I'm looking forward to seeing an official response from Linode on this. Hopefully they are fast and honest about it. I've been a happy customer for quite a while, but this is definitely a concern.
Linode hacked, CCs and passwords leaked
351–360 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#352OFTC has disabled Linode IRC channel: * mode/#linode [+m] by tjfontaine this is what I'm going to say, as a network representative regardless of what has or has not happened with linode, OFTC cannot tolerate release of sensitive information with itself as that mechanism this channel is moderated until staff determines otherwise
Re: Linode hacked, CCs and passwords leaked
#353Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…
http://www.carehart.org/blog/client/index.cfm/2013/1/2/serio...
The basic overview is this: CF servers have an administrative portal at /cfide/. A bug in the scheduler code (think cron) allowed remote attackers to upload arbitrary code to the server and then execute it. Savvy attackers could upload their own backdoors directly into the administrative folder on the site and then execute that code to gain additional access.
As a Linode customer (admittedly only for a small VM I play around with) I have to say I've been impressed with their service and their prices of course, and I'm waiting for further confirmation about the depth of this hack. I was unaware Linode was using ColdFusion. It should be pointed out that CF is a very mature language, akin to ASP.NET. It is actively maintained by Adobe and used by a huge number of websites globally.
Source: I'm a long time ColdFusion developer.
Re: Linode hacked, CCs and passwords leaked
#354Earlier quoted context omitted.
There's nothing wrong with ColdFusion, especially if you've had it around for a while. It's not as glitzy as Rails, but it works and it's still supported and modern. Besides, this isn't ColdFusion's fault. Leave because Linode violated your trust, but not because of the programming language they wrote their site in.
It's closed-source, made by Adobe and seems to have a bad security record - there are 3 things wrong with it. Besides, it's not the reason I'm leaving - it just makes me question them. I'm not after glitzy. If anything, I'd have expected Linode to have been written in Perl or something.
Re: Linode hacked, CCs and passwords leaked
#355The purported "evidence" is a list of supposed entries in a public_html directory.
https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc
Has anyone seen any evidence that this is not simply a hoax?
Re: Linode hacked, CCs and passwords leaked
#356This is disappointing and scary. A friend on another forum posted that some guy on IRC told him the last 4 digits of his CC and his e-mail address. I just called my bank and cancelled my current CC and give me a new number. I really liked Linode too :(
Re: Linode hacked, CCs and passwords leaked
#357Earlier quoted context omitted.
"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…
Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.
Re: Linode hacked, CCs and passwords leaked
#358Earlier quoted context omitted.
To dismiss this breach seems odd to me. The tech community in general has placed a lot of trust and faith in Linode over the years. The shareowners at Linode have surely been great beneficiaries to that. Part of that "unspoken agreement", if you will, is that Linode be competent at what they do and that means keeping your data and information secure. If even an iota of what I read in the abridged IRC log is true, Lin…
Sigh, really? Ok, you typed your credit card number into a web browser at some point. If your sole reason for doing so was "I absolutely trust the people on the other end of this socket not to do what 99% of all people handling credit card data do whether they pretend otherwise or not", instead of something like "hmm that reminds me, I haven't scanned last month's statement yet", then the problem lies squarely with y…
If your expectation when taking credit card numbers was "I'm confident in my abilities to keep this information safe, and if I get hacked I expect my customers not to move to another service and never, ever touch mine with a ten foot pole", then the problem lies squarely with you, the uninformed business.
Re: Linode hacked, CCs and passwords leaked
#359Love the whole side discussion about bitcoin from the supposed attacker: 06:07 They say there's no 'central weak point' 06:07 Yeah there is, there's the developers 06:08 There's been bugs in the client that have allowed the blockchain to split previously 06:08 One could just backdoor the bitcoin client binaries, not the source. 06:08 Nobody would figure it out until it's too late http://turtle.dereferenced.org/~nenol…
Re: Linode hacked, CCs and passwords leaked
#360Earlier quoted context omitted.
That wouldn't work since CVV codes aren't sent with recurring transactions (they can't, since they cannot be stored).
Why can't they be stored? Is it a legal requirement to prevent merchants without the CCV from using the credit card? ...oh wait