Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

291–300 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#292
Is it just me or is each passing minute without an acknowledgment of this issue bad for Linode? There's tens of thousands of customers right now who would kind of like to know if they need to request new credit cards or not, or don't know about this and deserve to know that their VPS provider's credit card database has been compromised.

Re: Linode hacked, CCs and passwords leaked

#293

Earlier quoted context omitted.

Either this, or a assignable CVV codes. Something like that would be awesome.

That wouldn't work since CVV codes aren't sent with recurring transactions (they can't, since they cannot be stored).

Why can't they be stored?

Is it a legal requirement to prevent merchants without the CCV from using the credit card?

...oh wait

Re: Linode hacked, CCs and passwords leaked

#294
post #278

Earlier quoted context omitted.

None of those are binding credit agreements, which was OP's complaint

I'm confused. The person you were replying to said: > you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process!

I've never been charged a late fee by a firm I didn't have a credit agreement with. Perhaps other parts of the world are more insane, but here that is definitely not commonplace.

Re: Linode hacked, CCs and passwords leaked

#295
post #278

Earlier quoted context omitted.

I'm confused. The person you were replying to said: > you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process!

I've never been charged a late fee by a firm I didn't have a credit agreement with. Perhaps other parts of the world are more insane, but here that is definitely not commonplace.

I don't know who does and who doesn't, honestly. I try to avoid being delinquent. I know from the last time I had to change my card that my phone provider and ISP certainly do. Anybody who charges you on a recurring basis certainly can — they just add the amount to your next bill. They won't take you to court for it, but it will be added to the amount that you must pay or be disconnected.

Re: Linode hacked, CCs and passwords leaked

#297
post #278

Earlier quoted context omitted.

None of those are binding credit agreements, which was OP's complaint

I'm confused. The person you were replying to said: > you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process!

I think the key here is "Hopefully you don't incur any late fees while you're going through the process!"

Re: Linode hacked, CCs and passwords leaked

#298

Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.

Bank of America provides this [1], as does Citibank [2] and likely others. Paypal at one time provided this service as well, but it doesn't seem to anymore [3] 1: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... 2: https://www.citibank.com/us/cards/gen-content/messages/van/i... 3: https://www.paypal.com/va/webapps/mpp/security/general-freet...

I've used the BoA and it's fantastic for one-time purchases. Like another commenter mentioned, it's only good for 1 year and you give a global cap. It would be nice if it was more permanent and allowed for a weekly or monthly cap so you could use it with subscription services or something like Amazon.

Re: Linode hacked, CCs and passwords leaked

#299
post #36

Earlier quoted context omitted.

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

That is not the way to handle this issue. I've found my one problem with Linode is they are arrogant. It comes off pretty strong if you ever ask them questions in chat.

One thing to note is that the irc channel if that is what you mean by chat, is mostly populated by non linode staff. And many of us there tend to be sarcastic as we idle there and chat about all sorts of stuff while we are bored at work or whatever. Unless it's someone with ops, you aren't getting an official reply and even then for something official they usually refer to ticket system.

Re: Linode hacked, CCs and passwords leaked

#300
post #145

Earlier quoted context omitted.

I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.

There's baseless speculation and then there's I have some information speculation. I'm operating on heuristics which rely on information that is handily available. Yes, in the end you're right, I'm just speculating. But hey, it's better to err on the side of caution.

Credit card numbers are of pretty low value. Like way less than a buck in medium volume and still just a few bucks for the super premium ones. And there is way, way more inventory of them than interested buyers. The likelyhood of a coordinated break in of a large hosting service with the intention of stealing credit cards is pretty low, and the chance that they'd be exploited so quickly is even lower.

Unless the attacker dumped them all (semi) publicly, the more likely explanation is that the breakin caused people to check their accounts and a statistically normal percentage of them showed fraud from another origin. But anybody who sees it will be sure to get online and find others in a similar situation.

Everybody would be doing themselves a big favor if they stopped treating CC info as the #1 scary OMG data theft. The banks programmed you to care because congress made sure they're liable instead of you. Theoretically you might owe $50 due to fraud but practically you never pay a dime. Sure it's a bit of a pain in the ass to get resolved, but it's not worth stressing about until it happens.

I'd be way more concerned if my hoster lost my contact info, ip logs and identity challenge questions & answers.

Post reply on HN