Earlier quoted context omitted.
To be fair the hacker didn't say the keys were stored on the same server as the credit card numbers, he said they were stored on the web server. It's most likely the database containing the CC numbers resides on a separate set of boxes than the web servers.
The Cigital-recommended way to hash your passwords is to use an HMAC/scrypt combo, with the HMAC key stored on the app server (not the database). What Linode did may, or may not, be dumb. They are being tight-lipped so we can only guess.
Linode hacked, CCs and passwords leaked
301–310 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#302How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…
Re: Linode hacked, CCs and passwords leaked
#303Earlier quoted context omitted.
I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…
So here's what Linode support is actually saying when asked about the breach: Thank you for contacting us. We have no evidence at this time that any payment information was compromised.
"We appreciate the response, and we can assure you that we have implemented all appropriate measures to provide the maximum amount of protection to our customers."
Re: Linode hacked, CCs and passwords leaked
#304Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.
Bank of America provides this [1], as does Citibank [2] and likely others. Paypal at one time provided this service as well, but it doesn't seem to anymore [3] 1: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf... 2: https://www.citibank.com/us/cards/gen-content/messages/van/i... 3: https://www.paypal.com/va/webapps/mpp/security/general-freet...
Re: Linode hacked, CCs and passwords leaked
#305Re: Linode hacked, CCs and passwords leaked
#306Earlier quoted context omitted.
I'd say support tickets or posting on their forum[1] may help try to get a response. But based one one of the support ticket responses posted in the comments in this HN story already, it sounds like Linode isn't allowed to release that kind of information yet. They may be waiting on the police and/or their lawyers to allow them to talk publicly about it. And if that isn't the gating factor, they are probably trying t…
its a recursion! the forum points back to here
/end nitpick
Re: Linode hacked, CCs and passwords leaked
#307Earlier quoted context omitted.
That seems unnecessarily pre-emptive, especially since you are protected as a card user and don't know your card was compromised.
Not with a debit card - you don't get the same protections as a credit card and I'd rather just have a few days of hassle and then know my card is secure than be unsure and have to constantly check my account for odd transactions. Also, whilst I may get money refunded if taken from my account, if I miss bill payments as a result - that would affect my credit report and I don't know if that would be removed when I rep…
The Debit Card was used in a Credit transaction, so Visa's general protections still apply. You can dispute any of the transactions if they were done through credit (which online ones are nearly 100% of the time).
Re: Linode hacked, CCs and passwords leaked
#308Earlier quoted context omitted.
its a recursion! the forum points back to here
That's an endless loop. Recursion would be the forum pointing to itself. /end nitpick
Re: Linode hacked, CCs and passwords leaked
#309Re: Linode hacked, CCs and passwords leaked
#310Earlier quoted context omitted.
The paste-bin link he provided seems to time out for me. But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.
pastebin is a directory listing of linode.com - trying out a few of the files checks out, including very difficult to guess file names such as: http://www.linode.com/y_key_57284cb2de704e02.html