Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

251–260 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#251

Earlier quoted context omitted.

What about for people who did not use a credit card to pay for linode but instead relied on PayPal. Should they follow the same steps? What about other cautious steps?

I don't think they allow paypal as a payment method

I've got a PayPal business mastercard which is connected to PayPal Smart Connect. They may not allow PayPal proper but you could pay using PayPal by way of their card. I use my PayPal card hooked into Smart Connect for a good number of recurring payments like this.

So I guess the answer would be, if you ended up hooking your PayPal account up to Linode in the way I described, yeah follow the same steps as other cards, otherwise it's not even possible to have a problem.

Re: Linode hacked, CCs and passwords leaked

#252
post #89

Earlier quoted context omitted.

These guys are looking totally incompetent at this point. If you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email? "You are of course free to take any steps you deem prudent or necessary to ensure the integrity…

To be fair the hacker didn't say the keys were stored on the same server as the credit card numbers, he said they were stored on the web server. It's most likely the database containing the CC numbers resides on a separate set of boxes than the web servers.

the database server is local, read the entire log...

Re: Linode hacked, CCs and passwords leaked

#253

Just got a response from linode: somethings not adding up? ---------------------- dportalatin 30 minutes ago Hello, Thanks for getting into contact with us about this. Linode has found no evidence that payment information of any customer was accessed. We have implemented all appropriate measures to provide the maximum amount of protection to our customers. If you have any other concerns we can address, please let us…

you seem to be new to this, most companies lie all the time about the nature of their security compromises.

Re: Linode hacked, CCs and passwords leaked

#254
Remember when the Linode customer service portal was compromised which exposed everyone's VPS?: http://julianyap.com/2012/03/01/compromised-linode-vps.html

In that case, specific Bitcoin users were targeted.

It's pretty much why I don't trust Linode.

You can't trust a company which puts random AMI BIOS files on the main index directory on the main web site. You can't trust a company that can't even lock down their own Linode customer service portal (which could lead to a breach of each and every customer's VPS).

Perhaps history is fuzzy for people when new announcements come out or low prices are around.

Re: Linode hacked, CCs and passwords leaked

#255
post #89

Earlier quoted context omitted.

These guys are looking totally incompetent at this point. If you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email? "You are of course free to take any steps you deem prudent or necessary to ensure the integrity…

To be fair the hacker didn't say the keys were stored on the same server as the credit card numbers, he said they were stored on the web server. It's most likely the database containing the CC numbers resides on a separate set of boxes than the web servers.

The Cigital-recommended way to hash your passwords is to use an HMAC/scrypt combo, with the HMAC key stored on the app server (not the database).

What Linode did may, or may not, be dumb. They are being tight-lipped so we can only guess.

Re: Linode hacked, CCs and passwords leaked

#256
post #178

Earlier quoted context omitted.

Maybe I'm weird, but I know exactly which binding credit agreements I'm in and how they're paid, and definitely none of them get paid using another binding credit agreement. :)

You don't pay for Netflix, Adwords, Amazon Prime, AWS, etc. using a card? If so, yes, I think you're weird. What do you do? Give them all your bank details?

None of those are binding credit agreements, which was OP's complaint

Re: Linode hacked, CCs and passwords leaked

#257
post #225

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

The portuguese ATM network operator provides this for free (its called mbnet btw). You can even set expiry times and value limit, it's the best thing to use when paying for stuff online. Want to buy a 9€ game? Just create a 10€ card and use it.

Yup, I use this all the time. They even, recently, added support to multi-use cards with bigger expire dates.

I wonder how hard would it be to make a startup like this.

Re: Linode hacked, CCs and passwords leaked

#259

Earlier quoted context omitted.

Until they have a security breach.

Yes But if that happens, it's not your responsibility (at least not 100%), it's theirs

Following the traditional responsibility/accountability dichotomy: They are responsible for storing the cc number securely but you are accountable when something goes wrong (because you gave them that task)

Much like Linode are responsible for hosting my clients site but I sigh am accountable when something goes wrong.

Re: Linode hacked, CCs and passwords leaked

#260
post #246

Earlier quoted context omitted.

>>Shouldn't you at least do this over SSH? Yeah, I mentioned that at the bottom of my post. Using ssh or some other inline encryption would be a good idea if it is a system you care about. If you have a site to site VPN tunnel between your systems, you can skip adding the encryption.

Yeah, I mentioned that at the bottom of my post It wasn't there when windsurfer replied to you (I was reading the thread earlier), hence his question.

Thanks. I thought I was just dumb.
Post reply on HN