Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

331–340 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#331

How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…

Remember this is the SECOND time it has happened.

Before it was the widespread hacking that resulted in Bitcoins being stolen. And users were never told exactly what happened and what was done about it.

People have every right to expect the worse with a company with a track record as poor as Linodes.

Re: Linode hacked, CCs and passwords leaked

#332
post #310

Earlier quoted context omitted.

pastebin is a directory listing of linode.com - trying out a few of the files checks out, including very difficult to guess file names such as: http://www.linode.com/y_key_57284cb2de704e02.html

Am I the only one who is more confused about why there are compiled java classes and AMI BIOS updates in the www directory than about the hacking itself?

> Am I the only one who is more confused about why there are compiled java classes and AMI BIOS updates in the www directory than about the hacking itself?

Sysadmins being lazy.

Somebody needs to get a file from a workstation to a remote machine. There's a firewall in the way somewhere that prevents SSH directly between them or one of them is a Windows box that isn't running an SSH server.

The "correct" solution is complicated and takes 5 minutes to setup. So the sysadmin just copies the file to the web server and downloads it with a browser on the other end. Because port 80 is always open.

Re: Linode hacked, CCs and passwords leaked

#333

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Anyone know of any good way to export linode images to other VPS providers? Seems like I'll have to be doing it manually.

You mean the comprised image?

Re: Linode hacked, CCs and passwords leaked

#335
OFTC has disabled Linode IRC channel:

* mode/#linode [+m] by tjfontaine

this is what I'm going to say, as a network representative

regardless of what has or has not happened with linode, OFTC cannot tolerate release of sensitive information with itself as that mechanism

this channel is moderated until staff determines otherwise

Re: Linode hacked, CCs and passwords leaked

#336

Earlier quoted context omitted.

That is one (good) way to handle the encryption. You don't want to leave out the compression or block size however, so add those back in. Most WAN links are low bandwidth enough that compression will not slow things down (this is usually true even on 1 GBE LAN links for pigz ) and in my experience the speed-up is substantial. pigz is much faster than using ssh compression as it is multicore. apt-get it or http://zlib…

the compression is unnecessary here, you're moving a max of less than a couple of hundred GB of data.

A few hundred GB here, a few hundred GB there, pretty soon you're talking real bandwidth.

Re: Linode hacked, CCs and passwords leaked

#337
post #316
post #250

Earlier quoted context omitted.

I know. I've asked for further clarification, especially since their email on Friday said API keys should be reset "if applicable." Edit: Groan , here's their clarification. It's starting to look like they don't know what the heck they're talking about: "Thanks for getting back to us. To be extra cautious it would not hurt to regenerate your Linode API key. You can do that in your user profile. Please let us know if…

After seeing your original post here, I also asked for clarification, and received a similar reply from support: The Lish password is set to a random string by default, however we would still recommend resetting this password even if you had not set one manually previously. I had expected that if the password was not set, then password auth was disabled. I've told them that's what I want and have asked when it will b…

I'm kind of upset they didn't clarify this in the initial email/blog entry. The way it was worded ("if applicable") implies that resetting the API might not be necessary in some cases. I think it is reasonable to assume that those who never generated an API key in the first place would've fallen under such a bucket.

Now it sounds like basically everyone should have reset their API key. Bleh.

Re: Linode hacked, CCs and passwords leaked

#338
post #312

Earlier quoted context omitted.

Credit card numbers are of pretty low value. Like way less than a buck in medium volume and still just a few bucks for the super premium ones. And there is way, way more inventory of them than interested buyers. The likelyhood of a coordinated break in of a large hosting service with the intention of stealing credit cards is pretty low, and the chance that they'd be exploited so quickly is even lower. Unless the atta…

You bring up very good points, thanks. I contacted Linode support and they've said in clear terms that they have no evidence that payment information of customers was accessed. I initially signed up for Linode because my friends spoke highly of the tech people working at Linode. Right now amidst all the commotions it's ryan's words (some anonymous dude who joined #linode/irc.oftc.net) vs. an established company's. I'…

>I contacted Linode support and they've said in clear terms that they have no evidence that payment information of customers was accessed.

Well that's a first. They were very evasive about it earlier.

Re: Linode hacked, CCs and passwords leaked

#339
post #278

Earlier quoted context omitted.

I'm confused. The person you were replying to said: > you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process!

I think the key here is "Hopefully you don't incur any late fees while you're going through the process!"

Sorry, I should have said "fees". I've recently had to deal with this process, and I've found a few vendors who charge a penalty if the attempt to charge my card doesn't go through for any reason.

Re: Linode hacked, CCs and passwords leaked

#340
post #74

Earlier quoted context omitted.

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

I would cancel that card right now. IMHO You should never ever ever ever use a debit card anywhere else other than the ATM. Credit cards give you way more financial protection.

Unless said ATM has been compromised :s
Post reply on HN