Live data from Hacker News

If you didn't cancel the credit card you used for linode.com, now is the time

news.ycombinator.com

131–138 of 138 posts

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#131

Earlier quoted context omitted.

Get the Fidelity Amex from FIA (aka BofA). It's one of the few genuine 2% cashback cards, has no annual fee, no forex fees iirc, and lets you create "ShopSafe" numbers.

Are you sure it is the amex card that supports shopsafe? I thought Amex discontinued their similar product _years_ ago.

It's not an Amex issued by American Express, it's a card issued by Bank of America that is processed on the Amex network.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#132

Earlier quoted context omitted.

The fact that Linode stored the public and private keys in the same directory is strong evidence that they do not have any competence in security. Their reluctance to disclose the compromise of their customer's passwords and financial data is evidence that they are not trustworthy. So on one hand we have someone who is careful enough about their finances to use disposable prepaid cards for renting a VPS. On the other…

"stored the public and private keys in the same directory" People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate. Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups;…

And if you have the private key, you can generate the public key! You should never store the private key anywhere!

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#133
post #88

Earlier quoted context omitted.

How does storing the public key on the key bastion make it useless?

The public key is used by the webserver to encrypt credit card data. If it was stored in the key bastion, it wouldn't be available to the webserver.

Generally, you will have many copies of the public key on many servers.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#134

Earlier quoted context omitted.

Are you sure it is the amex card that supports shopsafe? I thought Amex discontinued their similar product _years_ ago.

It's not an Amex issued by American Express, it's a card issued by Bank of America that is processed on the Amex network.

Interesting. Thanks for the info.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#135
post #132

Earlier quoted context omitted.

"stored the public and private keys in the same directory" People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate. Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups;…

And if you have the private key, you can generate the public key! You should never store the private key anywhere !

Not even the ram of the crypto module doing the work!

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#136
post #70
post #64

Earlier quoted context omitted.

Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.

Your available credit line is not debt, and I can't recall ever hearing of anyone being held accountable for fraudulent purchases made against their account. Does this happen?

I wound up being held accountable for a small amount because I missed a deadline in the follow-up paperwork. So yes, it happens, but only when it doesn't matter much.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#137

Earlier quoted context omitted.

I've got an account with Bank of America and they have that feature as well. Downside, none of their service reps even know it exists, even worse they are slowly phasing it out (making it more and more difficult to find) even-though it is a feature I absolutely love.

Could you point me in the direction of finding this feature? I always thought BofA did not have this and would like to use it while I can.

If you have a Bank of America credit card you will find ShopSafe under "Information and Services" tab when you click on the card in question.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#138
post #70
post #64

Earlier quoted context omitted.

Your balance is irrelevant - your available credit line is debt, as at any moment you can be liable for up to that amount.

Your available credit line is not debt, and I can't recall ever hearing of anyone being held accountable for fraudulent purchases made against their account. Does this happen?

Credit card terms vary from country to country.

Here (Singapore) card conditions were recently changed so that you would only be liable for the first $100 of fraudulent transactions (assuming you can prove it wasn't you). I think the bank can still hold you liable for more if they find you were negligent about guarding your card details.

Prior to these condition changes, I remember being told by the bank that you would be liable for all charges incurred before you had reported the card physically stolen or lost.

Post reply on HN