Is there any confirmation on this? [edit] Just looked at twitter, this tweet doesn't look good: https://twitter.com/Jamiesingleton/status/322730588459114500 But it may just be random coincidence. [edit again] Links from slashdot article: IRC chat: http://turtle.dereferenced.org/~nenolod/linode/linode-abridg... Link in IRC chat (i think it is of linode.com's web directory): https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc
Linode hacked, CCs and passwords leaked
101–110 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#102Re: Linode hacked, CCs and passwords leaked
#103Earlier quoted context omitted.
That's totally shit. Its also why we invoice and take wire payments rather than storing CC details. There's just so much to go wrong. Also PKI is shit for this sort of thing. As demonstrated, the moment that public key is gone, then the whole system falls like a house of cards. For the non believers of this fact, why else would there be a certificate revocation list and root CA updates for windows periodically...
Using a processor who stores the card number outside of your infrastructure (ie. Stripe) can also be helpful.
Card vaulting as a service: https://spreedly.com/ ($10/mo for up to 5000 cards)
Re: Linode hacked, CCs and passwords leaked
#104Earlier quoted context omitted.
You missed the step where you have to find all charges going to your old CC and then deal with moving every one of those accounts to your new one when it gets there. Hopefully you don't incur any late fees while you're going through the process! Kind of sucks to have to spend hours doing that for someone else's oversight. It's not the end of the world, but it paints a clear picture about where a company's priorities…
Maybe I'm weird, but I know exactly which binding credit agreements I'm in and how they're paid, and definitely none of them get paid using another binding credit agreement. :)
Even just dealing with all of those is going to be a pain in the ass though. I'd probably end up spending hours all together just on hold with some of those people.
Edit: Netflix. I forgot Netflix.
Re: Linode hacked, CCs and passwords leaked
#105To those of you who have claimed that your CCs have been abused -- I checked mine (which I used to pay for Linode) and it hasn't been used to do anything funny.
Re: Linode hacked, CCs and passwords leaked
#106Earlier quoted context omitted.
Don't be so logical please. This can happend to anyone in the industry.
"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.
Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked???
It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COMPANY for all we know and looking to scare people off Linode) should be taken with a grain of salt.
Re: Linode hacked, CCs and passwords leaked
#107My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…
Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.
Visa has a zero liability program for debit card - http://usa.visa.com/personal/security/visa_security_program/...
These are the FTC's rules [1], I'm not sure if Visa or Mastercard can make them 'better' (give you a larger window). They have an interesting tidbit below their chart -
>If someone makes unauthorized transactions with your debit card number, but your card is not lost, you are not liable for those transactions if you report them within 60 days of your statement being sent to you.
Isn't it free to get a new card? That'd be the easier way than worrying.
[1] http://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cre...
Re: Linode hacked, CCs and passwords leaked
#108I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915
Not only that, it also makes me wonder about the free RAM upgrade from almost a week ago. Some people are reporting their Linode credit cards being used for fraudulent purchases as far as a week ago, so this might have been a move to gain some pre-emptive goodwill. I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.
I think it was just an unfortunately timed third phase of their upgrade plan.
Re: Linode hacked, CCs and passwords leaked
#109Really off-topic, but still sad: This is a link to slashdot, but it's on HN's frontpage before it's on slashdot's front-page (if it'll ever get there). (And IMHO that's sad, because /. used to be top notch). I've noticed before that stuff from the HN frontpage appears on /. one to three days after, but I've never seen it for links to slashdot :-)
Re: Linode hacked, CCs and passwords leaked
#110Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…
You then put your trust in the gateway/processor to store the credit card. Which I assume is most likely behind the best possible security stuff money can afford. Since that's their entire business. One screw up and their gone.