Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

351–360 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#351

I'm looking forward to seeing an official response from Linode on this. Hopefully they are fast and honest about it. I've been a happy customer for quite a while, but this is definitely a concern.

You think linode is going to be transparent about things?

Re: Linode hacked, CCs and passwords leaked

#352

OFTC has disabled Linode IRC channel: * mode/#linode [+m] by tjfontaine this is what I'm going to say, as a network representative regardless of what has or has not happened with linode, OFTC cannot tolerate release of sensitive information with itself as that mechanism this channel is moderated until staff determines otherwise

Channel now unmoderated. Edit: HTP came in and trolled (pretending to be ex-Linode), re-moderated.

Re: Linode hacked, CCs and passwords leaked

#353

Found it interesting that Linode uses Coldfusion. Wonder if Adobe has anything to say about the apparent 0-day. If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web se…

This is not a brand new 0-day. This is a bug that Adobe communicated and patched months ago, a bug that affected a lot of folks who didn't follow the standard practice of locking down an administrative directory on the website.

http://www.carehart.org/blog/client/index.cfm/2013/1/2/serio...

The basic overview is this: CF servers have an administrative portal at /cfide/. A bug in the scheduler code (think cron) allowed remote attackers to upload arbitrary code to the server and then execute it. Savvy attackers could upload their own backdoors directly into the administrative folder on the site and then execute that code to gain additional access.

As a Linode customer (admittedly only for a small VM I play around with) I have to say I've been impressed with their service and their prices of course, and I'm waiting for further confirmation about the depth of this hack. I was unaware Linode was using ColdFusion. It should be pointed out that CF is a very mature language, akin to ASP.NET. It is actively maintained by Adobe and used by a huge number of websites globally.

Source: I'm a long time ColdFusion developer.

Re: Linode hacked, CCs and passwords leaked

#354

Earlier quoted context omitted.

There's nothing wrong with ColdFusion, especially if you've had it around for a while. It's not as glitzy as Rails, but it works and it's still supported and modern. Besides, this isn't ColdFusion's fault. Leave because Linode violated your trust, but not because of the programming language they wrote their site in.

It's closed-source, made by Adobe and seems to have a bad security record - there are 3 things wrong with it. Besides, it's not the reason I'm leaving - it just makes me question them. I'm not after glitzy. If anything, I'd have expected Linode to have been written in Perl or something.

(made by Adobe) ⇒ (closed-source) ∧ (has a bad security record)

Re: Linode hacked, CCs and passwords leaked

#356
post #348

This is disappointing and scary. A friend on another forum posted that some guy on IRC told him the last 4 digits of his CC and his e-mail address. I just called my bank and cancelled my current CC and give me a new number. I really liked Linode too :(

FYI, the last 4 and your e-mail address are both visible in plaintext from your /account page in Linode Manager. Obviously, still disappointing and scary, but it doesn't necessarily mean that whoever has that information also has the full CC number.

Re: Linode hacked, CCs and passwords leaked

#357

Earlier quoted context omitted.

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.

Even old card numbers can be used for transactions in some cases.

Re: Linode hacked, CCs and passwords leaked

#358

Earlier quoted context omitted.

To dismiss this breach seems odd to me. The tech community in general has placed a lot of trust and faith in Linode over the years. The shareowners at Linode have surely been great beneficiaries to that. Part of that "unspoken agreement", if you will, is that Linode be competent at what they do and that means keeping your data and information secure. If even an iota of what I read in the abridged IRC log is true, Lin…

Sigh, really? Ok, you typed your credit card number into a web browser at some point. If your sole reason for doing so was "I absolutely trust the people on the other end of this socket not to do what 99% of all people handling credit card data do whether they pretend otherwise or not", instead of something like "hmm that reminds me, I haven't scanned last month's statement yet", then the problem lies squarely with y…

> If your sole reason for doing so was "I absolutely trust the people on the other end of this socket not to do what 99% of all people handling credit card data do whether they pretend otherwise or not", instead of something like "hmm that reminds me, I haven't scanned last month's statement yet", then the problem lies squarely with you, the uninformed consumer.

If your expectation when taking credit card numbers was "I'm confident in my abilities to keep this information safe, and if I get hacked I expect my customers not to move to another service and never, ever touch mine with a ten foot pole", then the problem lies squarely with you, the uninformed business.

Re: Linode hacked, CCs and passwords leaked

#359

Love the whole side discussion about bitcoin from the supposed attacker: 06:07 They say there's no 'central weak point' 06:07 Yeah there is, there's the developers 06:08 There's been bugs in the client that have allowed the blockchain to split previously 06:08 One could just backdoor the bitcoin client binaries, not the source. 06:08 Nobody would figure it out until it's too late http://turtle.dereferenced.org/~nenol…

I'm curious how he's going to backdoor the binaries running on my computer built by the launchpad servers without anyone noticing. Granted, I'm not checking the commit logs every time apt gives me a new version, but all the same.

Re: Linode hacked, CCs and passwords leaked

#360
post #293

Earlier quoted context omitted.

That wouldn't work since CVV codes aren't sent with recurring transactions (they can't, since they cannot be stored).

Why can't they be stored? Is it a legal requirement to prevent merchants without the CCV from using the credit card? ...oh wait

Because the CVV is used to indicate the "presence" of the customer at a transaction. CVV1 (which is on the magstripe) is used to indicate "card-present" physical transactions, CVV2 (printed on the back) is used for "customer just typed this in" non-physical transactions.
Post reply on HN