Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

141–150 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#141
post #74

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

I would cancel that card right now. IMHO You should never ever ever ever use a debit card anywhere else other than the ATM. Credit cards give you way more financial protection.

Re: Linode hacked, CCs and passwords leaked

#142
post #112

Earlier quoted context omitted.

Quite. I like the company and their servers are good - but we need a detailed response, and we need one now.

I'd say support tickets or posting on their forum[1] may help try to get a response. But based one one of the support ticket responses posted in the comments in this HN story already, it sounds like Linode isn't allowed to release that kind of information yet. They may be waiting on the police and/or their lawyers to allow them to talk publicly about it. And if that isn't the gating factor, they are probably trying t…

its a recursion! the forum points back to here

Re: Linode hacked, CCs and passwords leaked

#144
post #74

Earlier quoted context omitted.

Great, now I am feeling paranoid although I don't see any unauthorized charges on my card. Does anyone know if debit cards are legally protected the same way as credit cards with 0% liability.

I'm pretty sure that depends on who issued your card. Visa has a zero liability program for debit card - http://usa.visa.com/personal/security/visa_security_program/... These are the FTC's rules [1], I'm not sure if Visa or Mastercard can make them 'better' (give you a larger window). They have an interesting tidbit below their chart - >If someone makes unauthorized transactions with your debit card number, but your…

Generally these days they are, but the problem is the money is removed is from your account by the time the charge appears, (at least a period of time), whereas on a credit card you have 30 days to review charges. This could cause overdrafts, etc. depending on timing and amount. Those too can generally be reversed, but the whole thing becomes more of a headache. I never use debit cards for any kind of recurring charges, and I avoid using them online in general.

Re: Linode hacked, CCs and passwords leaked

#145
post #111

Earlier quoted context omitted.

I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours dispu…

I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.

There's baseless speculation and then there's I have some information speculation. I'm operating on heuristics which rely on information that is handily available. Yes, in the end you're right, I'm just speculating. But hey, it's better to err on the side of caution.

Re: Linode hacked, CCs and passwords leaked

#146

My Visa card that I used with Linode was stolen and used on an Amazon order I didn't authorise last week, my bank successfully blocked the charge. Someone else reported their Visa had also been compromised in the thread 2 days ago, looks like that confirms the suspicions: https://news.ycombinator.com/item?id=5542015 Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it…

I have two accounts with them, one for my day job and one through my LLC. Right now neither card is showing unusual charges.

My day job had some Google Apps account compromises last month, and this is making me paranoid that the database that contained hashed/salted passwords for our Intranet hosted on Linode was the culprit. The time frame doesn't seem to line up, but we didn't see any evidence of phishing or compromised desktops being involved.

(Don't want to spread fear - I haven't been able to find any evidence our Linodes were compromised either.)

I'm normally huge a Linode evangelist, but I'm severely disappointed with the lack of transparency on this. I'm debating right now whether to rebuild all our nodes from scratch as I'm not sure they can be trusted.

Re: Linode hacked, CCs and passwords leaked

#147

So what happens now to all the goodwill Linode has amassed through the years? Does it all turn to shite, almost overnight? This sounds very very bad, and as a customer it's very off-putting.

They made a mistake. They'll learn from it, hopefully (among other things) by ensuring no customer credit card details ever hit their servers ever again.

Re: Linode hacked, CCs and passwords leaked

#148
post #13
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

Wouldn't doing that be a massive PCI violation? Aren't there extensive audits for this sort of thing?

The audits are toothless and ultimately the audit only happens once (if ever) and people keeping pub/secret key in the same place unprotected... well.... They're just unlikely to get security at all...

Re: Linode hacked, CCs and passwords leaked

#149

I had a VPS on linode. I think that Linode did a big mistake here. Let's wait for a formal communication. But this is the moment to support them. Yes, maybe sounds crazy. When you host on any third party datacenter, you take risks that something like this could happen. So, deal with it. Check your credit card, if your receive something wrong, call to your card and that's all. But we need to support also the good work…

The service is not the problem, hiding what happened and the continued silence on these accusations is.

This is not a mistake/technical issue, it's becoming an ethics/service one.

Re: Linode hacked, CCs and passwords leaked

#150
post #36

Earlier quoted context omitted.

Here is what Linode replied to me when I asked them about that chat log in a support ticket: Hello, Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation. We have no comment regarding ryan*'s…

Despite what the other replies here are saying, this seems like a perfectly acceptable response to me. This comes off to me not as they're refusing to talk about it, but they _can't_ talk about it, presumably because of an ongoing investigation. I'm not sure what else people here are expecting them to say.

Then why not say that?
Post reply on HN