do the same? I don't understand how a reasonable analysis of the situation can come to that conclusion.

You don't know the names of companies A through X, or supposedly safe Z for that matter. All you'll be doing is an enormous amount of work and bother to move from Y to, lets say, A, because you think you'll be more secure but unfortunately if anything its probably the other way around, its just that A hasn't been hacked... yet... so far as they know...

none of them get a free pass they all suck, but the one that just got busted is probably going to be a little more security focused in the near future.

Hmm stay at a place that just got burned, or expend lots of effort to move to a place that hasn't been burned yet...

Post reply on HN