Live data from Hacker News

Linode Manager Two-Step Authentication

blog.linode.com

61–70 of 87 posts

Re: Linode Manager Two-Step Authentication

#61
post #58
post #6

Earlier quoted context omitted.

It's per-device, not per account (I know the guy who developed it for Google; one of the smarter people in the industry). It uses protected storage for the credential so it isn't backed up to iCloud, either. Sadly on Android they don't have the same security features available, due to limitations in the OS; it would be fun to talk to Samsung and make a "actually secure Google Authenticator" specific to the S3/S4 sinc…

The Duo-Security people, who have an Android Token claim to use the secure element in NFC enabled phones. It is a TOTP token and can be used just like the Google Authenticator. You don't have to use Duo-Security's system to use it (though there system is worth looking at if you are rolling out your own authentication system).

URL? I don't see anything about their android "duo push" or "duo mobile" client supporting the secure element, but their website is designed around the kind of people who buy $3/mo authentication systems (enterprise, not saas developers).

Re: Linode Manager Two-Step Authentication

#62
post #23

Earlier quoted context omitted.

They admitted that the encrypted CC numbers were leaked, they didn't mention if the encryption keys were stored on the same machine. The alleged hacker said that the encryption keys were stored on the same machine, making the encryption useless.

It was also made clear that the encryption key was protected by a passphrase which was not stored on the machine.

IRC logs showed the passphrase was extracted from the ColdFusion app's memory.

Re: Linode Manager Two-Step Authentication

#63
post #31

Earlier quoted context omitted.

It was also made clear that the encryption key was protected by a passphrase which was not stored on the machine.

"which was not stored on the machine", like they should be commended ( Reminds me of exams where you received some credit for including your name... ). I am sorry, them confirming this fact, and even if I recall adding a smiley in the tweet they did it, just cemented that they do not understand their business. They clearly wish to give the impression that they are "secure". They need more lock icons...they are almost…

The real problem here is that PCI certification is an absolute joke.

There should be several classes of certification, from "I want to sell a few pet rocks" to "I'm Apple with 150,000,000 credit cards on file". Right now there's basically two.

Re: Linode Manager Two-Step Authentication

#64

Not everybody owns or wants a smartphone. Linode needs to extend this to some non-smartphone device, like YubiKey, or offer SMS codes, like Google Authenticator. This is a step in the right direction, but is ultimately disappointing for me.

Why can't they just use a second email address?

Re: Linode Manager Two-Step Authentication

#65
post #54
post #51

Earlier quoted context omitted.

How about for those that just want a small instance system. I just do the smallest linode setup for some personal projects. From my understanding, AWS is expensive for that type of use case?

AWS Free Tier is...free. I'd probably go with http://prgmr.com/xen/ for low end above that.

How do people expect prgmr.com compares with linode in terms of security?

Re: Linode Manager Two-Step Authentication

#68
Is this likely to actually fix anything? Were the past intrusions via the manager? Or via a compromise of the login to the manager via individual user accounts?

Or is this just a show? Either way, this question itself reflects the fact that they refuse to give proper information and postmortems.

Re: Linode Manager Two-Step Authentication

#69

After being bitten the first time with Linode I don't care what technical measures they are taking. I want to know what process and policy changes have been made. Do they still store public/private keys on the same server ? How often are they doing security audits (which clearly never happened before) ? Are they still going to be dodgy and withhold key information from their users ? Are users still going to find out…

Sure Linode sucked at security and probably still sucks. But what makes you think its competitors are any better?

Hope that there is some sanity in the world?

Re: Linode Manager Two-Step Authentication

#70

Not everybody owns or wants a smartphone. Linode needs to extend this to some non-smartphone device, like YubiKey, or offer SMS codes, like Google Authenticator. This is a step in the right direction, but is ultimately disappointing for me.

How many of linode's subscribers do you think not own a smartphone? I mean, outside of your enclave?

So because the majority of users have smartphones, the option for everyone else is "too bad"?

I've had my non-smartphone for six years now. It still works, and while I'm sure I'll upgrade to a smartphone one day, I have no urgent desire to do so.

Is it really that hard to set up an SMS system as a fallback? I'm still able to use two-factor on my Google account because they offer this solution.

Post reply on HN