Live data from Hacker News

GoGrid-hosted server hacked between provisioning and first login

plus.google.com

1–10 of 23 posts

Re: GoGrid-hosted server hacked between provisioning and first login

#2
From Lore Sjöberg:

My former server host, GoGrid, tells me (via my business partner) that it's my fault my server was hacked fifteen hours after they installed it, because I didn't log into it before it was hacked.

To paraphrase freely, GoGrid is admitting that their security is so shitty that I should have known not to trust them to install a safe server. I should have been so suspicious of their policies and practices that I should have rushed to log into the server to lock it down as soon as they made it live, knowing that their default setup is such a screen door that hacking within a matter of hours was inevitable.

And, because of this, GoGrid is not refunding a cent of my year of pre-paid money.

Re: GoGrid-hosted server hacked between provisioning and first login

#6
post #3

Frankly, I don't buy this at all. It is very difficult in 2011 to provision a server that is really vulnerable by default. I suspect that the person who posted this was in some other way compromised, and is blaming it on GoGrid.

Yup, the fact that he didn't share anything about how the server was hacked is a bit suspicious.

Re: GoGrid-hosted server hacked between provisioning and first login

#7

I'm guessing that GoGrid provisioned the server, then sent him an email with his password. After first login, he would have been prompted to change his password, but somebody got to his email before he logged in...

Maybe they weren't sending truly random one-time-use passwords.

Re: GoGrid-hosted server hacked between provisioning and first login

#8
post #3

Frankly, I don't buy this at all. It is very difficult in 2011 to provision a server that is really vulnerable by default. I suspect that the person who posted this was in some other way compromised, and is blaming it on GoGrid.

I don't know what happened in this case, but it doesn't seem very difficult:

1. Configure server to use password authentication and allow logins from anywhere.

2. Send password to user via unencrypted email.

There's a reason that people are uncomfortable receiving passwords via email.

Re: GoGrid-hosted server hacked between provisioning and first login

#9

Just wondering, can't you just format the server again? Or doesn't GoGrid provide that option at all? Since it's a brand new server, I guess there's no problem in formatting and installing it again.

That's what I was thinking. When you rent a server you're renting hardware and a connection. If you screw up the software side (like getting hacked) you can always wipe the drive and reinstall. Why would you want to cancel a year long contract because you're set back an hour to reimage?

Re: GoGrid-hosted server hacked between provisioning and first login

#10

Just wondering, can't you just format the server again? Or doesn't GoGrid provide that option at all? Since it's a brand new server, I guess there's no problem in formatting and installing it again.

That's what I was thinking. When you rent a server you're renting hardware and a connection. If you screw up the software side (like getting hacked) you can always wipe the drive and reinstall. Why would you want to cancel a year long contract because you're set back an hour to reimage?

Because the company may have demonstrated both a carelessness about security and poor customer service on day 1?
Post reply on HN