Live data from Hacker News

Hetzner Servers Compromised

wiki.hetzner.de

81–90 of 133 posts

Re: Hetzner Servers Compromised

#81

Earlier quoted context omitted.

> I just wish that they used bcrypt instead of a salted SHA256 but at least it's salted (and anyway in my case I never reuse passwords so no big deal). If they fall under PCI:DSS, they might not be able to use bcrypt since it isn't an official recommended standard. (I am of course assuming that they mean PBKDF2 when they say salted SHA256.)

https://www.pcisecuritystandards.org/pdfs/pci_dss_glossary_v... seems to list Blowfish as an approved standard as far as the PCI standards group is concerned.

Thanks for that link. I think that means blowfish is approved as a standard encryption algorithm, but that doesn't mean it is approved as a standard way to store passwords.

From http://security.stackexchange.com/questions/4781/do-any-secu..., I gather this: bcrypt is neither a NIST or FIPs standard, but PBKDF2 is.

> For any business required to comply with U.S. NIST or FIPS standards, bcrypt is not a valid option. Check every nation's laws and regulations separately if you do business there, of course.

However, from a comment on this other answer: http://security.stackexchange.com/questions/11552/would-it-m..., someone mentions this:

> As far as I know, PCI doesn't specify actual technology, especially Encryption specifications. The legal cases I've seen support what's technically feasible, not technically ideal or perfect. I'm sure either one [bcrypt or PBKDF2] meets PCI requirements

An opinion shared by many people that deal with PCI, is that you follow PCI not to secure your systems, but to limit your exposure to PCI fines and remedies. It seems like it is a rock-solid defense for PCI compliance to choose the algorithm that is certified by NIST.

Re: Hetzner Servers Compromised

#82
post #25

Earlier quoted context omitted.

I am not a Hetzner customer, but the comment about Nagios perked up my ears. I work with some clients who have Nagios running in their environment, and I'm wondering if there is an exploit in Nagios or if it's just a coincidence that this was where they noticed the infection?

It makes me wonder if there's any connection with the recent Drupal Security problem (they cited a "third-party software installed on the Drupal.org server infrastructure" but they haven't - afaik - disclosed the software name yet)

Nope, there is not, the two are fundamentally different.

Re: Hetzner Servers Compromised

#83
post #72

Earlier quoted context omitted.

So "yes" – what would you do if you had, say, several hundred (or several thousand) servers?

If I have that many servers then I can assume I have a large budget for security, right? I would make a password entering automation system. Ensure that that system is dead-simple and secured to death. It must run no other services, firewalled to death even from the intranet, physically secured in a cage, and must be off most of the time. It is only to be turned on when booting a system, and turning it on not only re…

Wait, this sounds way harder than the previous solution and entering the password over a remote IPMI console.

Re: Hetzner Servers Compromised

#84
Hetzner is very open, transparent, and exact in their communication about this. I'm not a customer but I really like that they didn't try to dress anything up and were forthcoming with information.

Re: Hetzner Servers Compromised

#85
post #14

Several events with Linode, now Hetzner. These are relatively "premier," high-quality hosting companies, you can count on thousands and thousands of companies to pay even less attention. Yet every time, the discussion is only about one specific company, without seeing any broader pattern. When are we ever going to draw the conclusion that popular hosting companies (and, actually related, facilities like RubyGems) are…

Is it just the customer account details that apparently make hosting companies attractive targets. If that's the case, I'm wondering why we're not seeing more breaches from all over the e-commerce world. Why just hosting companies?

Re: Hetzner Servers Compromised

#86
post #69
post #67

Earlier quoted context omitted.

"you have to send them scans of personal documents (such as passport, drivers license or similar)." What? Seriously? "In addition to that, we delete that information after 21 days." Hmm, do they delete the info that ends up on backup copies? How do you know they even actually delete it in 21 days? It's not like there is a third party even auditing which you can rely on. (Not that I'd ever do that for something like t…

Yes seriously, here is what they asked me on first order with them: "Since you're a new customer with Hetzner, we ask you for a scan of your passport or ID card (authenticity check). It's only necessary for your first order with us. Please send the scan by fax or as an email attachment." When they say they delete it after 21 days, as they did in the mail I've just received, I trust them. I find their communication on…

not true for all customers - I needed to send them nothing of the kind (in the US)

Re: Hetzner Servers Compromised

#87
post #4
post #2

Full text of the email sent to cutomers: Dear Client At the end of last week, Hetzner technicians discovered a "backdoor" in one of our internal monitoring systems (Nagios). An investigation was launched immediately and showed that the administration interface for dedicated root servers (Robot) had also been affected. Current findings would suggest that fragments of our client database had been copied externally. As…

Have all Hetzner customers received this mail? I currently have a couple of servers with them and have received nothing yet.

Thanks all, finally got my mail. I was worried my account was hijacked! Panic over

Re: Hetzner Servers Compromised

#88
post #53

The info in the mail regarding the safety of credit card info contradicts with the linked FAQ. FAQ: Bank details are encrypted (two-way) in the database. However, it cannot be excluded that the attacker/s have also been able to obtain access to the key. Mail: With credit cards, only the last three digits of the card number, the card type and the expiry date are saved in our systems. All other card data is saved solel…

Hetzner probably has many customers who pay with debit card/recurring direct debit instead of credit card. It's quite common in Germany.

Re: Hetzner Servers Compromised

#89
post #84

Hetzner is very open, transparent, and exact in their communication about this. I'm not a customer but I really like that they didn't try to dress anything up and were forthcoming with information.

Doesn't surprise me. I'm a customer and the whole experience feels like this.

Re: Hetzner Servers Compromised

#90
post #46

Something was happening with their routers, too. Using PingPlotter to one of my servers shows severe packet loss on the hos-bb2.juniper2.rz19.hetzner.de router. I see it just cleared up for now. Still, I'm moving my traffic to other locations till this blows over.

That might be because various parts of germany are flooded at the moment. One of Hetzners datacenters is located in Falkenstein near Regensburg and others might me affected too
Post reply on HN