Live data from Hacker News

Linode Manager Two-Step Authentication

blog.linode.com

71–80 of 87 posts

Re: Linode Manager Two-Step Authentication

#71
post #49

Earlier quoted context omitted.

Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.

I'd really like to know this as well. (and I'm writing this post instead of just upvoting to hopefully encourage the grandparent poster by showing him that more than one person would like to know of the alternatives out there for switching)

[deleted]

Re: Linode Manager Two-Step Authentication

#72
post #49

Earlier quoted context omitted.

Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.

I have been testing/working with a few different providers. The three I'm currently working with the most are Ramnode, Gigenet and DigitalOcean. Ramnode's panel is SolusVM which isn't as good as Linode but their performance blows Linode out of the water. They have ipv4/ipv6, multiple locations (Atlanta and Seattle) and a good owner who seems very open/honest with customers. I expect we'll see feature enhancements as…

Great post. I'm interested to know which you end up ultimately choosing. I just worry that ramnode and digital ocean won't be able to keep their current price model and still maintain quality service in the years to come.

Re: Linode Manager Two-Step Authentication

#74

just a warning: I just enabled it and it wasn't working with my account & google authenticator for android. I had to call customer support in order to disable the feature so I could login into my account again.

Same here with Google Authenticator for iPhone.

Re: Linode Manager Two-Step Authentication

#75

Earlier quoted context omitted.

Do they think their customers are stupid and will forget the incident? Yes. They have done it before and people on here still recommend them with a straight face. It honestly confuses me that people care so little about security.

I'm one of those people who have a slight interest in the security but don't know enough about it to be properly informed about my own decisions. For people like me who basically can't make my own decisions properly, where should I switch to? Is DigitalOcean better in this regard?

Digital Ocean is largely untested in this regard.

Re: Linode Manager Two-Step Authentication

#76
post #49

I left Linode after 5 years of being a customer because I can no longer trust them. I let the first issue slide as I thought they would learn and communicate better to their customer base but the second incident has shown they learned nothing. Security issues will happen with any provider it is all in how a provider communicates and remediates those issues. Linode has shown it will not communicate thoroughly and does…

Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.

I'm not the comment author, but I've been looking at switching to a dedicated box (probably with Hetzner) and running it as my own Xen host. See https://github.com/jawj/linode-to-hetzner-xen/blob/master/in...

Re: Linode Manager Two-Step Authentication

#77
I find all the whining of all these armchair security experts a bit wearing. No one outside of Linode and the alleged hacker knows exactly why and how Linode was hacked so quit speculating, you are simply making things up. "Ooh, this is a bad thing, I bet Linode did this bad thing". For example people are suggesting that 2FA is useless if outsiders had free run of Linode's infrastructure, and so it would be. BUT, is there any evidence whatsoever that this was the case? If not then STFU and stop spreading lies. 2FA is useless against a nuclear strike, what exactly is the point of saying so? Anyone can fantasise disasters.

To get some positive content out of this thread. Is there a VM provider with a provably better security record than Linode?

If you are going to stay with Linode then 2FA seems like a no brainer. So, is there a simple way to get the 2FA iDevice systems (Google, Duo) to work on multiple devices, say to allow an iPad or an iPhone to be used interchangeably?

Re: Linode Manager Two-Step Authentication

#78
post #42

Earlier quoted context omitted.

I have to imagine the overlap between Linode customers and smart phone owners was so large (and the cost of implementation so low) that leaving out hardware authenticators makes sense for v1.

One area where hardware authenticators work really well is where you want to split access to an account, or have some accountable/logged procedure for it. You put the physical token in an envelope and in a safe/put it in the control of a finance person. Tech people have the password, but need to request the token to do logins. This also requires having role accounts which aren't able to reset authentication settings…

I see what you mean about losing the phone, but unless you're saving your password locally it still satisfies the old "Something you have, and something you know" rule. If you lose your phone, the attacker won't know your password. And an attacker without your phone won't have your OTP.

These physically secure OTP techniques are interesting, but shouldn't you have accountability at the system level anyways? If everyone has a two-factor device and a password, it's pretty tough to plausibly deny that you logged into a server. Someone would have to guessed your password and stolen your device.

Re: Linode Manager Two-Step Authentication

#79
post #75

Earlier quoted context omitted.

I'm one of those people who have a slight interest in the security but don't know enough about it to be properly informed about my own decisions. For people like me who basically can't make my own decisions properly, where should I switch to? Is DigitalOcean better in this regard?

Digital Ocean is largely untested in this regard.

And that's the real issue

Two factor auth addresses the user password as being a weak link, and this is a nice step

Oh and btw, yes, the private keys were on the server, with a passphrase

Re: Linode Manager Two-Step Authentication

#80
post #49

Earlier quoted context omitted.

Out of curiosity, who did you switch to? I would leave too (after being a customer for nearly 8 years) but I'm having trouble finding other providers which don't have their own set of issues.

I have been testing/working with a few different providers. The three I'm currently working with the most are Ramnode, Gigenet and DigitalOcean. Ramnode's panel is SolusVM which isn't as good as Linode but their performance blows Linode out of the water. They have ipv4/ipv6, multiple locations (Atlanta and Seattle) and a good owner who seems very open/honest with customers. I expect we'll see feature enhancements as…

Great list of choices.

My experience with Rackspace is similar to what you describe

Another issue with AWS is that it's expensive (for always on systems)

Might check these afterwards

Post reply on HN