Essentially: I am a linode customer. My cc details were somehow leaked. Adds a data point here.
Linode hacked, CCs and passwords leaked
321–330 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#322How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…
I mean, if I was a linode customer I'd definitely be on the phone to the bank, but this guy presented no evidence I'm aware of that he had the kind of access he claims.
Re: Linode hacked, CCs and passwords leaked
#323My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…
Switched to https://www.digitalocean.com/ last week. Excellent service and pricing.
also a twitter feed for the customers page ?
Re: Linode hacked, CCs and passwords leaked
#324I thought Linode was different but based on their lack of transparency in this matter, I'm seriously considering just moving all of my sites to DigitalOcean, Rackspace or even AWS instead. This makes me wonder who originally cleared them for PCI compliance in the first place. This is a huge violation of trust and now I've got to keep my eyes focused on my credit card statement for fraudulent transactions, the bank I am with ANZ however has great fraud detection systems and considering I'm in Australia any transaction should be easily reversible, but the fact there is a possibility my card could be fraudulently used saddens me.
Linode needs to come clean about this situation now.
Re: Linode hacked, CCs and passwords leaked
#325http://arstechnica.com/business/2012/03/bitcoins-worth-22800...
http://forum.linode.com/viewtopic.php?f=20&t=8509
I had really hoped that they had changed their stance on incident management. If it's true that they suppressed information about a possible wide-scale compromise where customer data could have been affected, then despite everything else about their service that's so great, there's no way anyone should want to continue to be a customer there.
Given Linode's past behavior and the information provided in the IRC chat, I think there's reasonable suspicion that customers' password hashes were stolen and Linode wasn't completely honest in their recent email to customers.
Re: Linode hacked, CCs and passwords leaked
#326Linode hasn't been very forthcoming in the past where security "incidents" are concerned: http://arstechnica.com/business/2012/03/bitcoins-worth-22800... http://forum.linode.com/viewtopic.php?f=20&t=8509 I had really hoped that they had changed their stance on incident management. If it's true that they suppressed information about a possible wide-scale compromise where customer data could have been affected, then de…
Nevermind the security concerns. These guys aren't using version control!
Re: Linode hacked, CCs and passwords leaked
#327How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…
And on both occasions no information was given to customers about what happened, what was fixed and whether it would happen again.
The only moron here is you for NOT assuming the worst with a company with a track record as poor as Linodes.
Re: Linode hacked, CCs and passwords leaked
#328Earlier quoted context omitted.
There's nothing wrong with ColdFusion, especially if you've had it around for a while. It's not as glitzy as Rails, but it works and it's still supported and modern. Besides, this isn't ColdFusion's fault. Leave because Linode violated your trust, but not because of the programming language they wrote their site in.
The problem more lies with Linode not properly dealing with a disclosed ColdFusion vulnerability: http://breenmachine.blogspot.com/2013/03/cool-coldfusion-pos...
Re: Linode hacked, CCs and passwords leaked
#329Earlier quoted context omitted.
I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…
"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…
Re: Linode hacked, CCs and passwords leaked
#330Earlier quoted context omitted.
Not with a debit card - you don't get the same protections as a credit card and I'd rather just have a few days of hassle and then know my card is secure than be unsure and have to constantly check my account for odd transactions. Also, whilst I may get money refunded if taken from my account, if I miss bill payments as a result - that would affect my credit report and I don't know if that would be removed when I rep…
Yes, you do. The Debit Card was used in a Credit transaction, so Visa's general protections still apply. You can dispute any of the transactions if they were done through credit (which online ones are nearly 100% of the time).