Live data from Hacker News

If you didn't cancel the credit card you used for linode.com, now is the time

news.ycombinator.com

31–40 of 138 posts

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#31
My credit card was recently reissued without my request. The accompanying letter said it was being reissued to prevent fraud, as a merchant had recently disclosed a compromise. It did not say which merchant, but not I suspect it could have been linode. Has anyone else had this happen?

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#32
post #27

What do you mean by "cancel"? If you mean have your card issuer give you a new card with a new number, and stop allowing charges using the old number, that isn't necessarily sufficient. You may have to close your underlying account. Visa and MasterCard both have updater services, which are available to some (but not all--I'm not sure what exactly the requirements are for access) merchants that accept their cards. The…

There is absolutely no risk that this would happen if you call and report your card as stolen. None.

Now, if you've already had a charge authorized, then yes, the issuers has to allow that charge to be captured, even if you cancelled the card in the interim. But your issuer can certainly tell you if there are any valid authorizations outstanding.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#33
post #13
post #2

Thanks, I was thankfully canceled my card. Is there anyone else here that has had their card compromised?

I haven't had anything odd yet. Ironically, Chase did flag my DigitalOcean charges last week.

Chase notified that a 3rd party was breached and my credit card was at risk. They sent me a new card two weeks ago. Figured it was because of linode.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#35

Signing up for on-line services is a good use for "virtual account numbers". This is a feature offered on some Citibank and Discover credit cards (maybe others) that allows you to generate a separate credit card number that's billed to your original account. The nice thing about them is that once a virtual account number has been billed by a vendor, it does not accept any charges in the future except from the same ve…

I wish other banks offered that functionality. I am not a fan of Citibank.

Get the Fidelity Amex from FIA (aka BofA). It's one of the few genuine 2% cashback cards, has no annual fee, no forex fees iirc, and lets you create "ShopSafe" numbers.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#36
post #34

WF opted to send me a new card out of nowhere, without explaining why they're sending me a new card. I suspect it's due to the linode breach.

My bank does this to me from time to time, without bothering to notify me. It seems incredibly insecure to me - I do have to call to activate it, but there are no "secret" questions asked during this process, just the last four digits of my social security number, and my zip code (and guess where the card gets sent to?)

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#37
Please provide a little more evidence than starting a flame war. Although it could in theory be true, it's a fairly baseless claim until you present a little more evidence.

For my online transactions I use prepaid cards that are easy to dispose of, and this card was used solely for linode.

Couldn't the online card issuer be to blame? How do we know you haven't mistakenly used it for anything else? The fact that you use prepaid cards for online purchases seems fishy to me in the first place (which is just as baseless of a claim on my part as yours is here).

groceries, cheese

How do you use a online generated CC for groceries and cheese??

From Linode:

Credit card numbers in our database are stored in encrypted format, using public and private key encryption. The private key is itself encrypted with passphrase encryption and the complex passphrase is not stored electronically. Along with the encrypted credit card, the last four digits are stored in clear text to assist in lookups and for display on things like your Account tab and payment receipt emails. We have no evidence decrypted credit card numbers were obtained.

https://blog.linode.com/2013/04/16/security-incident-update/

TL;DR - This is unfair to Linode and I think the community (who uses their service quite frequently) would appreciate if you took it up with them first, before you start a smear campaign.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#38
post #23

Bank Simple actually reached out to me and asked me if I wanted to cancel my card. I did. But I was impressed that they saw that I'd had charges from them and knew about the security issues.

I also use Simple and I've been very happy with their customer support. Not having checks has been a pain in a few cases, but I definitely prefer it over a brick and mortar. I have a few invitations on my account if anyone is interested.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#40
post #37

Please provide a little more evidence than starting a flame war. Although it could in theory be true, it's a fairly baseless claim until you present a little more evidence. For my online transactions I use prepaid cards that are easy to dispose of, and this card was used solely for linode. Couldn't the online card issuer be to blame? How do we know you haven't mistakenly used it for anything else? The fact that you u…

The fact that Linode stored the public and private keys in the same directory is strong evidence that they do not have any competence in security. Their reluctance to disclose the compromise of their customer's passwords and financial data is evidence that they are not trustworthy.

So on one hand we have someone who is careful enough about their finances to use disposable prepaid cards for renting a VPS. On the other, a company that doesn't understand how encryption works and had to be forced to disclose the attack by the FBI.

Which do you believe?

Post reply on HN