Live data from Hacker News

Compromised Linode, thousands of BitCoins stolen

bitcoinmedia.com

111–120 of 249 posts

Re: Compromised Linode, thousands of BitCoins stolen

#112
post #93
post #79

Earlier quoted context omitted.

Actually not. Just use a loopback cypto FS to store the sensitive stuff. The reason they had to reboot the machine is that they just had access to the HDD where they could change the password, as opposed to having live root access.

where do you keep the key to the crypto fs?

You memorize it.

Re: Compromised Linode, thousands of BitCoins stolen

#113
post #112
post #93

Earlier quoted context omitted.

where do you keep the key to the crypto fs?

You memorize it.

how do you transmit it to the server in such a way that it can't be intercepted by someone that compromises the bits of your virtual that boot before the key is uploaded?

Re: Compromised Linode, thousands of BitCoins stolen

#114
post #93
post #79

Earlier quoted context omitted.

Actually not. Just use a loopback cypto FS to store the sensitive stuff. The reason they had to reboot the machine is that they just had access to the HDD where they could change the password, as opposed to having live root access.

where do you keep the key to the crypto fs?

Written on a scrap of paper in your wallet. only the password and no other info should be on the scrap.

If you can memorize it, it is a bad password.

Re: Compromised Linode, thousands of BitCoins stolen

#115
post #62

Earlier quoted context omitted.

Where are you reading this? The status page and the blog have no mention of the incident.

It's from his e-mail conversation with Linode support: http://pastebin.com/UW7iT5fj

So hardly "from linode"

More accurately "according to somebody at linode"

Re: Compromised Linode, thousands of BitCoins stolen

#116
post #8
post #6

Hmm, for a customer of a cloud provider, this sort of thing will be very hard to defend against. Maybe if the customer service system had had two-factor security, this might have been avoided (i.e., customer service can access your account only if you read them your hardware token's code). Requiring SSL/SSH client certificates even for intranet accesses might have deterred this attack. I hope other cloud providers ta…

> customer service can access your account only if you read them your hardware token's code At the very least, I'd hope Linode implements two-factor authentication for their own logins. A customer-provided OTP would be great but you'd need a customer service reset tool for that when people forget, which would put you back where you started...

You obviously have never worked for a retail ISP.

Re: Compromised Linode, thousands of BitCoins stolen

#117
post #75

The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscri…

This is why insurance exists. I wonder if there are any insurance providers who'd be willing to provider coverage for this sort of event.

I write software for use by high risk insurance carrier. There is coverage for just about anything. One of the inland marine insurance types might cover this. (possibly Electronic Data Protection or Valuable Papers)

Re: Compromised Linode, thousands of BitCoins stolen

#118

The OP's tone clearly indicates that he expects some compensation, Linode's TOS are pretty clear: Therefore, subscriber agrees that Linode.com shall not be liable for any damages arising from such causes beyond the direct and exclusive control of Linode.com. Subscriber further acknowledges that Linode.com's liability for its own negligence may not in any event exceed an amount equivalent to charges payable by subscri…

I am pretty sure this is OP's first experience with ISP contracts. I guarantee it is not Linode's first legal dispute over their TOS with a noob.

Re: Compromised Linode, thousands of BitCoins stolen

#119
post #33

Earlier quoted context omitted.

Are you sure? I think that you may be mistaken. The bar is just set higher in a "virtualized environment"... "In a public cloud environment, additional controls must be implemented to compensate for the inherent risks and lack of visibility into the public cloud architecture. A public cloud environment could, for example, host hostile out-of-scope workloads on the same virtualization infrastructure as a cardholder da…

Amazon getting a PCI compliance pass was a big deal. The last time I looked, you needed to be able to ensure secure access to the facility, enumerate who has physical access to the hardware and when, and things of that effect. And you need to be able prove all that in the event you're ever compromised.

Securing physical access is a requirement for anyone wishing to obtain pci compliance.

Re: Compromised Linode, thousands of BitCoins stolen

#120
Without passing too much judgement........ it's common sense that as your revenue goes up, the time and effort put into ensuring you are on an appropriate platform should go up as well.

Because sh*t happens...... whether we like it or not. Even if the technical requirements are light and it runs fine on a tiny linode, that might not be the right place from a security or integrity point of view, depending on the value of the app.

(for me, a digital wallet worth that much, I'd want at my home..... where I can control it)

Post reply on HN