Live data from Hacker News

Security incident update

blog.linode.com

121–130 of 282 posts

Re: Security incident update

#121
Hey Linode how about addressing the claims that the private and public keys were both stored in the same location on the compromised manager server. Is that true? And if so, why wasn't it revealed? Did they get access to any credit card information or was it truly just the last 4 digits used for lookup purposes?

In my opinion these are the real questions us Linode customers want to know the answers to, sooner rather than later.

Re: Security incident update

#122

Hey Linode how about addressing the claims that the private and public keys were both stored in the same location on the compromised manager server. Is that true? And if so, why wasn't it revealed? Did they get access to any credit card information or was it truly just the last 4 digits used for lookup purposes? In my opinion these are the real questions us Linode customers want to know the answers to, sooner rather…

> Credit card numbers in our database are stored in encrypted format, using public and private key encryption. The private key is itself encrypted with passphrase encryption and the complex passphrase is not stored electronically.

Re: Security incident update

#123
post #85

The one thing that puzzles me above anything else about this whole thing is: "Linode uses ColdFusion". I mean, you have this Linux company that's pretty much an open source champion to us Linux guys and then... Adobe ColdFusion. Really? I know nothing about ColdFusion, don't get me wrong, I just find it an incredibly odd choice for a Linux company. That having been said, I think Linode just learnt a really unpleasant…

Linode is a Linux company, but it's also a company founded in 2002-3. Back then, there weren't many great options for web programming and ColdFusion would have made a degree of sense (PHP 4.0 was released in 2000, and Ruby on Rails 1.0 didn't appear until 2004; Django was released in 2005). A modern, reasonably-secure web stack in those days really did mean "PHP with register_globals=Off". (Facebook and YouTube were…

There was a heck of a lot of Java out there used for web development around that time. But your point still stands - Java probably would've been a lot more difficult to setup and maintain than CF.

Re: Security incident update

#124
post #4

The hacker has claimed the public and private key were both stored on the same machine and both accessible. The only protection left is the passphrase then. Various people have reported fraudulent activity on their CCs. Personally, I think Linode didn't mess this up as badly as many other companies. The statement took a while to appear but it's there. As a Linode customer myself I can neither report anything unusual…

It'd be worth having a read of the logs, if true it appears that the attack was only to compromise a specific target.

The fraud won't occur till the database is released and the private key is cracked.

Re: Security incident update

#125

"Along with the encrypted credit card, the last four digits are stored in clear text to assist in lookups and for display on things like your Account tab and payment receipt emails." I really don't see the need for that at all. What sort of credit card "lookup" are they doing exactly?

It is fairly standard. Go look at your Amazon account, you'll see the last four digits.

Re: Security incident update

#126
post #12
post #4

The hacker has claimed the public and private key were both stored on the same machine and both accessible. The only protection left is the passphrase then. Various people have reported fraudulent activity on their CCs. Personally, I think Linode didn't mess this up as badly as many other companies. The statement took a while to appear but it's there. As a Linode customer myself I can neither report anything unusual…

> Various people have reported fraudulent activity on their CCs Most likely not even related

Well, lets think about it a bit. It turns out the numbers are ridiculously hard to find although I'm a pretty good searcher/infovore. Better info would be appreciated. Anyway the best I could find was two claims:

There were 11 million american victims of identity theft in 2011 (outta 400 million) for a ratio of about 1 in 40 of the general population gets p0wned per year. Obviously not all ID theft is CC theft but I'd guess a lot of it is. Based on friends and family experience getting a CC number stolen every four decades of use passes the smell test so I will go with that.

A quote from prweb.com found by google: "Started in 2003, Linode has grown to over 45,000 customers". I wonder what year that quote is from. Still "forty five thousand" is probably not totally ridiculous. It makes sense looking at their hostname scheme, ip space allocations as per whois, and some educated guesses. Lots of people including myself like linode.

So assuming the average linode customer is the same as the average joe6pack then 45000/40/365 = about 3 linode customers should get p0wned per day regardless of any linode problem. To make my inner EE happy I'll call the "noise level" about 3/day and evaluate the SNR based on that noise level to see if there's a signal of p0wnership.

Obviously the two reports over the course of a couple days is not 100% of all linode customers who got p0wned. But it does show that two reports doesn't really prove anything.

Now, as a made up example, 900 reports over 3 days would be a HUGE indicator "something" happened. But at a predicted noise level of about ten or so over three days, two reported is down there in or below the noise. So, as a long term linode customer I'm not freaking out (yet). My CC does email me every time a charge is made, and nothing weird has been seen. All quiet on the western front.

Re: Security incident update

#127
I was going to post a TL;DR but the article is pretty short. Suffice it to say there are things in the database that should not be there. Encrypted credit card numbers along with the public and private keys? Plain text Lish passwords?

I am curious why the fix for this specific vulnerability[0] wasn't implemented even though it's been out for a week now (obviously slightly less by the time they were affected).

[0] http://www.adobe.com/support/security/bulletins/apsb13-10.ht...

Re: Security incident update

#128

I don't know why so many guys here who obviously are not customers of linode care about this case so much, I've been a user of linode for 5 years, it's a company that you know you can trust, that's simply what I can tell from my experience.

I am a former customer who was burned the last time they were hacked and were less than truthful. Now it has happened again and nothing has changed. Clearly non existent security audits (cleartext passwords ?) and still lots of unanswered questions. It should be crystal clear by now that Linode is fundamentally untrustworthy.

Typical hackernews binary thinking. Trust is a spectrum not a binary.

I'd trust them more than the 16 yr old waitress at the local restaurant who is legally judgment proof and as a juvenile frankly has no punishment related reason not to rip me off. Every time I pay with a CC at a restaurant and don't get my number stolen it pretty much restores my faith in humanity. Or I'd trust them more than the seedy psuedo-organized crime operator of my local gas station. Or the supermarket checker, again, juvenile and judgement proof.

Would I date/marry/have kids with linode? Well probably not that much trust. Luckily rather than sharing precious bodily fluids with them, all I've been sharing is a 16 digit number which if lost can be replaced at no cost to myself other than some time.

Where it gets fuzzy is something in the thousands of dollar range. Would I trust linode with the keys to my car? Well... it is insured, but the deductible is about a kilobuck because for me that's (more or less) pocket change...

Re: Security incident update

#129
How can it be a 0-day vulnerability if it was addressed in a patch that came out more than a day ago?

I understand patch cycles and I'm not hating on them for not having the latest update when it's been less than a week but still...

Re: Security incident update

#130
post #76

Earlier quoted context omitted.

Well, the official statement re: the passphrase is: > @Eivind – our private key is stored only in encrypted format. The passphrase is not guessable, sufficiently long and complex, not based on dictionary words, and not stored anywhere but in our heads.

> in our heads So it's short enough to remember and likely has some sort of pattern. There's a limit to what a person can remember, lower if there are several people that have to remember it.

You've assumed that everyone involved has the entire passphrase.
Post reply on HN