Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

271–280 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#271
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.

No weird activities on mine either but I will give a call to my CC company anyway. I have had to cancel the card I use on linode twice in the past few months because of suspicious activities. I just didn't think it would be coming from Linode

Re: Linode hacked, CCs and passwords leaked

#272

If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…

Two alternatives often mentioned on here are DigitalOcean and RamNode. I've only used DigitalOcean. My anecdotal experience from running a Chef Server on a 1GB instance has been pretty mixed. The price is good, but network and CPU performance feels very variable to me. A month ago their Amsterdam servers were unable to be resized, and there was nothing about it on their status page. I tweeted and was told they'd be w…

Yeah, I just migrated from Linode to Ramnode (just in time!) and I'm quite happy with the performance. Great network connectivity.

Re: Linode hacked, CCs and passwords leaked

#273
post #246

Earlier quoted context omitted.

>>Shouldn't you at least do this over SSH? Yeah, I mentioned that at the bottom of my post. Using ssh or some other inline encryption would be a good idea if it is a system you care about. If you have a site to site VPN tunnel between your systems, you can skip adding the encryption.

Yeah, I mentioned that at the bottom of my post It wasn't there when windsurfer replied to you (I was reading the thread earlier), hence his question.

I thought my only edit had been to replace might with probably. If this was not the case I'm sorry. Maybe I edited it to add that right after posting and forgot-

Re: Linode hacked, CCs and passwords leaked

#274

Just got a response from linode: somethings not adding up? ---------------------- dportalatin 30 minutes ago Hello, Thanks for getting into contact with us about this. Linode has found no evidence that payment information of any customer was accessed. We have implemented all appropriate measures to provide the maximum amount of protection to our customers. If you have any other concerns we can address, please let us…

They're doing canned responses right now guys. Just got this exact same message myself.

Re: Linode hacked, CCs and passwords leaked

#275
post #269
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

Do this immediately if it is a debit card!

If it's a debit card that can be used as a credit card (and it must be, otherwise it couldn't have been used to pay for Linode), then it enjoys the same protection as regular credit cards when it's used as one.

Re: Linode hacked, CCs and passwords leaked

#276

Earlier quoted context omitted.

Either this, or a assignable CVV codes. Something like that would be awesome.

That wouldn't work since CVV codes aren't sent with recurring transactions (they can't, since they cannot be stored).

Good point. Regardless, there should be __something__.

Re: Linode hacked, CCs and passwords leaked

#277

Earlier quoted context omitted.

What if you want to change processors? If you weren't storing the CC details, wouldn't you have to have customers enter all their details again? I imagine this could cause a drop in revenues due to people either forgetting, procrastinating, or just not bothering. It's never cool to be actually- or quasi-locked into a vendor.

Most decent processors have processes in place for the transfer of CC numbers. I was involved with this process at a decent-sized magazine, it involved armed security, an encrypted hard drive in a locked container and millions of dollars of insurance. It's not an easy process, but is possible.

Sounds ... expensive.

Re: Linode hacked, CCs and passwords leaked

#278
post #178

Earlier quoted context omitted.

You don't pay for Netflix, Adwords, Amazon Prime, AWS, etc. using a card? If so, yes, I think you're weird. What do you do? Give them all your bank details?

None of those are binding credit agreements, which was OP's complaint

I'm confused. The person you were replying to said:

> you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process!

Re: Linode hacked, CCs and passwords leaked

#279

Just rang my bank to cancel my debit card. Hate doing that. Now I have a week or two of failing payments, bills, etc to look forward to. I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic…

That seems unnecessarily pre-emptive, especially since you are protected as a card user and don't know your card was compromised.

Re: Linode hacked, CCs and passwords leaked

#280

Earlier quoted context omitted.

Don't be so logical please. This can happend to anyone in the industry.

"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.

The key thing (that "ryan" mentions not) is whether the private key was password-protected.
Post reply on HN