Linode Manager Two-Step Authentication
11–20 of 87 posts
Re: Linode Manager Two-Step Authentication
#12Re: Linode Manager Two-Step Authentication
#13After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…
Re: Linode Manager Two-Step Authentication
#14This will do absolutely nothing if Linode themselves are hacked, which is what happened the past two (100% of the) times.
Re: Linode Manager Two-Step Authentication
#15After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…
Nice, but has nothing to do with the issues they experienced recently: Still runs on cold fusion, still they do not understand PKI( more tweets about how awesome the passphrase is on your private key, you know the one in adversarial hands...confidence + 10!....)
Re: Linode Manager Two-Step Authentication
#16Re: Linode Manager Two-Step Authentication
#17After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…
Re: Linode Manager Two-Step Authentication
#18This will do absolutely nothing if Linode themselves are hacked, which is what happened the past two (100% of the) times.
Ok, so they get hacked and passwords are stolen and those are cracked. Guess what? They're useless. With 2FA, the attackers still won't be able to get in.
Re: Linode Manager Two-Step Authentication
#19Earlier quoted context omitted.
Ok, so they get hacked and passwords are stolen and those are cracked. Guess what? They're useless. With 2FA, the attackers still won't be able to get in.
The problem wasn't in passwords being stolen. CC information was allegedly leaked.
Re: Linode Manager Two-Step Authentication
#20just a warning: I just enabled it and it wasn't working with my account & google authenticator for android. I had to call customer support in order to disable the feature so I could login into my account again.