Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

381–390 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#381
post #288

Earlier quoted context omitted.

Or until they let other customers see all the data on VMs that you've shut down. Oh wait, that already happened: http://www.wired.com/wiredenterprise/2013/04/digitalocean/

DigitalOcean is new and they fixed the problem the same day the article was written: https://www.digitalocean.com/blog_posts/resolved-lvm-data-is... If I had a choice between a VPS provider who either: - Only has large issues (eg. leaks credit card data) and goes weeks without reporting them to customers, or - Has lots of small issues (eg. forgetting to clean the free space of LVM volumes) but fixes them the same day…

There is no evidence to suggest that Linode leaked credit card data.

Personally I took precautionary measures and just called my bank to replace my credit card, which I think is the sane approach, as when it comes to hacking you have to assume the worst.

However, your statement on "has lots of small issues but fixes them the same day" is just stupidly childish. Linode's issues are bigger just because they are a bigger target.

Re: Linode hacked, CCs and passwords leaked

#382
post #380

Earlier quoted context omitted.

> Am I the only one who is more confused about why there are compiled java classes and AMI BIOS updates in the www directory than about the hacking itself? Sysadmins being lazy. Somebody needs to get a file from a workstation to a remote machine. There's a firewall in the way somewhere that prevents SSH directly between them or one of them is a Windows box that isn't running an SSH server. The "correct" solution is c…

Something that took me a long time to notice was that you can actually copy files directly over a RDP session from/to the local machine or other RDP sessions using the clipboard.. Even nested RDPs. Has been an absolute timesaver to know about when doing Windows admin work.

Doesn't work for me when using an RDP client on Linux. Is this an RDP spec thing or a microsoft only feature?

Re: Linode hacked, CCs and passwords leaked

#385
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

It depends on how sophisticated the identify theft is. I had a good friend who was taken for about $9000 in credit card fraud in 1998/1999, with Well Fargo. It took him the better part of six months, and endless correspondence with WF to prove all of the purchases were not his. There are lots of stories of people who were financially wiped out, to the point of bankruptcy, because of Credit Card/Identify fraud.

With that said - almost everyone seems to feel comfortable handing out their credit card to random taxi drivers, waiters, sales staff - with no idea whether a copy of their information is being taken down. Heck - if you give them the Credit Card, they even get your CCV as well.

Re: Linode hacked, CCs and passwords leaked

#386

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Anyone know of any good way to export linode images to other VPS providers? Seems like I'll have to be doing it manually.

Check out http://www.cloudconverter.com - move from Linode to pretty much any other provider out there.

Re: Linode hacked, CCs and passwords leaked

#387
post #380

Earlier quoted context omitted.

Something that took me a long time to notice was that you can actually copy files directly over a RDP session from/to the local machine or other RDP sessions using the clipboard.. Even nested RDPs. Has been an absolute timesaver to know about when doing Windows admin work.

Doesn't work for me when using an RDP client on Linux. Is this an RDP spec thing or a microsoft only feature?

I think it depends on how you mount your clipboard/drives on rdp connect. To get it right with windows you just check the share clipboard/share drive checkboxes and off to the races. With rdesktop you have to throw the -r flag and mount a clip board and then the -r flag and mount a drive. Not sure about other Linux clients but I'm sure there's a similar option in all of them.

Re: Linode hacked, CCs and passwords leaked

#388
06:15 hello, i forgot my password and linode's email reminder service doesn't work. i checked spam box but there's no email from linode. 06:15 ryannn: can you give him the password? 06:15 shmoon: damn you, you beat me to it! 06:23 shmoon, sorry I only have the sources on my server 06:23 db is on my desktop 06:24 ryannn: so your not in this to do large scale damage, only after a few clients?

Re: Linode hacked, CCs and passwords leaked

#389
post #288

Earlier quoted context omitted.

Or until they let other customers see all the data on VMs that you've shut down. Oh wait, that already happened: http://www.wired.com/wiredenterprise/2013/04/digitalocean/

DigitalOcean is new and they fixed the problem the same day the article was written: https://www.digitalocean.com/blog_posts/resolved-lvm-data-is... If I had a choice between a VPS provider who either: - Only has large issues (eg. leaks credit card data) and goes weeks without reporting them to customers, or - Has lots of small issues (eg. forgetting to clean the free space of LVM volumes) but fixes them the same day…

Wait a second.. you consider a provider giving data from your VMs to another random customer a SMALL issue?

Maybe you don't have anything of importance on your VMs, but plenty of people do. That data could contain credit card data, passwords, etc, etc, etc. It is very much a large issue.

Re: Linode hacked, CCs and passwords leaked

#390

Earlier quoted context omitted.

There's very nice utility called Ghost 4 Unix that makes the whole thing even easier: http://www.feyrer.de/g4u/

Looks like overkill for a simple one time task that can easily be handled the UNIX way. Worth looking into if you need to do this alot-

Your procedure already requires booting out of live cd, and then uses "unix way" that might be easy to screw up for less advanced people, so using G4U simplifies it substantially, does the same good job and by no means is a 'overkill' ;)
Post reply on HN