I was hoping for Yubikey support. But I'll take this for now. I'll have to see if the Google Authenticator app shows up on all of my iDevices linked to my Apple account and whether the code from any of them will work (from the setup process, I don't see why not). Does anybody know? If the app will work from any of iDevices, it would not be secure enough for a service storing bitcoins :) because the second factor shou…
Each copy of the software needs to be initialized with a token. Google tries to limit you to have one copy initialized at a time, but I'm not too sure how effective they are.
Linode Manager Two-Step Authentication
41–50 of 87 posts
Re: Linode Manager Two-Step Authentication
#42Not everybody owns or wants a smartphone. Linode needs to extend this to some non-smartphone device, like YubiKey, or offer SMS codes, like Google Authenticator. This is a step in the right direction, but is ultimately disappointing for me.
I have to imagine the overlap between Linode customers and smart phone owners was so large (and the cost of implementation so low) that leaving out hardware authenticators makes sense for v1.
This also requires having role accounts which aren't able to reset authentication settings when logged in, though, to really be good (or else you just disable tokens on first successful login).
Also works well for paranoid people who don't trust their phone, or people who log in only from a phone/tablet and thus where MFA is really one-device-authentication.
Re: Linode Manager Two-Step Authentication
#43Ok, so can anyone recommend an established VPS provider, with a comparable management interface, and a track-record of excellent security practices?
AWS also has the best first and second derivative on everything related to product; they were essentially crippled crap in 2006, and have turned into a viable option over the past years, without slowing down. Compared to the level of innovation in colo/dedicated hosting (~zero per year) and openstack, AWS is amazing.
It's still inferior to a good on-premises or colocated environment (mainly due to technical limitations in the virtualized environment; AWS's policy is top-notch commercial standard), but that may not matter for you. AWS pricing and performance is also worse in a lot of ways than dedicated hardware, but may also not matter to you.
A lot of the big cloud/dedicated hosting companies have decent security (SoftLayer, Rackspace), but aren't as good at AWS at policy or technical security. The sketchy VPS providers are miles below the middling standard set by companies like Rackspace.
Linode is solidly in the "sketchy VPS provider" realm. A bit better for availability, and not likely to actually be attacking you themselves, but not a responsible choice for anyone who cares about security from everything I've seen.
PaaS, in practice, is also a good solution if you care about security but have no skills or budget. While Heroku has its own set of problems around price, performance, and availability, it's more secure out of the box than a badly configured/maintained AWS deployment of your own, or a badly configured on-premises/colocated cage or dedicated servers.
Re: Linode Manager Two-Step Authentication
#44For anyone installing the Linode's recommended Windows App "Authenticator", WARNING, it does not work! I was locked out! I then used the Microsoft's Authenticator app to find the right token.
Do not logout without verifying it works first in an incognito mode. Better yet, save the secret key temporarily to your PC.
Re: Linode Manager Two-Step Authentication
#45After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…
I also find it really troubling they haven't released a "Here's what we're doing different" blog post in response to the attack. Their only blog post on the matter came a week (2 weeks?) after the intrusion, which they were of course pressured to release after everyone found out via a pastebin IRC transcript... By chance I happened to sign up for my first Linode account the day before that hit HN. I hope their silenc…
Do they think their customers are stupid and will forget the incident?
Yes. They have done it before and people on here still recommend them with a straight face. It honestly confuses me that people care so little about security.Re: Linode Manager Two-Step Authentication
#46Earlier quoted context omitted.
Each copy of the software needs to be initialized with a token. Google tries to limit you to have one copy initialized at a time, but I'm not too sure how effective they are.
Is this an iDevice limitation? The android version doesn't connect to Google's servers at all, so there would be no way for them to know you've setup multiple copies.
Re: Linode Manager Two-Step Authentication
#47Security issues will happen with any provider it is all in how a provider communicates and remediates those issues. Linode has shown it will not communicate thoroughly and does not talk about any remediation so why would you trust a company like that with your data?
The last incident was extremely sad for me because I thought I was using a company that I had a good relationship with. I could care less that CC details were lost as CCs are easily replaceable and protected against fraudulent use. What they lost was my trust which is far more valuable that my credit card number.
Re: Linode Manager Two-Step Authentication
#48Earlier quoted context omitted.
They admitted that the encrypted CC numbers were leaked, they didn't mention if the encryption keys were stored on the same machine. The alleged hacker said that the encryption keys were stored on the same machine, making the encryption useless.
It was also made clear that the encryption key was protected by a passphrase which was not stored on the machine.
Re: Linode Manager Two-Step Authentication
#49I left Linode after 5 years of being a customer because I can no longer trust them. I let the first issue slide as I thought they would learn and communicate better to their customer base but the second incident has shown they learned nothing. Security issues will happen with any provider it is all in how a provider communicates and remediates those issues. Linode has shown it will not communicate thoroughly and does…
Re: Linode Manager Two-Step Authentication
#50After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…
But what makes you think its competitors are any better?