If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.
Linode hacked, CCs and passwords leaked
191–200 of 418 posts
Re: Linode hacked, CCs and passwords leaked
#192Earlier quoted context omitted.
Extensive PCI audits. Heh.
That compliance web form I absentmindedly clicked through sure had a lot of buttons.
Re: Linode hacked, CCs and passwords leaked
#193Earlier quoted context omitted.
I've done PCI "audits" for several companies I've worked for; it's a checklist you go down yourself . That's why its called a "pci self assessment".
Actually, if you're processing cards directly, you do in fact need to have an PCI-qualified outside firm† (a QSA) audit you for PCI compliance. But those audits are notoriously superficial; PCI audits are a race-to-the-bottom affair. † We are not one of those.
Will add that just having gone through an ICANN registrar audit (which by the way were specified and supposed to be done literally 10 or 12 years ago but never requested by ICANN) with a third party company hired (accounting firm) it's total compliance theater.
Add: "hired by ICANN after a bidding process". Same happened with data escrow which was just implemented a few years ago and is operated by Iron Mountain.
Re: Linode hacked, CCs and passwords leaked
#194From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
"Where are the keys?"
"In the locks."
Re: Linode hacked, CCs and passwords leaked
#195Earlier quoted context omitted.
"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.
What are they supppose to say? Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked??? It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COM…
Re: Linode hacked, CCs and passwords leaked
#196Earlier quoted context omitted.
Anyone know of any good way to export linode images to other VPS providers? Seems like I'll have to be doing it manually.
If your using lvm you can create a snapshot to do this while online, if not just read from your disk (assuming sda here): 1. (offline) Boot new and old VM servers from live CD 2. old server: dd if=/dev/sda bs=8M | pbzip2 -c | netcat 3. new server: netcat -l | pbzip2 -cd | dd of=/dev/sda bs=8M Compression: You can use something besides pbzip2, maybe pigz of if you only have a single core use bzip2 or gzip. Security: Y…
Re: Linode hacked, CCs and passwords leaked
#197Earlier quoted context omitted.
Well said. It's a fact of life that companies get hacked. So it's no surprise that it eventually happened to Linode. If you flee somewhere else, all you're doing is hoping that the other company you run to won't get hacked rather than using any logical thought. I can think of two good reasons why you should flee Linode. It remains to be seen if either are actually true, and until indications say yes, then panic is un…
Linode has already grossly mishandled the situation by not coming out with a complete statement about what exactly happened. I only read this news because it was posed here -- no email notification, no update on their homepage, no twitter, no nothing. The alleged hacker has made serious and specific claims, and Linode has done jack shit; without more information, how should I proceed? I don't want to call my bank and…
There was an email notification a few days ago.
Re: Linode hacked, CCs and passwords leaked
#198I just requested a new CC. Can never be too safe. Not sure I'm going to stick with Linode now... sucks because they seemed to be doing so many things right.
Re: Linode hacked, CCs and passwords leaked
#199Re: Linode hacked, CCs and passwords leaked
#200Just like I can have application-specific passwords for my Google account, I wish I could have application-specific credit card numbers from my CC issuer. If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.
Do some research on "virtual account numbers". I haven't used them myself, so I can't verify how well they work.