Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…
You have to decide whether to take HTP at their word that they deleted credit cards. Don't we also have to take them at their word that they even had decrypted CC's? I haven't seen any proof yet that they obtained the decrypted private key, just their statement saying they grabbed in-memory keys.
The story around the Linode hack
121–130 of 175 posts
Re: The story around the Linode hack
#122Earlier quoted context omitted.
You have to decide whether to take HTP at their word that they deleted credit cards. Don't we also have to take them at their word that they even had decrypted CC's? I haven't seen any proof yet that they obtained the decrypted private key, just their statement saying they grabbed in-memory keys.
If they pwned the server that accepted the HTTP(S) POST with the payment information, they were in a position to obtain at least some CC numbers. They were probably also in a position to obtain the keys by which the CCs were encrypted.
Re: The story around the Linode hack
#123Earlier quoted context omitted.
I didn't pull my hosting from Linode because they got hacked, I pulled it because they were hiding this from me. I even went as far as replacing the card I used to pay them and dealing with the massive headache of updating payment info with a new card number because I didn't know if I could trust their assertion that CC numbers didn't get released. If I can't trust you at your word, you no longer have the privilege o…
I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…
I fail to understand how you can think Linode has a great track record. It is an unequivocal disgrace. TWICE they have mislead their own customers over a major security incident. And there have been lots of times during outages (in particular my time at Fremont) where they were MIA.
Re: The story around the Linode hack
#124Earlier quoted context omitted.
The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends. What? I could name 20 channels of the top of my head this is not true for.
tech-oriented channels? Care to name any?
IRC is nothing like you've described, at least to me.
Re: The story around the Linode hack
#125Earlier quoted context omitted.
Did you honestly just use militarized cyberwarfare as an example of legitimate black hat? The US/Israel are involved in a proxy war with Iran that involves cyberwarfare, clandestine operations and conventional military strikes (in the case of Israel striking Iranian-sourced Syrian weaponry). It's an extremely poor example to use open cyberwarfare between nations engaged in everything but overt warfare to attempt to l…
I'm curious how you would classify China's crack teams engaging in industrial espionage. Is that black hat activity, or legitimate cyberwarfare by a nation-state?
Re: The story around the Linode hack
#126Earlier quoted context omitted.
I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…
I have found lots of the smaller VPS providers (especially those that provided dedicated/colo services) to have great service. Check on http://webhostingtalk.com I fail to understand how you can think Linode has a great track record. It is an unequivocal disgrace. TWICE they have mislead their own customers over a major security incident. And there have been lots of times during outages (in particular my time at Frem…
In an ideal world, yes, they should be more secure. However, as in this case, they got taken advantage of via a zero-day attack, with others planned well outside the scope of what Linode could have planned for. Which is insane. Can you even name something, anything that they could have done to protect themselves? Additionally, given the unique form of attack, figuring out what was going wrong was probably not possible. Thus, they knew as little as you did.
And then, everybody switches to some other provider. But do they switch to "super secure, we examine every byte of the software that we run to make sure we're bullet proof" hosting provider? NO, everyone just switches to another commodity VPS provider that is vulnerable to all the same super high level attacks that Linode is vulnerable (maybe even more attacks, given that Linode actually has a tremendous amount of experience).
In reality, you're only getting more security by switching to a less prominent hosting provider, A.K.A. security through obscurity. Which is the worst kind of security because it's not secure at all.
It's like getting mad at the mayor of your city when a meteor falls on your house: unproductive and misguided.
Re: The story around the Linode hack
#127Slightly OT, Is it possible to have a web application (using popular tech like RoR, PHP etc.) that cannot be cracked by anyone ?
Re: The story around the Linode hack
#128Earlier quoted context omitted.
I'm curious how you would classify China's crack teams engaging in industrial espionage. Is that black hat activity, or legitimate cyberwarfare by a nation-state?
I think criley's point is that if your activities closely resemble international warfare, they probably aren't "legitimate" by any reasonable standards.
Re: The story around the Linode hack
#129Earlier quoted context omitted.
If they pwned the server that accepted the HTTP(S) POST with the payment information, they were in a position to obtain at least some CC numbers. They were probably also in a position to obtain the keys by which the CCs were encrypted.
The encryption keys are useless. The decryption keys are what's important. You do have a point that they could have theoretically intercepted HTTP(S) POSTs, but I don't think anyone's claimed that they actually did that.
Re: The story around the Linode hack
#130Earlier quoted context omitted.
> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.
Everyone bitching about HTP or AnonOps or any other hacking group that likes bragging should at least be thankful that they talk about their hacks. I would bet that the crime syndicates have better hacks and keep their mouths shut about them. Those vulnerabilities don't get patched, those customers never get notified. I am not defending HTP or the like, just saying, at least they boast.