Live data from Hacker News

The story around the Linode hack

straylig.ht

151–160 of 175 posts

Re: The story around the Linode hack

#151

Earlier quoted context omitted.

Yes. Linode publicly stated that they were using public-key cryptography, that the private key was secured with some crazy-long passphrase, and that the passphrase wasn't stored digitally, meaning that once a month when they billed they had to manually enter the private key. So for the hackers to get the decrypted private key, then either Linode must have royally screwed up and kept the decrypted key in-memory during…

> So for the hackers to get the decrypted private key, then either Linode must have royally screwed up and kept the decrypted key in-memory during the rest of the month (which seems rather unlikely), They bill you the moment you add a Linode, automatically, if your credit is not sufficient to cover the new Linode. Careful walking that assumption too far; I think it's safe to say the key was kept in memory.

Well it's not like it originally comes in encrypted with the public key, it has to be on there for a short amount of time already, why would they keep the unencrypted version around longer than the initial billing?

Re: The story around the Linode hack

#152

Earlier quoted context omitted.

I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…

I moved away to me. I enjoyed having my test server in a data center so I could work on it from anywhere, but it wasn't worth risking a security breech where no one would tell me I had been compromised. Instead, now I somewhat inconveniently host it on a machine sitting in my basement. I'm merely a hobbyist/researcher, so I don't have a production environment to worry about.

I see. For me this is unfortunately not an option.

I need to be able to serve my customers, and they are all over the world. So I need a provider with data centers in multiple global locations, that offers an API, that has decent support that responds quickly, and at a similar price range... Interested to find alternatives that are also more secure and better at communication.

Re: The story around the Linode hack

#153
post #15

Earlier quoted context omitted.

> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.

Well then you are not a hacker. And I hope FBI can not cause trouble for them, they did not do anything unethical in my POV. The server is not a house. Black hat hacking is a mixture of art and politics (I never support hackers who hack for stealing money), and if you want the analogy, they just spotted a fancy lock on the door of some institution (not a private house), lock-picked it and looked what's behind the doo…

If they only "looked" it would not be too bad, but they did much more here. They threatened to release credit card numbers, user names, emails and passwords of customers. Do you think it's fair that someone's personal information is released just because they are customers of Linode?

Re: The story around the Linode hack

#154

Earlier quoted context omitted.

I worry more about governments than organized crime these days.

Yep, them too, don't tell anyone about their hacks. (I mean, "More about governments than organized crime? There's a difference?")

You should pay a visit to Sicily or Naples if you don't think there's a difference.

Re: The story around the Linode hack

#155
post #15

Earlier quoted context omitted.

> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.

I'm afraid your analogy is stretched a little too far for me - that your open door leading to someone physically wandering into your personal living space is the same as some corporation with tens of millions of revenue a year that has some script kiddie sitting in his mom's basement seeing some Linode stuff come onto his screen. I guess when I think of some kid snooping around some corporation's computers, I'm suppo…

Actually, these guys cost people a whole hell of a lot more time and money than someone breaking into a home probably ever did. Just for starters:

http://blog.phusion.nl/2013/05/07/phusion-server-security-re...

Re: The story around the Linode hack

#156
post #154

Earlier quoted context omitted.

Yep, them too, don't tell anyone about their hacks. (I mean, "More about governments than organized crime? There's a difference?")

You should pay a visit to Sicily or Naples if you don't think there's a difference.

I'd generally prefer government to organized crime, but would probably take the Yakuza over NK or Belarus or wherever.

Re: The story around the Linode hack

#157

Earlier quoted context omitted.

It bugs me that apparently, everything I'll ever host can just be "owned" at will by some random bunch of hackers doing whatever they feel like doing. Is it feasible for a "mere mortal" to stay safe?

User input is trying to kill you until proven otherwise. And even then, it probably still is. If you accept anything from a user, treat it like you're carrying spent nuclear fuel around your application; that doesn't just mean form inputs, either; sometimes you have to wear gloves that even consider files read from the filesystem as suspicious. There are numerous attacks on temporary files if implemented incorrectly.…

Well, it's somewhat comforting to know it's mostly about user input. Thanks! Not that it's easy to secure input handling either.

I've seen that kind of timing attack discussed somewhere, and the solution there was to do some kind of byte-by-byte comparison that would always take the same amount of time. It makes sense.

Re: The story around the Linode hack

#158
post #156
post #154

Earlier quoted context omitted.

You should pay a visit to Sicily or Naples if you don't think there's a difference.

I'd generally prefer government to organized crime, but would probably take the Yakuza over NK or Belarus or wherever.

So you're comparing what might be the "best" of something in one category with some of the dregs in another.

Italy is not known for having particularly good politicians or government, but I'd take the government here any day over the Mafia or Camorra. Despite any romanticized movies you may have seen, those guys are pretty cold-blooded SOB's. Recently, a man was shot dead waiting to pick his son up from pre-school in Naples.

Re: The story around the Linode hack

#159
post #154

Earlier quoted context omitted.

Yep, them too, don't tell anyone about their hacks. (I mean, "More about governments than organized crime? There's a difference?")

You should pay a visit to Sicily or Naples if you don't think there's a difference.

And I hope none of us ever pay a visit to Guantanamo.

But seriously, yeah, of course there's a difference, but government is also often in league with organized crime, from local levels of corrupt cops and drug leaders, to international levels of the CIA and arms traders and 'our' 'freedom fighers' -- I bet this is also true in Sicily and Naples, that many parts of the government act in league with organized crime.

But yeah, to go back to the actual topic/thread, mainly, I think the guy is right that the government is the other main actor which is going to keep it's security exploits to itself, and just use them to monitor you silently. (And that's probably more likely in the US than any other country on the planet, at the moment).

Re: The story around the Linode hack

#160
post #94

Earlier quoted context omitted.

tech-oriented channels? Care to name any?

Tech oriented indeed. You know, all of the Open source IRC channels on Freenode are a good start. IRC is nothing like you've described, at least to me.

IRC is nothing like you've described

User hderms didn't describe them, I did. And I can show you hundreds of thousands of channels like I describe, on most popular IRC networks (Freenode is a tiny network in comparison).

Also, I challenge you to show me proof of intelligent discourse in any Freenode channel. It's simply not easy, especially in a channel with 5 or more active participants in conversations. Try taking your time to make intelligent points and either people get bored with you or your points get lost in the scrollback.

Post reply on HN