Live data from Hacker News

The story around the Linode hack

straylig.ht

61–70 of 175 posts

Re: The story around the Linode hack

#61

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

> - Linode got railroaded here and the general reaction by folks is a little overdone. You know that's true when even the hackers' overview of the hack specifically calls out people bitching about Linode security on Twitter. All it takes is one zero-day, and you will all be hit by one in your career, so cut Linode a little slack.

Unfortunately, there's not much slack left to cut. Linode pulled that line taught with the last major breach of their system (and their subsequent opaque response).

It's clear Linode's security practices leave a _lot_ to be desired, and their response to this incident, while better than the last, didn't go anywhere near far enough in terms of transparency (as well as demonstrating some fundamental gaps in their understanding of the current state of infosec).

Re: The story around the Linode hack

#62

Earlier quoted context omitted.

A right? I didn't say they have a right. They hacked into. Did the US/Israel have a _right_ to use Stuxnet against Iran? No. They hacked into. When did you accuse the US secret service or hope that they will be punished? Double standards? I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

You're not getting it. No one is saying that Stuxnet was "right". That conversation is set in an entirely different context than the Linode hack. Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country. There is no segue from Stuxnet to this Linode hack. "Fault" is not in question here either. Let's say I leave my front door unlocked. If you enter my home withou…

I admit Stuxnet was a bad analogy to black hat hacking. But either is the analogy of hacking into a server and physically trespassing into a private property.

The main goal of my comments is to object to the opinion that hacking is somewhat comparable to physical break and enter actions. This is an age where one can find himself in prison for tens of years for hacking and getting access to information (the prospects of Aaron) or even for IP violations, as it were a murder or rape.

Being in an underground hackers crew is much fun and possibilities to learn things for young men who are smart and different than their friends. Those guys and gals are the future top-class engineers at Google and other IT giants and I want them to continue hacking and growing personally and professionally, not rotting in the prison.

Re: The story around the Linode hack

#64
Some of their claims seem a bit far-fetched. Hacking name.com, Xinnet, MelbourneIT, and Moniker? That would be huge. Why haven't we heard more from them?

> We identified which users on HTP were involved with the FBI, and promptly gained access to one of their cams.

Not sure what they mean here. FBI camera? User's laptop camera? Either way this also seems far-fetched.

If everything they said was actually true it's very impressive.

Re: The story around the Linode hack

#65

Some of their claims seem a bit far-fetched. Hacking name.com, Xinnet, MelbourneIT, and Moniker? That would be huge. Why haven't we heard more from them? > We identified which users on HTP were involved with the FBI, and promptly gained access to one of their cams. Not sure what they mean here. FBI camera? User's laptop camera? Either way this also seems far-fetched. If everything they said was actually true it's ver…

They claim to have accessed the mole's webcam. That's not very far-fetched at all.

Re: The story around the Linode hack

#66

I can't think of a better classification for a terrorist than people who sit around all day working to destroy credibility of corporations and expose personal and financial information for the sake of their own fucked up moral code and amusement. It would be nice if we had internet role models. IRC is full of low-life degenerates who perpetuate the vitriol that reinforces this way of life as an acceptable pastime. If…

IRC is a communication medium. Could we please not vilify it? It's like saying people who use burner phones are bad people.

Re: The story around the Linode hack

#67

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

I don't give a shit about my (former) linode servers and never want to have anything to do with the bastards again.

I just want to know one thing: did or didn't they leak the credit cards?

Re: The story around the Linode hack

#68

I am not familiar with the crackers' terms. So does this mean that name.com is not safe? All my domains are there...

Looking around there doesn't seem to be any news on a breach at name.com, official or un-official (aside from this of course).

It does have me worried however.

Re: The story around the Linode hack

#69

I can't think of a better classification for a terrorist than people who sit around all day working to destroy credibility of corporations and expose personal and financial information for the sake of their own fucked up moral code and amusement. It would be nice if we had internet role models. IRC is full of low-life degenerates who perpetuate the vitriol that reinforces this way of life as an acceptable pastime. If…

IRC is a communication medium. Could we please not vilify it? It's like saying people who use burner phones are bad people.

It's also a machine that generates dumbed-down conversation. The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends. There's nothing inherently wrong with this. But it does foster negativity much of the time.

I know hundreds of people who dedicate their lives to the drama and bullshit that is spawned solely by being in an IRC channel. If it went away, these people might just find something productive or positive to do with their lives.

Re: The story around the Linode hack

#70
post #18

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

> For this to go down entirely unnoticed is extraordinarily difficult. I won't say impossible, but damned close without a copy of the zone in hand and with Linode running AXFR disabled (you should be too). There are subzones of linode.com; they wouldn't have gotten them all, and it would have been noticed within minutes. what's stopping the bad guys from just proxying dns queries they don't care about to the original…

>with this sort of trickery you could get a "domain control validated" https certificate too!

I don't understand why HSTS didn't allow some sort of pinning, or the ability to specify a certain kind flag in the certificate is required (like EV).

Post reply on HN