Earlier quoted context omitted.
Yes. Linode publicly stated that they were using public-key cryptography, that the private key was secured with some crazy-long passphrase, and that the passphrase wasn't stored digitally, meaning that once a month when they billed they had to manually enter the private key. So for the hackers to get the decrypted private key, then either Linode must have royally screwed up and kept the decrypted key in-memory during…
> So for the hackers to get the decrypted private key, then either Linode must have royally screwed up and kept the decrypted key in-memory during the rest of the month (which seems rather unlikely), They bill you the moment you add a Linode, automatically, if your credit is not sufficient to cover the new Linode. Careful walking that assumption too far; I think it's safe to say the key was kept in memory.
The story around the Linode hack
151–160 of 175 posts
Re: The story around the Linode hack
#152Earlier quoted context omitted.
I'm curious to know who you moved away to? and what gave you the confidence that they are a) better at security b) better at communicating transparently when things go wrong. This security incident is very upsetting, but for me the linode track record in communication, responsiveness and support is still pretty amazing compared to the competition. At least at this price range. AWS might be safer, but I basically don'…
I moved away to me. I enjoyed having my test server in a data center so I could work on it from anywhere, but it wasn't worth risking a security breech where no one would tell me I had been compromised. Instead, now I somewhat inconveniently host it on a machine sitting in my basement. I'm merely a hobbyist/researcher, so I don't have a production environment to worry about.
I need to be able to serve my customers, and they are all over the world. So I need a provider with data centers in multiple global locations, that offers an API, that has decent support that responds quickly, and at a similar price range... Interested to find alternatives that are also more secure and better at communication.
Re: The story around the Linode hack
#153Earlier quoted context omitted.
> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.
Well then you are not a hacker. And I hope FBI can not cause trouble for them, they did not do anything unethical in my POV. The server is not a house. Black hat hacking is a mixture of art and politics (I never support hackers who hack for stealing money), and if you want the analogy, they just spotted a fancy lock on the door of some institution (not a private house), lock-picked it and looked what's behind the doo…
Re: The story around the Linode hack
#154Earlier quoted context omitted.
I worry more about governments than organized crime these days.
Yep, them too, don't tell anyone about their hacks. (I mean, "More about governments than organized crime? There's a difference?")
Re: The story around the Linode hack
#155Earlier quoted context omitted.
> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.
I'm afraid your analogy is stretched a little too far for me - that your open door leading to someone physically wandering into your personal living space is the same as some corporation with tens of millions of revenue a year that has some script kiddie sitting in his mom's basement seeing some Linode stuff come onto his screen. I guess when I think of some kid snooping around some corporation's computers, I'm suppo…
http://blog.phusion.nl/2013/05/07/phusion-server-security-re...
Re: The story around the Linode hack
#156Earlier quoted context omitted.
Yep, them too, don't tell anyone about their hacks. (I mean, "More about governments than organized crime? There's a difference?")
You should pay a visit to Sicily or Naples if you don't think there's a difference.
Re: The story around the Linode hack
#157Earlier quoted context omitted.
It bugs me that apparently, everything I'll ever host can just be "owned" at will by some random bunch of hackers doing whatever they feel like doing. Is it feasible for a "mere mortal" to stay safe?
User input is trying to kill you until proven otherwise. And even then, it probably still is. If you accept anything from a user, treat it like you're carrying spent nuclear fuel around your application; that doesn't just mean form inputs, either; sometimes you have to wear gloves that even consider files read from the filesystem as suspicious. There are numerous attacks on temporary files if implemented incorrectly.…
I've seen that kind of timing attack discussed somewhere, and the solution there was to do some kind of byte-by-byte comparison that would always take the same amount of time. It makes sense.
Re: The story around the Linode hack
#158Earlier quoted context omitted.
You should pay a visit to Sicily or Naples if you don't think there's a difference.
I'd generally prefer government to organized crime, but would probably take the Yakuza over NK or Belarus or wherever.
Italy is not known for having particularly good politicians or government, but I'd take the government here any day over the Mafia or Camorra. Despite any romanticized movies you may have seen, those guys are pretty cold-blooded SOB's. Recently, a man was shot dead waiting to pick his son up from pre-school in Naples.
Re: The story around the Linode hack
#159Earlier quoted context omitted.
Yep, them too, don't tell anyone about their hacks. (I mean, "More about governments than organized crime? There's a difference?")
You should pay a visit to Sicily or Naples if you don't think there's a difference.
But seriously, yeah, of course there's a difference, but government is also often in league with organized crime, from local levels of corrupt cops and drug leaders, to international levels of the CIA and arms traders and 'our' 'freedom fighers' -- I bet this is also true in Sicily and Naples, that many parts of the government act in league with organized crime.
But yeah, to go back to the actual topic/thread, mainly, I think the guy is right that the government is the other main actor which is going to keep it's security exploits to itself, and just use them to monitor you silently. (And that's probably more likely in the US than any other country on the planet, at the moment).
Re: The story around the Linode hack
#160Earlier quoted context omitted.
tech-oriented channels? Care to name any?
Tech oriented indeed. You know, all of the Open source IRC channels on Freenode are a good start. IRC is nothing like you've described, at least to me.
User hderms didn't describe them, I did. And I can show you hundreds of thousands of channels like I describe, on most popular IRC networks (Freenode is a tiny network in comparison).
Also, I challenge you to show me proof of intelligent discourse in any Freenode channel. It's simply not easy, especially in a channel with 5 or more active participants in conversations. Try taking your time to make intelligent points and either people get bored with you or your points get lost in the scrollback.