Live data from Hacker News

Security Notification and Linode Manager Password Reset

blog.linode.com

151–160 of 173 posts

Re: Security Notification and Linode Manager Password Reset

#151
post #5

Sure wish they had sent out an email notification to users instead of a slashdotted blog post. Now the question is how long can Linode stand in the face of these sorts of hacks and network attacks in the face of stiff VPS competition.

(Linode Employee) Already got it covered, we are sending out an email to everyone in batches, but pushed out the blog first since it can be seen by everyone right away.

How come, still, no one I know, including myself, has received this email?

Re: Security Notification and Linode Manager Password Reset

#152

Earlier quoted context omitted.

Bitcoin.

That's an awful lot of faith in virtual currency and its speculative nature to be betting the next 50-60 years of your life.

I can't even tell you how many pen testers I know with criminal records. Somewhere, someone will hire him to do security.

Re: Security Notification and Linode Manager Password Reset

#153

I'm glad to see that this information has now been publicly disclosed. In July 2015, we suffered a compromise at PagerDuty via the Linode Manager. I hope that we can provide a bit more of an official in-depth post-mortem of our compromise, but I'd be happy to disclose some of the details here. Using the access gained within the Linode Manager, the attacker reset the root password on a few systems, and used Lish to ga…

Isn't this like the third Linode hack? Back in 2012 one of their cust tools was compromised in order to steal bitcoins. In 2013, cc# and password hashes were compromised, Linode denied it until the hackers showed proof, then did a piss poor job of handling it afterwards.

Why were people still using Linode after their poor handling in the 2013 hack?

Re: Security Notification and Linode Manager Password Reset

#154
post #140

Earlier quoted context omitted.

That crosses into personal attack, which is not ok, even if it's just insinuated. We detached this subthread from https://news.ycombinator.com/item?id=10847715 and marked it off-topic.

It's not a personal attack, it's something that ryanlol publicly claims in ##security on freenode FFS. If it wasn't, I wouldn't have referenced it From what I gather, he thinks law enforcement is hilarious.

OK, I believe you, though I don't know any of the details. It's an important misunderstanding to prevent, though. In this case, including enough of the details to make the comment substantive would probably have been enough to clarify your intent as well.

you could have made the comment more substantive in a way that was clearly not a personal attack, and that would have solved the problem.

Re: Security Notification and Linode Manager Password Reset

#155

Earlier quoted context omitted.

Bitcoin.

That's an awful lot of faith in virtual currency and its speculative nature to be betting the next 50-60 years of your life.

Who is to say xe didn't buy a bunch of it at $1 and sell it off, making millions, when it hit $200-$300?

Re: Security Notification and Linode Manager Password Reset

#156

Earlier quoted context omitted.

Bitcoin.

That's an awful lot of faith in virtual currency and its speculative nature to be betting the next 50-60 years of your life.

Diversification is pretty important if you want to keep any kind of currency for 50-60 years.

Re: Security Notification and Linode Manager Password Reset

#160

I'm fairly confident that Linode has been compromised since July, if not earlier. PagerDuty moved off of Linode after an incident in July. We've been under strict gag orders from legal about that incident until today when Linode finally announced their compromise. Really, the only way I can see that this attacker could have gotten in the way they did (they logged into our Linode Manager account on the first try using…

Hello, my name is Julius Kivimaki. I am the one who hacked Linode. You guys are all stupid if you think you can catch me. I say, CATCH ME IF YOU CAN, or GTFO! LULZ!
Post reply on HN