Live data from Hacker News

Linode hacked, CCs and passwords leaked

slashdot.org

391–400 of 418 posts

Re: Linode hacked, CCs and passwords leaked

#391

Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers. I've been living comfortably on Linode servers for over…

Please do realize: lack of suspicious charges on your credit card is not evidence that it was not stolen.

Aah!, the self-fulfilling nature of paranoia.

Re: Linode hacked, CCs and passwords leaked

#392

Earlier quoted context omitted.

Doesn't work for me when using an RDP client on Linux. Is this an RDP spec thing or a microsoft only feature?

I think it depends on how you mount your clipboard/drives on rdp connect. To get it right with windows you just check the share clipboard/share drive checkboxes and off to the races. With rdesktop you have to throw the -r flag and mount a clip board and then the -r flag and mount a drive. Not sure about other Linux clients but I'm sure there's a similar option in all of them.

Excellent, thank you very much. I use KRDC and a bit of googling shows that that uses rdesktop in the background. I shall investigate.

Re: Linode hacked, CCs and passwords leaked

#393

Earlier quoted context omitted.

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

I've had roughly the same experience: in the last 8 years, I've had suspicious activity on my CC about 5 times. Each time, the bank caught and trapped it before I noticed and issued me a new card quickly. I've only had to fill out paperwork for a disputed charge once, and it was a 2-page, 2 question, sign-and-mail-it-in deal. My advice is different, though. I notice that I tend to get lucky in places where people can…

Or most people are lucky, and you hear about those who have aggravating experiences.

Re: Linode hacked, CCs and passwords leaked

#394
post #367
post #357

Earlier quoted context omitted.

Even old card numbers can be used for transactions in some cases.

Sure, but that isn't the former owners problem. Are you thinking of expired cards? That is different.

I can be in some cases. I got mugged and my card was used to pay for parking garages for 1.5 years until it expired even though it was canceled and blocked by the issuing bank. They said that for some transactions, the blocking mechanisms are so expensive its more economically sane to them to refund whatever was drawn.

Re: Linode hacked, CCs and passwords leaked

#395

How about you guys cool it and stop organizing a lynching mob devoid of any real data? It's embarrassing. HN is supposed to be populated with lots of very smart, data-driven analytical folks. Yet, every time something like this happens out of the woodwork come people who would ran you and your children down in the event of an emergency rather than turn around, carefully evaluate the situation, and help you. Don't be…

Mob-mentality. Unfortunately naturally occurs whenever a group gets to be about the size of a mob.

The IQ of a Mob = (The lowest IQ in the Mob) / (The size of the Mob)

This from a Terry Pratchett book. Can't remember which one, but it's one of the earlier Discworld books.

Re: Linode hacked, CCs and passwords leaked

#396
post #377
post #156

I am an ex-customer of Linode and I'm still worried about this incident - Do they still store your card after you've quit the service? This is terrible :(

I've asked them this question. Here is the answer: Credit card information continues to be stored in our database in an encrypted format, and the decryption key is not stored electronically. We are working on a process on remove the credit card details of past customers on request and can handle this for you soon if you would like. If you have any further questions or concerns please let us know.

Thank you :)

Re: Linode hacked, CCs and passwords leaked

#397
post #312

Earlier quoted context omitted.

Credit card numbers are of pretty low value. Like way less than a buck in medium volume and still just a few bucks for the super premium ones. And there is way, way more inventory of them than interested buyers. The likelyhood of a coordinated break in of a large hosting service with the intention of stealing credit cards is pretty low, and the chance that they'd be exploited so quickly is even lower. Unless the atta…

You bring up very good points, thanks. I contacted Linode support and they've said in clear terms that they have no evidence that payment information of customers was accessed. I initially signed up for Linode because my friends spoke highly of the tech people working at Linode. Right now amidst all the commotions it's ryan's words (some anonymous dude who joined #linode/irc.oftc.net) vs. an established company's. I'…

Apparently they weren't entirely honest with you, then: https://news.ycombinator.com/item?id=5556846

Re: Linode hacked, CCs and passwords leaked

#399
post #6

From a purported abridged chatlog with the alleged hacker: > 05:42 credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security > 06:00 They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...

There is literally zero evidence to suggest they compromised anything more than a webserver.

Re: Linode hacked, CCs and passwords leaked

#400

Earlier quoted context omitted.

"because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions." I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times. Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained. I think it w…

It depends on how sophisticated the identify theft is. I had a good friend who was taken for about $9000 in credit card fraud in 1998/1999, with Well Fargo. It took him the better part of six months, and endless correspondence with WF to prove all of the purchases were not his. There are lots of stories of people who were financially wiped out, to the point of bankruptcy, because of Credit Card/Identify fraud. With t…

That makes me wonder why the credit card system is so insecure in the first place. Why are credit card systems not secured with a password that the merchant never gets to see? Yet at the same time credit card suppliers keep bragging about how "secure" their cards are.
Post reply on HN