Live data from Hacker News

OVH Security Incident

status.ovh.net

41–50 of 55 posts

Re: OVH Security Incident

#41
post #25
post #5

Earlier quoted context omitted.

Maybe SHA-512, salted?

Salted SHAx passwords are basically the entire reason GPU John The Ripper and oclHashcat exist, although SHA2-512 is significantly slower than SHA2-256, so if you're going to use a terrible SHA-based password hash, SHA2-512 is your best bet.

SHA512 is slower on most (all?) current GPUs, but there is plenty of hardware on which it is faster than SHA256.

Re: OVH Security Incident

#42
post #37

"The encryption password is "Salted" and based on SHA-512, to avoid brute-force attacks. It takes a lot of technical means to find the word password clearly" "clearly?" OVH is wrong. Based on this information alone, it is not sufficient to say how costly it is to recover the password. SHA-512 needs to be iterated to make it costly to brute force. For example, a raw SHA-512 hash, even salted, is not iterated and is ea…

I think you may be reacting to a mis-parse. The sentence is awkwardly phrased either way, but "clearly" could mean "it is clear that it takes a lot of technical means," or it could mean "to find a clear version (i.e. plaintext) of the password."

Re: OVH Security Incident

#44
post #25

Earlier quoted context omitted.

Salted SHAx passwords are basically the entire reason GPU John The Ripper and oclHashcat exist, although SHA2-512 is significantly slower than SHA2-256, so if you're going to use a terrible SHA-based password hash, SHA2-512 is your best bet.

SHA512 is slower on most (all?) current GPUs, but there is plenty of hardware on which it is faster than SHA256.

Hm. Example?

Re: OVH Security Incident

#45
post #37

"The encryption password is "Salted" and based on SHA-512, to avoid brute-force attacks. It takes a lot of technical means to find the word password clearly" "clearly?" OVH is wrong. Based on this information alone, it is not sufficient to say how costly it is to recover the password. SHA-512 needs to be iterated to make it costly to brute force. For example, a raw SHA-512 hash, even salted, is not iterated and is ea…

It's an ESL issue. He meant to say "in clear" as in "plaintext" rather than "clearly", clearly.

Re: OVH Security Incident

#46

OVH has come a long way. They used to be cheap and bad at service and totally incommunicado about any issues. Then a few years back something changed and they started to work on their image. Their still cheap, but their service is good and getting better and they seem to have nailed the communications angle. Good for them. Between OVH, Hetzner and Leaseweb the EU hosting space is doing fine.

We tried a number of hosting companies before settling on OVH including the premium dedicated companies. They do have the occasional hiccup but overall we have been very impressed with the pricing and the support both reactive and proactive. The day we signed up for our 50th server we received a nice personal email from the head of their support in Montreal.

Re: OVH Security Incident

#47
post #23

Earlier quoted context omitted.

> a blown PSU (caused by their own inability to wire a rack); Please explain. I spotted the BGP failure but this happens from time to time with basically everyone.

A set of dedi's a bought as soon as BHS opened were on a rack that wasn't wired properly, an electrical short blew a PSU.

I believe we also had a bunch of servers in that same rack. Downtime was around 5 minutes from memory.

Re: OVH Security Incident

#48
post #16

OVH has come a long way. They used to be cheap and bad at service and totally incommunicado about any issues. Then a few years back something changed and they started to work on their image. Their still cheap, but their service is good and getting better and they seem to have nailed the communications angle. Good for them. Between OVH, Hetzner and Leaseweb the EU hosting space is doing fine.

Wasn't there a recent thing with their CEO hating Github because of "Githubs agenda of poaching developers" or some shit like that?

Their CEO is not the brightest guy in the universe. This security notice is well written and signed by him... but obviously not written by him.

Re: OVH Security Incident

#49

OVH has come a long way. They used to be cheap and bad at service and totally incommunicado about any issues. Then a few years back something changed and they started to work on their image. Their still cheap, but their service is good and getting better and they seem to have nailed the communications angle. Good for them. Between OVH, Hetzner and Leaseweb the EU hosting space is doing fine.

We tried a number of hosting companies before settling on OVH including the premium dedicated companies. They do have the occasional hiccup but overall we have been very impressed with the pricing and the support both reactive and proactive. The day we signed up for our 50th server we received a nice personal email from the head of their support in Montreal.

We have over 25 machines with them. How do you cope with having to pay individually for every single machine, every single month? Their billing system is non-sense, unless I'm missing something?

Re: OVH Security Incident

#50
post #37

"The encryption password is "Salted" and based on SHA-512, to avoid brute-force attacks. It takes a lot of technical means to find the word password clearly" "clearly?" OVH is wrong. Based on this information alone, it is not sufficient to say how costly it is to recover the password. SHA-512 needs to be iterated to make it costly to brute force. For example, a raw SHA-512 hash, even salted, is not iterated and is ea…

It's an ESL issue. He meant to say "in clear" as in "plaintext" rather than "clearly", clearly.

Definitely: the french for plaintext would be "en clair"
Post reply on HN