Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

311–320 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#311
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

I did it, not worth the worrying. But then again I only bill two things to this CC, one of which is annual.

Re: Linode hacked, CCs and passwords leaked

#312
post #145

Earlier quoted context omitted.

There's baseless speculation and then there's I have some information speculation. I'm operating on heuristics which rely on information that is handily available. Yes, in the end you're right, I'm just speculating. But hey, it's better to err on the side of caution.

Credit card numbers are of pretty low value. Like way less than a buck in medium volume and still just a few bucks for the super premium ones. And there is way, way more inventory of them than interested buyers. The likelyhood of a coordinated break in of a large hosting service with the intention of stealing credit cards is pretty low, and the chance that they'd be exploited so quickly is even lower. Unless the atta…

You bring up very good points, thanks.

I contacted Linode support and they've said in clear terms that they have no evidence that payment information of customers was accessed. I initially signed up for Linode because my friends spoke highly of the tech people working at Linode. Right now amidst all the commotions it's ryan's words (some anonymous dude who joined #linode/irc.oftc.net) vs. an established company's. I'm just going to now stop worrying and get back to my work.

On an interesting note, the big target who actually incurred identifiable damage was seclists.org: http://seclists.org/nmap-dev/2013/q2/3

Re: Linode hacked, CCs and passwords leaked

#313

Just rang my bank to cancel my debit card. Hate doing that. Now I have a week or two of failing payments, bills, etc to look forward to. I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic…

There's nothing wrong with ColdFusion, especially if you've had it around for a while. It's not as glitzy as Rails, but it works and it's still supported and modern. Besides, this isn't ColdFusion's fault. Leave because Linode violated your trust, but not because of the programming language they wrote their site in.

The problem more lies with Linode not properly dealing with a disclosed ColdFusion vulnerability: http://breenmachine.blogspot.com/2013/03/cool-coldfusion-pos...

Re: Linode hacked, CCs and passwords leaked

#314
post #83

Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…

The majority of CC names have "Virtual CC numbers" which is precisely this - You generate a new number, which links to your account, but can only be used for the merchant you specify.

Re: Linode hacked, CCs and passwords leaked

#316
post #250
post #216

Earlier quoted context omitted.

I've never generated an API key, and Linode showed it as blank. I generated a new one anyway, but I can't imagine how they'd have a default key and somehow not show it in the UI.

I know. I've asked for further clarification, especially since their email on Friday said API keys should be reset "if applicable." Edit: Groan , here's their clarification. It's starting to look like they don't know what the heck they're talking about: "Thanks for getting back to us. To be extra cautious it would not hurt to regenerate your Linode API key. You can do that in your user profile. Please let us know if…

After seeing your original post here, I also asked for clarification, and received a similar reply from support:

  The Lish password is set to a random string by default, however we would still recommend resetting this password even if you had not set one manually previously.
I had expected that if the password was not set, then password auth was disabled. I've told them that's what I want and have asked when it will be implemented.

Re: Linode hacked, CCs and passwords leaked

#317

I wonder if they've deleted CC details of previous clients. Is Linode going to contact all relevant customers? Seems like the right thing to do. Not everyone reads HN.

I stopped using linode in mid February and I have not received an email. They also still appear to have my credit card attached to my account (and I had to change my password when I logged in).

Re: Linode hacked, CCs and passwords leaked

#318

Is this why Linode doubled the RAM? To bribe us and make us stay. I'm pretty pissed off about this and will be exploring other options. I'm not pissed off they got hacked, I'm pissed off they are hiding and not being forth coming about it. A simple, "We fucked up, we are going to take steps 1, 2 3 to fix it and reduce the likely hood of this ever happening again" will make me happy. I understand that any server can b…

I'm stunned that you, and plenty of other people in this thread, are taking the anonymous IRC person's word as the gospel truth.

Re: Linode hacked, CCs and passwords leaked

#319

How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…

Mob-mentality. Unfortunately naturally occurs whenever a group gets to be about the size of a mob.

I don't think that quite explains it. Someone who calls himself "ryan" on IRC makes unsubstantiated claims, and in response many dozens of people say loathsome, sneering things about the security practices of this company. The appearance of a mob emerges after a thread exists, it doesn't create the thread.

Re: Linode hacked, CCs and passwords leaked

#320
I Got this response:

"Hello,

Your credit card / financial institution should have a mechanism in place that protects you from occurrences of fraud. While we have found no evidence that payment information of any customer was accessed, you're welcome to reach out to your financial institution for clarification on this policy for personal assurance.

This is still an ongoing investigation and in the event that any additional information fruitions which negates our preliminary investigations, we'll be sure to advise customers accordingly."

I feel this is arrogant

Post reply on HN