Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

281–290 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#281
post #269

Earlier quoted context omitted.

Do this immediately if it is a debit card!

If it's a debit card that can be used as a credit card (and it must be, otherwise it couldn't have been used to pay for Linode), then it enjoys the same protection as regular credit cards when it's used as one.

Yeah, but it's one thing to deal with a line of credit that is maxed out by fraud and another to deal with an empty checking account.

Re: Linode hacked, CCs and passwords leaked

#282
post #279

Just rang my bank to cancel my debit card. Hate doing that. Now I have a week or two of failing payments, bills, etc to look forward to. I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic…

That seems unnecessarily pre-emptive, especially since you are protected as a card user and don't know your card was compromised.

Not with a debit card - you don't get the same protections as a credit card and I'd rather just have a few days of hassle and then know my card is secure than be unsure and have to constantly check my account for odd transactions. Also, whilst I may get money refunded if taken from my account, if I miss bill payments as a result - that would affect my credit report and I don't know if that would be removed when I report the transactions as fraudulent.

Re: Linode hacked, CCs and passwords leaked

#283

If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security. Hopefully, they own up and start being transparent. If this is true then what alternative hosts should I loo…

Don't be so logical please. This can happend to anyone in the industry.

"Logical" is not a fancy synonym for "severe" or "unforgiving", and is probably not the word you wanted here. There are sometimes good, logical arguments that you can make for cutting people some slack.

Re: Linode hacked, CCs and passwords leaked

#284

Earlier quoted context omitted.

If it's a debit card that can be used as a credit card (and it must be, otherwise it couldn't have been used to pay for Linode), then it enjoys the same protection as regular credit cards when it's used as one.

Yeah, but it's one thing to deal with a line of credit that is maxed out by fraud and another to deal with an empty checking account.

Very true. If your bank gives you a separate savings account you can transfer the bulk of your money there and just use the card from the current account to limit your exposure.

Re: Linode hacked, CCs and passwords leaked

#285
post #74

Earlier quoted context omitted.

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

Debit cards have less protection. Wouldn't hurt just to ask your bank to re-authorise it anyway? It will change the three digits on the back.

they typically have the same protections, the only difference is that while credit cards only check that the charge can be made during the authorization period, debit cards lock up the bank's funds immediately which may cause your checking account to be temporarily unusable even if all the charges are successfully disputed.

a good practice that bankers constantly tell me is to have a separate credit card for online purchases for the fact alone that it is one step removed from your checking account.

Re: Linode hacked, CCs and passwords leaked

#287
post #179

Earlier quoted context omitted.

Every site can be hacked. It's just a matter of time. You just have to properly react: call your CC provider, check for any charges on your bill, and move on.

I do not think anyone here is actually worried about their funds; as mentioned below, any reputable provider will have such charges promptly reversed. The problem is instead with their response to the situation. Linode has addressed the breach, but assured customers nothing of value had been compromised. This infers two thoughts. One: they knew of the breach and lied, thereby unveiling a unforthcoming and dishonest n…

Mm, not equally. I'd rather have incompetence over malice.

Re: Linode hacked, CCs and passwords leaked

#288

Earlier quoted context omitted.

Until they're hacked, too...

Or until they let other customers see all the data on VMs that you've shut down. Oh wait, that already happened: http://www.wired.com/wiredenterprise/2013/04/digitalocean/

DigitalOcean is new and they fixed the problem the same day the article was written:

https://www.digitalocean.com/blog_posts/resolved-lvm-data-is...

If I had a choice between a VPS provider who either:

- Only has large issues (eg. leaks credit card data) and goes weeks without reporting them to customers, or

- Has lots of small issues (eg. forgetting to clean the free space of LVM volumes) but fixes them the same day,

I'd much prefer the latter.

EDIT: My bad, apparently the problem was reported on March 27 and wasn't fixed until April 2.

Re: Linode hacked, CCs and passwords leaked

#289
The best part is at the very bottom of the log. A customer enters the IRC channel to ask for support after ryann (the hacker) finishes explaining the attack.

Customer: "hello, i forgot my password and linode's email reminder service doesn't work. i checked spam box but there's no email from linode." Linode Guy: "ryannn: can you give him the password?"

Post reply on HN