Live data from Hacker News

The story around the Linode hack

straylig.ht

111–120 of 175 posts

Re: The story around the Linode hack

#111
post #100

Earlier quoted context omitted.

Offtopic, but have you got a source for "Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country." I had a quick look on the Wikipedia page but couldn't see anything there. http://en.wikipedia.org/wiki/Nuclear_program_of_Iran

This is the world stage, so objectivity is hard to find, but there is a substantial amount of posturing from Mahmoud Ahmadinejad that shows a pretty aggressive stance toward Israel, if not open contempt [1]. That's really besides the point though. Anyone who seeks to boil "right and wrong" down to a simple principle that applies in all cases is holding simplicity above practicality. "Simple principles" are no more su…

I do see you point about the inferred goals of Iran, it's just the statement "openly stated goal" is untrue and I think it's important to be accurate about these things where we can be.

I certainly agree with you about the actions of HTP being unethical.

Re: The story around the Linode hack

#112

There is a lot of inside-baseball in this, but the one they keep talking about, is, "shred customer data" - as in, " Recognizing their situation, we instead told them that if they acknowledged HTP in their analysis, we'd go ahead and shred their customer data anyway." Do they honestly, for a single second, think that any LEA, corporation, or, well, anyone would believe that once the information was compromised, that…

What choice did they have?

Comply, and trust the honor of black hat hackers?

Or refuse, and have customers' data appearing on FTP and torrent sites within the day?

As a Linode customer, I would rather them choose the latter. Not to try and sweep the incident under the rug (to your point about disclosure) but to prevent the data from being scraped by groups who exist solely for extracting credit card details from releases by groups like HTP (note the reference to "carders" in the article) and then being sold.

(According to Linode's own post, the CC data were encrypted, meaning that it should be intractable to actually extract usable CC numbers from the data. But why would Linode not accept those terms, even if they believed that HTP were lying? At least it would give them until 1 May to get their house in order.)

Re: The story around the Linode hack

#113
post #54

Earlier quoted context omitted.

A right? I didn't say they have a right. They hacked into. Did the US/Israel have a _right_ to use Stuxnet against Iran? No. They hacked into. When did you accuse the US secret service or hope that they will be punished? Double standards? I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

Did you honestly just use militarized cyberwarfare as an example of legitimate black hat? The US/Israel are involved in a proxy war with Iran that involves cyberwarfare, clandestine operations and conventional military strikes (in the case of Israel striking Iranian-sourced Syrian weaponry). It's an extremely poor example to use open cyberwarfare between nations engaged in everything but overt warfare to attempt to l…

I'm curious how you would classify China's crack teams engaging in industrial espionage. Is that black hat activity, or legitimate cyberwarfare by a nation-state?

Re: The story around the Linode hack

#114

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

It bugs me that apparently, everything I'll ever host can just be "owned" at will by some random bunch of hackers doing whatever they feel like doing. Is it feasible for a "mere mortal" to stay safe?

Re: The story around the Linode hack

#115

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

It bugs me that apparently, everything I'll ever host can just be "owned" at will by some random bunch of hackers doing whatever they feel like doing. Is it feasible for a "mere mortal" to stay safe?

Security is about mitigating risk, not about eliminating it.

Keep up with CVE's, don't provide a wide attack area (so lock down interfaces to your machine and don't expose much to the world), and keep blast radii as small as possible (so even if your machine does get owned, you can possibly restrict it so it doesn't automatically mean they gain access to other systems in your network.)

Oh, and model the threats to your network/application. Make sure you're securing against the right threat. As an example, anti-malware is wholly ineffective against social engineering - maybe it's more productive to train employees and make sure that each employee doesn't have total access to all privileged systems.

Re: The story around the Linode hack

#116

I can't think of a better classification for a terrorist than people who sit around all day working to destroy credibility of corporations and expose personal and financial information for the sake of their own fucked up moral code and amusement. It would be nice if we had internet role models. IRC is full of low-life degenerates who perpetuate the vitriol that reinforces this way of life as an acceptable pastime. If…

The more I think about it, the more similar these sorts of groups seem to inner-city gangs. Otherwise good kids get caught up in the wrong environment, find acceptance within a peer group, and then become seduced by the intoxicating taste of power over others. As someone who engaged in my fair share of computerized mischief as a teenager, I can understand how a kid could fall into that trap. As someone who's pulled a…

> If someone has a beef with society, there are plenty of honest and constructive ways of "sticking it to the man" without resorting to violating people's property.

People say this all the time, but always fail to give examples of what sort of activities they think would be a constructive alternative. Would you mind sharing what you envision as alternative activities?

Re: The story around the Linode hack

#117

Earlier quoted context omitted.

Agreed. The one thing I think Linode could do better is communicate. The secrecy model is ... odd.

I didn't pull my hosting from Linode because they got hacked, I pulled it because they were hiding this from me. I even went as far as replacing the card I used to pay them and dealing with the massive headache of updating payment info with a new card number because I didn't know if I could trust their assertion that CC numbers didn't get released. If I can't trust you at your word, you no longer have the privilege o…

I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong.

This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range.

AWS might be safer, but I basically don't get any support (for a reasonable price like I pay linode), Rackspace didn't seem nearly as responsive or transparent on much more trivial matters. Who else is out there which is worth switching to?

(I'm not being sarcastic, I'm genuinely curious)

Re: The story around the Linode hack

#118
post #89
post #67

Earlier quoted context omitted.

I don't give a shit about my (former) linode servers and never want to have anything to do with the bastards again. I just want to know one thing: did or didn't they leak the credit cards?

> I just want to know one thing: did or didn't they leak the credit cards? Does it really matter? If your card was used with Linode, it should have been blocked by now anyway.

Yes, because it is a huge pain to go through for no reason.

Re: The story around the Linode hack

#119

Earlier quoted context omitted.

I didn't pull my hosting from Linode because they got hacked, I pulled it because they were hiding this from me. I even went as far as replacing the card I used to pay them and dealing with the massive headache of updating payment info with a new card number because I didn't know if I could trust their assertion that CC numbers didn't get released. If I can't trust you at your word, you no longer have the privilege o…

I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…

I moved away to me. I enjoyed having my test server in a data center so I could work on it from anywhere, but it wasn't worth risking a security breech where no one would tell me I had been compromised. Instead, now I somewhat inconveniently host it on a machine sitting in my basement.

I'm merely a hobbyist/researcher, so I don't have a production environment to worry about.

Re: The story around the Linode hack

#120

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

> The access that HTP obtained does not, full stop, lead to root on Linode instances without at least one shutdown job or change of root password job showing up in your Linode's history that you did not ask for. ... the access they obtained does not lead to root on the Linode host fleet itself

I wouldn't bet on that.

> There will always be targets but harboring SwiftIRC is probably a malicious-actor magnet.

Isn't that the same logic Everydns/Dyn Inc. used when they censored Wikileaks?

> All it takes is one zero-day, and you will all be hit by one in your career, so cut Linode a little slack.

True dat.

Post reply on HN