Earlier quoted context omitted.
Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.
I'd really like to know this as well. (and I'm writing this post instead of just upvoting to hopefully encourage the grandparent poster by showing him that more than one person would like to know of the alternatives out there for switching)
Linode Manager Two-Step Authentication
71–80 of 87 posts
Re: Linode Manager Two-Step Authentication
#72Earlier quoted context omitted.
Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.
I have been testing/working with a few different providers. The three I'm currently working with the most are Ramnode, Gigenet and DigitalOcean. Ramnode's panel is SolusVM which isn't as good as Linode but their performance blows Linode out of the water. They have ipv4/ipv6, multiple locations (Atlanta and Seattle) and a good owner who seems very open/honest with customers. I expect we'll see feature enhancements as…
Re: Linode Manager Two-Step Authentication
#73Re: Linode Manager Two-Step Authentication
#74just a warning: I just enabled it and it wasn't working with my account & google authenticator for android. I had to call customer support in order to disable the feature so I could login into my account again.
Re: Linode Manager Two-Step Authentication
#75Earlier quoted context omitted.
Do they think their customers are stupid and will forget the incident? Yes. They have done it before and people on here still recommend them with a straight face. It honestly confuses me that people care so little about security.
I'm one of those people who have a slight interest in the security but don't know enough about it to be properly informed about my own decisions. For people like me who basically can't make my own decisions properly, where should I switch to? Is DigitalOcean better in this regard?
Re: Linode Manager Two-Step Authentication
#76I left Linode after 5 years of being a customer because I can no longer trust them. I let the first issue slide as I thought they would learn and communicate better to their customer base but the second incident has shown they learned nothing. Security issues will happen with any provider it is all in how a provider communicates and remediates those issues. Linode has shown it will not communicate thoroughly and does…
Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.
Re: Linode Manager Two-Step Authentication
#77To get some positive content out of this thread. Is there a VM provider with a provably better security record than Linode?
If you are going to stay with Linode then 2FA seems like a no brainer. So, is there a simple way to get the 2FA iDevice systems (Google, Duo) to work on multiple devices, say to allow an iPad or an iPhone to be used interchangeably?
Re: Linode Manager Two-Step Authentication
#78Earlier quoted context omitted.
I have to imagine the overlap between Linode customers and smart phone owners was so large (and the cost of implementation so low) that leaving out hardware authenticators makes sense for v1.
One area where hardware authenticators work really well is where you want to split access to an account, or have some accountable/logged procedure for it. You put the physical token in an envelope and in a safe/put it in the control of a finance person. Tech people have the password, but need to request the token to do logins. This also requires having role accounts which aren't able to reset authentication settings…
These physically secure OTP techniques are interesting, but shouldn't you have accountability at the system level anyways? If everyone has a two-factor device and a password, it's pretty tough to plausibly deny that you logged into a server. Someone would have to guessed your password and stolen your device.
Re: Linode Manager Two-Step Authentication
#79Earlier quoted context omitted.
I'm one of those people who have a slight interest in the security but don't know enough about it to be properly informed about my own decisions. For people like me who basically can't make my own decisions properly, where should I switch to? Is DigitalOcean better in this regard?
Digital Ocean is largely untested in this regard.
Two factor auth addresses the user password as being a weak link, and this is a nice step
Oh and btw, yes, the private keys were on the server, with a passphrase
Re: Linode Manager Two-Step Authentication
#80Earlier quoted context omitted.
Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.
I have been testing/working with a few different providers. The three I'm currently working with the most are Ramnode, Gigenet and DigitalOcean. Ramnode's panel is SolusVM which isn't as good as Linode but their performance blows Linode out of the water. They have ipv4/ipv6, multiple locations (Atlanta and Seattle) and a good owner who seems very open/honest with customers. I expect we'll see feature enhancements as…
My experience with Rackspace is similar to what you describe
Another issue with AWS is that it's expensive (for always on systems)
Might check these afterwards