Earlier quoted context omitted.
Stop acting so dramatic. There's no evidence that there was any security breach. People on IRC are saying this is FUD. zectorpt: no zectorpt: nothing was "hacked", but old stuff got posted again
Which is blatantly false, if it was "old stuff being posted again" then the mysql credentials wouldn't have been working 60 minutes ago.
Linode hacked again?
41–50 of 52 posts
Re: Linode hacked again?
#42Re: Linode hacked again?
#43Re: Linode hacked again?
#44So I switched to Digital Ocean after the last Linode security fiasco and I can't say I regret it. Should you decide to switch to another VPS provider I strongly recommend you cite the security problems when they ask you why you're closing your account. The only reliable way to get the security message across to technical managers and business people alike is to make it about money. That said the fact that this has ha…
Of course, Digital Ocean has had its own problems lately with not properly scrubbing decommissioned VPS containers... so to some degree, data security is not a Linode specific problem. And for that matter it is not just because someone is recycling passwords (bad), but because it is by nature one of the most fundamental and pervasive security challenges with any VPS hosting. Your AWS node might be perfectly secure, but it might be sharing a physical rack with a Russian botnet and you'd have no way to know.
Bottom line, if you are using a shared environment there is always some risk of having bad neighbors, experiencing disruption at the supervisory layer or of your data bleeding over into an untrusted location. Your application security design should be planned accordingly, and the choice of VPS host is only one part of that equation.
Re: Linode hacked again?
#45Earlier quoted context omitted.
Stop acting so dramatic. There's no evidence that there was any security breach. People on IRC are saying this is FUD. zectorpt: no zectorpt: nothing was "hacked", but old stuff got posted again
Which is blatantly false, if it was "old stuff being posted again" then the mysql credentials wouldn't have been working 60 minutes ago.
Re: Linode hacked again?
#46Earlier quoted context omitted.
the security hack was always on back of my mind. what really made me move away from linode is really their inability to accept paypal. Luckily, digitalocean accepted paypal. Also their $5 servers cannot be beat. Sure, linode has some good panels but it was more than I can chew and more than I needed. Digitalocean also had a good amount of docmentation to do everything I needed without filing a ticket.
A lot of merchants (e.g. Amazon) don't use PayPal because is isn't a real bank, and so isn't beholden by laws associated with banks. The terms of service state that you cannot seek any legal recourse from them should your account be shut down. How could this affect a VPS provider? Say a customer hosts a porn site, or a gun-selling site, or something else PayPal disagrees with. PayPal shuts the merchant's account down…
I am very sympathetic to anyone not wanting to use paypal for these reasons.
It is too big a risk, especially for something like a VPS provider that needs the recurring payments.
Re: Linode hacked again?
#47Re: Linode hacked again?
#48My guess is that this is an old development DB that was left on a server that may have been forgotten about.
Re: Linode hacked again?
#49So I switched to Digital Ocean after the last Linode security fiasco and I can't say I regret it. Should you decide to switch to another VPS provider I strongly recommend you cite the security problems when they ask you why you're closing your account. The only reliable way to get the security message across to technical managers and business people alike is to make it about money. That said the fact that this has ha…
Re: Linode hacked again?
#50Earlier quoted context omitted.
That doesn't really make any sense. That's not a MySQL default, so you're saying they intentionally set the root user password to '*'? I'm not sure I buy that.
They're also running MySQL 3.