Live data from Hacker News

If you didn't cancel the credit card you used for linode.com, now is the time

news.ycombinator.com

61–70 of 138 posts

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#61

Signing up for on-line services is a good use for "virtual account numbers". This is a feature offered on some Citibank and Discover credit cards (maybe others) that allows you to generate a separate credit card number that's billed to your original account. The nice thing about them is that once a virtual account number has been billed by a vendor, it does not accept any charges in the future except from the same ve…

I wish other banks offered that functionality. I am not a fan of Citibank.

NetSpend is free and it doesn't cost to generate a Vitual Card. BTW, it works great for netflix....every month ;)

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#62
post #60

Tangentially: Why do merchants really need to store CC numbers? From the consumers' standpoint, there would be no difference if, during the first transaction, the merchant is issued some alterate key with which to charge the account. Each merchant would be issued their own key, so there would be no risk of a security breach spreading outside of the merchant.

Hetzner, which was hacked today, did so. They got a unique id back from their payment provider which they stored in their database in order to bill.

Depending on your payment provider, you will be however locked in and can't change anymore.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#63

Earlier quoted context omitted.

The fact that Linode stored the public and private keys in the same directory is strong evidence that they do not have any competence in security. Their reluctance to disclose the compromise of their customer's passwords and financial data is evidence that they are not trustworthy. So on one hand we have someone who is careful enough about their finances to use disposable prepaid cards for renting a VPS. On the other…

"stored the public and private keys in the same directory" People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate. Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups;…

You must be kidding. This is encryption 101. The private key is supposed to be moved to a secure location after key generation.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#64
post #45

Earlier quoted context omitted.

Why is using prepaid cards for online purchases fishy? - Prepaid cards impose an upper limit on what can be spent, so that if the card details leak out you are protected against losing more money than is on the card. They can't plunder your entire bank account. - Some people don't like the idea of having debt. By using a credit card you immediately have a debt whether you like it or not.

By using a credit card you immediately have a debt whether you like it or not. Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago…

Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#65
post #2

Thanks, I was thankfully canceled my card. Is there anyone else here that has had their card compromised?

I have seen a $780 purchase in one of my card (which is only used online in App Store, PayPal, Amazon and Linode) on April 27th. I dispute the purchase and request reissue of the card immediately. Since I also use this card physically few times (all before Linode incident) I wouldn't say for sure that Linode was responsible. (I'm not located in US but the purchase was from online store in US, I suspect it might be compromised online by some means.)

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#66

Earlier quoted context omitted.

"stored the public and private keys in the same directory" People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate. Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups;…

You must be kidding. This is encryption 101. The private key is supposed to be moved to a secure location after key generation.

Er, what? I thought the keypair was supposed to be generated in a secure location (such as your 0700 mode ~/.ssh directory), and then only the public half ever leaves.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#67

I haven't seen anything yet, and I tend to keep pretty close watch on it.

I haven't seen anything yet either. All of my accounts have some policy in place where they call us. It actually got annoying when my wife was "couponing" and we hit 5-6 stores in a couple hours. Always got a call. Comforting. Any charge in another country is set to be a flag. When we travel we make a call and let them know so it doesn't get flagged.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#68
post #60

Tangentially: Why do merchants really need to store CC numbers? From the consumers' standpoint, there would be no difference if, during the first transaction, the merchant is issued some alterate key with which to charge the account. Each merchant would be issued their own key, so there would be no risk of a security breach spreading outside of the merchant.

Mostly they don't. The payment provider stores this and provides that and the truncated PAN (the card number with digits masked by asterisks).

One of the things you pay payment providers for is for taking on the risk of the higher levels of PCI compliance.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#69
post #64
post #45

Earlier quoted context omitted.

By using a credit card you immediately have a debt whether you like it or not. Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago…

Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.

If I have a $10,000 credit limit and $0 balance, my debt is $10,000? At any moment I can be liable for up to $10,000? How does that work?

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#70
post #64
post #45

Earlier quoted context omitted.

By using a credit card you immediately have a debt whether you like it or not. Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago…

Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.

Your available credit line is not debt, and I can't recall ever hearing of anyone being held accountable for fraudulent purchases made against their account. Does this happen?
Post reply on HN