Live data from Hacker News

Linode Manager Two-Step Authentication

blog.linode.com

11–20 of 87 posts

Re: Linode Manager Two-Step Authentication

#13

After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…

Of course the 2FA wouldn't prevent it from being hacked, but that's not the point of it. The point is that even if someone gets the password and cracks it, it's still useless as the attacker doesn't have the other factor.

Re: Linode Manager Two-Step Authentication

#14
post #11

This will do absolutely nothing if Linode themselves are hacked, which is what happened the past two (100% of the) times.

Ok, so they get hacked and passwords are stolen and those are cracked. Guess what? They're useless. With 2FA, the attackers still won't be able to get in.

Re: Linode Manager Two-Step Authentication

#15

After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…

This was exactly what I thought of as well.

Nice, but has nothing to do with the issues they experienced recently: Still runs on cold fusion, still they do not understand PKI( more tweets about how awesome the passphrase is on your private key, you know the one in adversarial hands...confidence + 10!....)

Re: Linode Manager Two-Step Authentication

#17

After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…

FWIW they claim the private key was encrypted. Granted, having it air-gapped as much as possible is even better.

Re: Linode Manager Two-Step Authentication

#18
post #14
post #11

This will do absolutely nothing if Linode themselves are hacked, which is what happened the past two (100% of the) times.

Ok, so they get hacked and passwords are stolen and those are cracked. Guess what? They're useless. With 2FA, the attackers still won't be able to get in.

The problem wasn't in passwords being stolen. CC information was allegedly leaked.

Re: Linode Manager Two-Step Authentication

#19
post #18
post #14

Earlier quoted context omitted.

Ok, so they get hacked and passwords are stolen and those are cracked. Guess what? They're useless. With 2FA, the attackers still won't be able to get in.

The problem wasn't in passwords being stolen. CC information was allegedly leaked.

Allegedly? They admitted it was.

Re: Linode Manager Two-Step Authentication

#20

just a warning: I just enabled it and it wasn't working with my account & google authenticator for android. I had to call customer support in order to disable the feature so I could login into my account again.

Would you mind sharing details ( process wise) of what they did to validate that it was a legitimate request from the account holder?
Post reply on HN