In my opinion these are the real questions us Linode customers want to know the answers to, sooner rather than later.
Security incident update
121–130 of 282 posts
Re: Security incident update
#122Hey Linode how about addressing the claims that the private and public keys were both stored in the same location on the compromised manager server. Is that true? And if so, why wasn't it revealed? Did they get access to any credit card information or was it truly just the last 4 digits used for lookup purposes? In my opinion these are the real questions us Linode customers want to know the answers to, sooner rather…
Re: Security incident update
#123The one thing that puzzles me above anything else about this whole thing is: "Linode uses ColdFusion". I mean, you have this Linux company that's pretty much an open source champion to us Linux guys and then... Adobe ColdFusion. Really? I know nothing about ColdFusion, don't get me wrong, I just find it an incredibly odd choice for a Linux company. That having been said, I think Linode just learnt a really unpleasant…
Linode is a Linux company, but it's also a company founded in 2002-3. Back then, there weren't many great options for web programming and ColdFusion would have made a degree of sense (PHP 4.0 was released in 2000, and Ruby on Rails 1.0 didn't appear until 2004; Django was released in 2005). A modern, reasonably-secure web stack in those days really did mean "PHP with register_globals=Off". (Facebook and YouTube were…
Re: Security incident update
#124The hacker has claimed the public and private key were both stored on the same machine and both accessible. The only protection left is the passphrase then. Various people have reported fraudulent activity on their CCs. Personally, I think Linode didn't mess this up as badly as many other companies. The statement took a while to appear but it's there. As a Linode customer myself I can neither report anything unusual…
The fraud won't occur till the database is released and the private key is cracked.
Re: Security incident update
#125"Along with the encrypted credit card, the last four digits are stored in clear text to assist in lookups and for display on things like your Account tab and payment receipt emails." I really don't see the need for that at all. What sort of credit card "lookup" are they doing exactly?
Re: Security incident update
#126The hacker has claimed the public and private key were both stored on the same machine and both accessible. The only protection left is the passphrase then. Various people have reported fraudulent activity on their CCs. Personally, I think Linode didn't mess this up as badly as many other companies. The statement took a while to appear but it's there. As a Linode customer myself I can neither report anything unusual…
> Various people have reported fraudulent activity on their CCs Most likely not even related
There were 11 million american victims of identity theft in 2011 (outta 400 million) for a ratio of about 1 in 40 of the general population gets p0wned per year. Obviously not all ID theft is CC theft but I'd guess a lot of it is. Based on friends and family experience getting a CC number stolen every four decades of use passes the smell test so I will go with that.
A quote from prweb.com found by google: "Started in 2003, Linode has grown to over 45,000 customers". I wonder what year that quote is from. Still "forty five thousand" is probably not totally ridiculous. It makes sense looking at their hostname scheme, ip space allocations as per whois, and some educated guesses. Lots of people including myself like linode.
So assuming the average linode customer is the same as the average joe6pack then 45000/40/365 = about 3 linode customers should get p0wned per day regardless of any linode problem. To make my inner EE happy I'll call the "noise level" about 3/day and evaluate the SNR based on that noise level to see if there's a signal of p0wnership.
Obviously the two reports over the course of a couple days is not 100% of all linode customers who got p0wned. But it does show that two reports doesn't really prove anything.
Now, as a made up example, 900 reports over 3 days would be a HUGE indicator "something" happened. But at a predicted noise level of about ten or so over three days, two reported is down there in or below the noise. So, as a long term linode customer I'm not freaking out (yet). My CC does email me every time a charge is made, and nothing weird has been seen. All quiet on the western front.
Re: Security incident update
#127I am curious why the fix for this specific vulnerability[0] wasn't implemented even though it's been out for a week now (obviously slightly less by the time they were affected).
[0] http://www.adobe.com/support/security/bulletins/apsb13-10.ht...
Re: Security incident update
#128I don't know why so many guys here who obviously are not customers of linode care about this case so much, I've been a user of linode for 5 years, it's a company that you know you can trust, that's simply what I can tell from my experience.
I am a former customer who was burned the last time they were hacked and were less than truthful. Now it has happened again and nothing has changed. Clearly non existent security audits (cleartext passwords ?) and still lots of unanswered questions. It should be crystal clear by now that Linode is fundamentally untrustworthy.
I'd trust them more than the 16 yr old waitress at the local restaurant who is legally judgment proof and as a juvenile frankly has no punishment related reason not to rip me off. Every time I pay with a CC at a restaurant and don't get my number stolen it pretty much restores my faith in humanity. Or I'd trust them more than the seedy psuedo-organized crime operator of my local gas station. Or the supermarket checker, again, juvenile and judgement proof.
Would I date/marry/have kids with linode? Well probably not that much trust. Luckily rather than sharing precious bodily fluids with them, all I've been sharing is a 16 digit number which if lost can be replaced at no cost to myself other than some time.
Where it gets fuzzy is something in the thousands of dollar range. Would I trust linode with the keys to my car? Well... it is insured, but the deductible is about a kilobuck because for me that's (more or less) pocket change...
Re: Security incident update
#129I understand patch cycles and I'm not hating on them for not having the latest update when it's been less than a week but still...
Re: Security incident update
#130Earlier quoted context omitted.
Well, the official statement re: the passphrase is: > @Eivind – our private key is stored only in encrypted format. The passphrase is not guessable, sufficiently long and complex, not based on dictionary words, and not stored anywhere but in our heads.
> in our heads So it's short enough to remember and likely has some sort of pattern. There's a limit to what a person can remember, lower if there are several people that have to remember it.