Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

321–330 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#321
I recently sent an email to linode support, and got a very murky response. I used my debit card on linode, and it was recently used on transactions I didn't make in random parts of the world that I'm not in, so I had to cancel it. My first guess was that it was linode, and all of the posts here make it more likely.

Essentially: I am a linode customer. My cc details were somehow leaked. Adds a data point here.

Re: Linode hacked, CCs and passwords leaked

#322

How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…

Reading through the IRC chat log it didn't look like he'd proved he had the CC numbers.

I mean, if I was a linode customer I'd definitely be on the phone to the bank, but this guy presented no evidence I'm aware of that he had the kind of access he claims.

Re: Linode hacked, CCs and passwords leaked

#323

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Switched to https://www.digitalocean.com/ last week. Excellent service and pricing.

was not convinced by the website, looks nice but prices are kind of very cheap ?

also a twitter feed for the customers page ?

Re: Linode hacked, CCs and passwords leaked

#324
As someone who has been a very happy and loyal Linode customer for a long time now, this whole situation paints an image of Linode I otherwise would never have thought. The fact they apparently had both the private and public keys for the credit card hashes in the same location as one another is beyond belief. The very fact that Linode failed to mention they made a deal with the attackers and then reneged on it all without telling anyone makes me sick. I don't want to bash Linode purely because everyone else is, I am legitimately concerned here that my personal details have been compromised.

I thought Linode was different but based on their lack of transparency in this matter, I'm seriously considering just moving all of my sites to DigitalOcean, Rackspace or even AWS instead. This makes me wonder who originally cleared them for PCI compliance in the first place. This is a huge violation of trust and now I've got to keep my eyes focused on my credit card statement for fraudulent transactions, the bank I am with ANZ however has great fraud detection systems and considering I'm in Australia any transaction should be easily reversible, but the fact there is a possibility my card could be fraudulently used saddens me.

Linode needs to come clean about this situation now.

Re: Linode hacked, CCs and passwords leaked

#325
Linode hasn't been very forthcoming in the past where security "incidents" are concerned:

http://arstechnica.com/business/2012/03/bitcoins-worth-22800...

http://forum.linode.com/viewtopic.php?f=20&t=8509

I had really hoped that they had changed their stance on incident management. If it's true that they suppressed information about a possible wide-scale compromise where customer data could have been affected, then despite everything else about their service that's so great, there's no way anyone should want to continue to be a customer there.

Given Linode's past behavior and the information provided in the IRC chat, I think there's reasonable suspicion that customers' password hashes were stolen and Linode wasn't completely honest in their recent email to customers.

Re: Linode hacked, CCs and passwords leaked

#326

Linode hasn't been very forthcoming in the past where security "incidents" are concerned: http://arstechnica.com/business/2012/03/bitcoins-worth-22800... http://forum.linode.com/viewtopic.php?f=20&t=8509 I had really hoped that they had changed their stance on incident management. If it's true that they suppressed information about a possible wide-scale compromise where customer data could have been affected, then de…

Did you see http://www.linode.com/linode4.css and http://www.linode.com/linode3.css?

Nevermind the security concerns. These guys aren't using version control!

Re: Linode hacked, CCs and passwords leaked

#327

How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…

This is the SECOND time this has happened.

And on both occasions no information was given to customers about what happened, what was fixed and whether it would happen again.

The only moron here is you for NOT assuming the worst with a company with a track record as poor as Linodes.

Re: Linode hacked, CCs and passwords leaked

#328

Earlier quoted context omitted.

There's nothing wrong with ColdFusion, especially if you've had it around for a while. It's not as glitzy as Rails, but it works and it's still supported and modern. Besides, this isn't ColdFusion's fault. Leave because Linode violated your trust, but not because of the programming language they wrote their site in.

The problem more lies with Linode not properly dealing with a disclosed ColdFusion vulnerability: http://breenmachine.blogspot.com/2013/03/cool-coldfusion-pos...

It may not have been disclosed yet when it was exploited.

Re: Linode hacked, CCs and passwords leaked

#329
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.

Re: Linode hacked, CCs and passwords leaked

#330

Earlier quoted context omitted.

Not with a debit card - you don't get the same protections as a credit card and I'd rather just have a few days of hassle and then know my card is secure than be unsure and have to constantly check my account for odd transactions. Also, whilst I may get money refunded if taken from my account, if I miss bill payments as a result - that would affect my credit report and I don't know if that would be removed when I rep…

Yes, you do. The Debit Card was used in a Credit transaction, so Visa's general protections still apply. You can dispute any of the transactions if they were done through credit (which online ones are nearly 100% of the time).

Ok, good to know. Even so - I could very easily miss £50-100 or so of fraudulent transactions each month so I'd rather just get a new card.
Post reply on HN