Live data from Hacker News

If you didn't cancel the credit card you used for linode.com, now is the time

news.ycombinator.com

41–50 of 138 posts

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#41
post #37

Please provide a little more evidence than starting a flame war. Although it could in theory be true, it's a fairly baseless claim until you present a little more evidence. For my online transactions I use prepaid cards that are easy to dispose of, and this card was used solely for linode. Couldn't the online card issuer be to blame? How do we know you haven't mistakenly used it for anything else? The fact that you u…

Why is using prepaid cards for online purchases fishy?

- Prepaid cards impose an upper limit on what can be spent, so that if the card details leak out you are protected against losing more money than is on the card. They can't plunder your entire bank account.

- Some people don't like the idea of having debt. By using a credit card you immediately have a debt whether you like it or not.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#43
post #33
post #13

Earlier quoted context omitted.

I haven't had anything odd yet. Ironically, Chase did flag my DigitalOcean charges last week.

Chase notified that a 3rd party was breached and my credit card was at risk. They sent me a new card two weeks ago. Figured it was because of linode.

Funny, that's about when I cancelled my Chase card. When they asked why I told them an internet company I do business with had been compromised. I have a monthly charge from Linode on the card.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#44
Linode stored the encrypted credit card numbers in our [linode's] database ... we have no evidence decrypted credit card numbers were obtained. [1] To me, this implies that the attackers did indeed get the encrypted data. This would be a mighty juicy target to focus your decryption efforts on! In my mind, it was only a matter of time. Regardless of whether OP's story holds water.. get your card re-issued if this applies to you!

[1] https://blog.linode.com/2013/04/16/security-incident-update/

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#45
post #37

Please provide a little more evidence than starting a flame war. Although it could in theory be true, it's a fairly baseless claim until you present a little more evidence. For my online transactions I use prepaid cards that are easy to dispose of, and this card was used solely for linode. Couldn't the online card issuer be to blame? How do we know you haven't mistakenly used it for anything else? The fact that you u…

Why is using prepaid cards for online purchases fishy? - Prepaid cards impose an upper limit on what can be spent, so that if the card details leak out you are protected against losing more money than is on the card. They can't plunder your entire bank account. - Some people don't like the idea of having debt. By using a credit card you immediately have a debt whether you like it or not.

By using a credit card you immediately have a debt whether you like it or not.

Credit cards are only debt if you treat them like debt. I use the shit out of mine, but pay the full balance pretty much every month. There's a lot of convenience, I'm fully protected from fraudulent activity, and I have a stupid amount of points/miles/whatever for free (or at least cheap) travel, to boot — I flew to .au a couple years ago for free on that basis, for example.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#46
post #38
post #23

Bank Simple actually reached out to me and asked me if I wanted to cancel my card. I did. But I was impressed that they saw that I'd had charges from them and knew about the security issues.

I also use Simple and I've been very happy with their customer support. Not having checks has been a pain in a few cases, but I definitely prefer it over a brick and mortar. I have a few invitations on my account if anyone is interested.

I am! You can reach me at mariodel@gmail.com

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#47
post #37

Please provide a little more evidence than starting a flame war. Although it could in theory be true, it's a fairly baseless claim until you present a little more evidence. For my online transactions I use prepaid cards that are easy to dispose of, and this card was used solely for linode. Couldn't the online card issuer be to blame? How do we know you haven't mistakenly used it for anything else? The fact that you u…

The fact that Linode stored the public and private keys in the same directory is strong evidence that they do not have any competence in security. Their reluctance to disclose the compromise of their customer's passwords and financial data is evidence that they are not trustworthy. So on one hand we have someone who is careful enough about their finances to use disposable prepaid cards for renting a VPS. On the other…

"stored the public and private keys in the same directory"

People keep harping on that, but as phrased that's not a problem. Wherever you have your private key, there's no reason not to also have your public key. The issue is if the private key was living somewhere inappropriate.

Consider that "public and private keys in the same directory" is exactly what happens when you run ssh-keygen on any of the typical setups; failing to then remove the public key is not any kind of a security threat.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#48

Are there any other alternatives out there for VPS service?

I've tested close to a dozen providers, mostly found via http://www.cloudorado.com/ or http://serverbear.com/, and there are many who can match or exceed both Linode and Digital Ocean (who seem to be all over every story here that even touches on VPSes) according to every possible criterion. Personally I went with Host Virtual when I left Linode (shortly after having left Rackspace), but the choice was largely dictated by physical location. Another day it might have been Ramnode. There are others too. The real point is that it's just not hard to find a better VPS host. It's a crowded space.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#49
post #42

Anecdata to the contrary, I've seen no suspicious activity on my Linode-associated card.

Yet? One of the things I've learned by reading Danchev and other blogs on the scourge of credit card fraud is that 'carders' seem to have waaaaaay more cards than they need so the turnaround time between having it be made public and having it used can be quite long. So far for me every time one of my cards has been compromised there was a small charge that went through before the bigger charges came in. And my bank has been pretty good about effectively freezing things as soon as that small charge hits.

Given all the big data stuff on my 'work' cards (like gas card which is only used to buy fuel) it should be instantly obvious if a charge is bogus coming from a non-gas station. But I digress.

I wish someone would set up a 'whitelist only' type credit card where I could first do a small test charge, then I could authorize that source with my bank, and then their regular charges would go through. But if the number was compromised any attempt to use it anywhere that I hadn't pre-approved would be rejected.

Re: If you didn't cancel the credit card you used for linode.com, now is the time

#50
post #34

WF opted to send me a new card out of nowhere, without explaining why they're sending me a new card. I suspect it's due to the linode breach.

My bank does this to me from time to time, without bothering to notify me. It seems incredibly insecure to me - I do have to call to activate it, but there are no "secret" questions asked during this process, just the last four digits of my social security number, and my zip code (and guess where the card gets sent to?)

I believe you only get that streamlined activation if you call from the number they have on file for you, which makes it more secure than it seems.
Post reply on HN