Live data from Hacker News

The story around the Linode hack

straylig.ht

121–130 of 175 posts

Re: The story around the Linode hack

#121

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

You have to decide whether to take HTP at their word that they deleted credit cards. Don't we also have to take them at their word that they even had decrypted CC's? I haven't seen any proof yet that they obtained the decrypted private key, just their statement saying they grabbed in-memory keys.

If they pwned the server that accepted the HTTP(S) POST with the payment information, they were in a position to obtain at least some CC numbers. They were probably also in a position to obtain the keys by which the CCs were encrypted.

Re: The story around the Linode hack

#122

Earlier quoted context omitted.

You have to decide whether to take HTP at their word that they deleted credit cards. Don't we also have to take them at their word that they even had decrypted CC's? I haven't seen any proof yet that they obtained the decrypted private key, just their statement saying they grabbed in-memory keys.

If they pwned the server that accepted the HTTP(S) POST with the payment information, they were in a position to obtain at least some CC numbers. They were probably also in a position to obtain the keys by which the CCs were encrypted.

The encryption keys are useless. The decryption keys are what's important. You do have a point that they could have theoretically intercepted HTTP(S) POSTs, but I don't think anyone's claimed that they actually did that.

Re: The story around the Linode hack

#123

Earlier quoted context omitted.

I didn't pull my hosting from Linode because they got hacked, I pulled it because they were hiding this from me. I even went as far as replacing the card I used to pay them and dealing with the massive headache of updating payment info with a new card number because I didn't know if I could trust their assertion that CC numbers didn't get released. If I can't trust you at your word, you no longer have the privilege o…

I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…

I have found lots of the smaller VPS providers (especially those that provided dedicated/colo services) to have great service. Check on http://webhostingtalk.com

I fail to understand how you can think Linode has a great track record. It is an unequivocal disgrace. TWICE they have mislead their own customers over a major security incident. And there have been lots of times during outages (in particular my time at Fremont) where they were MIA.

Re: The story around the Linode hack

#124
post #94
post #79

Earlier quoted context omitted.

The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends. What? I could name 20 channels of the top of my head this is not true for.

tech-oriented channels? Care to name any?

Tech oriented indeed. You know, all of the Open source IRC channels on Freenode are a good start.

IRC is nothing like you've described, at least to me.

Re: The story around the Linode hack

#125
post #54

Earlier quoted context omitted.

Did you honestly just use militarized cyberwarfare as an example of legitimate black hat? The US/Israel are involved in a proxy war with Iran that involves cyberwarfare, clandestine operations and conventional military strikes (in the case of Israel striking Iranian-sourced Syrian weaponry). It's an extremely poor example to use open cyberwarfare between nations engaged in everything but overt warfare to attempt to l…

I'm curious how you would classify China's crack teams engaging in industrial espionage. Is that black hat activity, or legitimate cyberwarfare by a nation-state?

I think criley's point is that if your activities closely resemble international warfare, they probably aren't "legitimate" by any reasonable standards.

Re: The story around the Linode hack

#126

Earlier quoted context omitted.

I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…

I have found lots of the smaller VPS providers (especially those that provided dedicated/colo services) to have great service. Check on http://webhostingtalk.com I fail to understand how you can think Linode has a great track record. It is an unequivocal disgrace. TWICE they have mislead their own customers over a major security incident. And there have been lots of times during outages (in particular my time at Frem…

I give Linode a lot of slack. When people say "Oh, they should be more secure" I often say "Really?"

In an ideal world, yes, they should be more secure. However, as in this case, they got taken advantage of via a zero-day attack, with others planned well outside the scope of what Linode could have planned for. Which is insane. Can you even name something, anything that they could have done to protect themselves? Additionally, given the unique form of attack, figuring out what was going wrong was probably not possible. Thus, they knew as little as you did.

And then, everybody switches to some other provider. But do they switch to "super secure, we examine every byte of the software that we run to make sure we're bullet proof" hosting provider? NO, everyone just switches to another commodity VPS provider that is vulnerable to all the same super high level attacks that Linode is vulnerable (maybe even more attacks, given that Linode actually has a tremendous amount of experience).

In reality, you're only getting more security by switching to a less prominent hosting provider, A.K.A. security through obscurity. Which is the worst kind of security because it's not secure at all.

It's like getting mad at the mayor of your city when a meteor falls on your house: unproductive and misguided.

Re: The story around the Linode hack

#127

Slightly OT, Is it possible to have a web application (using popular tech like RoR, PHP etc.) that cannot be cracked by anyone ?

The question is not if it can't be cracked, but who will be able to crack it. If a security analyst will be able to break it you should not worry that much as long as you adhere to good practices, but if a person without the proper knowledge will be able to break it, because it's a trivial vulnerability (ex. SQL injection via GET parameters), you should be really, really worried, because it means that something is wrong and it should be fixed soon.

Re: The story around the Linode hack

#128
post #125

Earlier quoted context omitted.

I'm curious how you would classify China's crack teams engaging in industrial espionage. Is that black hat activity, or legitimate cyberwarfare by a nation-state?

I think criley's point is that if your activities closely resemble international warfare, they probably aren't "legitimate" by any reasonable standards.

after re-reading it, you do appear to be correct. Thanks for the correction.

Re: The story around the Linode hack

#129

Earlier quoted context omitted.

If they pwned the server that accepted the HTTP(S) POST with the payment information, they were in a position to obtain at least some CC numbers. They were probably also in a position to obtain the keys by which the CCs were encrypted.

The encryption keys are useless. The decryption keys are what's important. You do have a point that they could have theoretically intercepted HTTP(S) POSTs, but I don't think anyone's claimed that they actually did that.

They were using asymmetric crypto on their CC data column?

Re: The story around the Linode hack

#130
post #15

Earlier quoted context omitted.

> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.

Everyone bitching about HTP or AnonOps or any other hacking group that likes bragging should at least be thankful that they talk about their hacks. I would bet that the crime syndicates have better hacks and keep their mouths shut about them. Those vulnerabilities don't get patched, those customers never get notified. I am not defending HTP or the like, just saying, at least they boast.

I worry more about governments than organized crime these days.
Post reply on HN