Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

111–120 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#111

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode.

I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions.

Linode customer support keeps saying they have "no comment" on this issue (which I suppose does make sense -- I'm assuming they've been ordered by law enforcement persons to not share details), so as we're not being given much information to work with... just treat this as a worst-case scenario (all names, addresses, credit card numbers, etc. have been compromised). Do operate now with the assumption that all of this data has been compromised and may very well be public soon.

Re: Linode hacked, CCs and passwords leaked

#112

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Quite. I like the company and their servers are good - but we need a detailed response, and we need one now.

I'd say support tickets or posting on their forum[1] may help try to get a response. But based one one of the support ticket responses posted in the comments in this HN story already, it sounds like Linode isn't allowed to release that kind of information yet. They may be waiting on the police and/or their lawyers to allow them to talk publicly about it. And if that isn't the gating factor, they are probably trying to determine what they are required and should share about the incident.

[1] http://forum.linode.com/viewtopic.php?f=20&t=9978

Re: Linode hacked, CCs and passwords leaked

#113
post #74

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

You should talk to your bank as it depends on the network your bank uses. Most of the time it's something like a 48 hour window to challenge charges but it's far less at some banks.

Re: Linode hacked, CCs and passwords leaked

#114
post #60

Earlier quoted context omitted.

Not only that, it also makes me wonder about the free RAM upgrade from almost a week ago. Some people are reporting their Linode credit cards being used for fraudulent purchases as far as a week ago, so this might have been a move to gain some pre-emptive goodwill. I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.

"Someone hacked us and stole customer details... quick, give everyone more RAM!" Doesn't sound very plausible to me.

Logically, they couldn't have planned it all in such a short period of time. However if they did, from a business perspective it is very good plan. Without the upgrade, today some customers would have had two reasons to leave Linode, now they only have one.

Re: Linode hacked, CCs and passwords leaked

#115
post #42

I guess this is why they wanted everyone to reset their password 2 days ago. https://news.ycombinator.com/item?id=5541915

Not sure how useful that reset was. All I had to do was type in my old password and then choose a new one. No email verification, no reset token, nothing. So if the password was indeed compromised, couldn't the attacker do the same?

Yes, he could. But he didn't. If he did that, the page would tell you that your password is wrong, and you'd contact support. The attacker probably didn't change any password, because it would be futile.

Also, the attaker could also change the account email. Neither tokens nor email confirmation would help.

The biggest problem is for people that used the same password on Linode and any other important service. (And, of course, all the CC stuff...)

Re: Linode hacked, CCs and passwords leaked

#117
post #83

Off topic but still relevant, but doesn't it seem a bit primitive that companies have to store you CC# for recurring payments? The one number that uniquely identifies your account and everyone you want to re-use it has to keep a copy. Couldn't the credit card company issue some unique ID to each vendor for recurrent payments? Ex. the vendor issues your CC# to the CC Company for charge and recurring process. The CC Co…

It's amazing that it doesn't work that way. You could argue that it's because of the amount of infrastructure already in place, but why couldn't a new system be gradually and optionally rolled out?

Stripe (and probably others) has functionality like this where the seller's server never sees the CC number, and developers can store a unique token to re-charge the customer at a later date.

Re: Linode hacked, CCs and passwords leaked

#118
Just rang my bank to cancel my debit card. Hate doing that. Now I have a week or two of failing payments, bills, etc to look forward to.

I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic.

Re: Linode hacked, CCs and passwords leaked

#119
post #90

Earlier quoted context omitted.

That's pretty much how trust works.

I'd give another trust vote to Linode, anyway this could happen to anyone.

That's true -- it could indeed happen to anyone who keeps encrypted data adjacent to the keys.

Re: Linode hacked, CCs and passwords leaked

#120
post #111

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

[deleted]
Post reply on HN