Live data from Hacker News

Linode Security Advisory

blog.linode.com

81–90 of 119 posts

Re: Linode Security Advisory

#81
post #34

Earlier quoted context omitted.

I'm not just trying to be argumentative. Here, let me quote more specifically: no evidence of abuse or misuse of Linode’s infrastructure that would have resulted in the disclosure of customer credentials. I feel like I must be misreading something. Didn't they say earlier that they found secrets from their account credentials database on a customer instance that was used to attack (apparently) PagerDuty? That's not "…

you forgot "that would have resulted in the disclosure of customer credentials". I'm speculating, but having been a fly on the wall at this kind of meeting before, here's my theory of how this went down: Manager: "So somebody got the key to generate one-time password tokens for PagerDuty. How did that happen?" Engineer: "I have no idea." Manager: "What about that Lish vulnerability? Could it have been that?" Engineer…

Hah, pretty close except the only person responsible is still there.

Re: Linode Security Advisory

#82

Not sure what to think about Linode anymore, on the one hand from a pure reliability point of view they have been bullet proof, had a few issues during the DDoS in December and I've always found their support to be good (the few times I've used them in 7 years). On the other hand they've had security issues fairly regularly and their response to the DDoS was pretty poor. That said if I was a cynic I'd say they probab…

I feel DO's level of service is on-bar. I've gotten multiple discounts from DO for "annoyances" I wasn't even annoyed by.

This is because DO is desperate to retain customers. I don't know if it's still the case, but a year or so ago the CEO was personally handling customer service, responding via email and adding credits to people's accounts. If the CEO has that much time on his hands, to personally handle every customer dissatisfaction, then the customer base must be quite small.

I think for me the largest red flag was DO not even having bandwidth monitoring in place. The only reason there were no bandwidth limitations was because they were not even physically tracking bandwidth usage. How do you launch a hosting platform without something as basic as being able to monitor bandwidth?

Re: Linode Security Advisory

#83
post #74
post #58

Earlier quoted context omitted.

Why not AWS? They have nano instance types for as little as $5 monthly and infinity more flexibility.

For me, because once you get beyond the $5 nano/free tier, things get expensive really quick. For example, I run about 10 different sites off one Linode, but only one of them gets any substantial traffic. Still, in order to run that site, which works just fine on a $20/mo 2GB/2core unit on Linode, I'll push out about 150GB in outbound bandwidth a month, and require around 15-20GB in storage. Pricing that out on AWS,…

DO box should give you roughly that.

Re: Linode Security Advisory

#84

Hey There, I'm a PagerDuty employee and am the same individual who made this post on the last HN thread: * https://news.ycombinator.com/item?id=10845985 Unfortunately, there are some facts in Linode's post that are not correct. >On July 9 a customer notified us of unauthorized access into their Linode account. The customer learned that an intruder had obtained access to their account after receiving an email notifica…

Are you all still using linode?

/edit never mind they are not as per another reply in this thread

Re: Linode Security Advisory

#85
post #37

Earlier quoted context omitted.

Pretending to do that is ok? I can't believe you're still employed there. Also, I upvoted the comment because I think it should stay visible. I hope other users do that too instead of just downvoting.

He's not. And I can describe his penis, so. There was also stabbing employees (to the point of requiring an ambulance) while fooling around with a knife, setting the building on fire more than once, and tormenting other employees who he didn't like. All of that was tolerated and dismissed by management, specifically Chris Aker and Tom Asaro, which should tell you what you need to know about ever working there. One of…

The responses from this guy are disgusting. Glad I didn't take that job, and I'm sorry to hear about your time there.

I've certainly worked in similar atmospheres. I'm glad you've put it behind you.

Re: Linode Security Advisory

#86
post #51
post #47

I've been using Linode for years and I haven't had too many problems with the service itself. That being said, this makes me think twice about staying with them. If I wanted to switch, is the only real competitor Digital Ocean or are there any other good choices?

http://oktawave.com and http://vultr.com are said to be good. I haven't used them though, I personally use baremetal servers at Hetzner.

I use vultr to host freebsd servers. Have no problems with it but it is young and it definitely shows. Good host provider to keep an eye on.

Re: Linode Security Advisory

#87

Not sure what to think about Linode anymore, on the one hand from a pure reliability point of view they have been bullet proof, had a few issues during the DDoS in December and I've always found their support to be good (the few times I've used them in 7 years). On the other hand they've had security issues fairly regularly and their response to the DDoS was pretty poor. That said if I was a cynic I'd say they probab…

I have to be fair about Linode's performance. My Argon2 test suite averaged around 45 seconds on my Linode.

I've relocated my VPS to AWS following these recent discussions around security, and the same test suite now runs between 5 and 20 minutes, presumably based on what my neighbours are doing at the time.

It's a frustrating tradeoff.

Re: Linode Security Advisory

#88
post #8

I'm just going to leave this glassdoor review here: https://i.imgur.com/sJd56AT.png

I left a Glassdoor review about Linode that was removed because I mentioned an employee (anonymously) who rubbed his genitals on coworkers' keyboards as a joke. This was reported to and covered up by management because the employee was essential. Anyway, Glassdoor responded to ostensibly a Linode complaint by removing my review several weeks after I left it. So they do watch it. There's a lot more to the story, for s…

Employee Disclaimer: It's not 2011 and Mike is not working at Linode anymore. You really don't get what it's like working at Linode TODAY. I'm sure everything your stating was terrible for you but it's not an accurate representation of what the company has become.

Re: Linode Security Advisory

#89
post #74
post #58

Earlier quoted context omitted.

Why not AWS? They have nano instance types for as little as $5 monthly and infinity more flexibility.

For me, because once you get beyond the $5 nano/free tier, things get expensive really quick. For example, I run about 10 different sites off one Linode, but only one of them gets any substantial traffic. Still, in order to run that site, which works just fine on a $20/mo 2GB/2core unit on Linode, I'll push out about 150GB in outbound bandwidth a month, and require around 15-20GB in storage. Pricing that out on AWS,…

If you're are paying double digits or more for cloud hosting, you'd probably get much better bang for your buck by getting a similarly priced dedicated hosting setup.

The main value provided by cloud hosting is easy scalability, not cheap prices.

Re: Linode Security Advisory

#90
post #72
post #44

Earlier quoted context omitted.

Please don't post off-topic replies to the top comment. Or to any comment, really, but with the top comment people sometimes do so to get their own post closer to the top of the page, which is not legit. We detached this subthread from https://news.ycombinator.com/item?id=11136707 and marked it off-topic.

I'm not sure if you actually read the top comment, because my response was very much relevant. tptacek asked about inconsistencies in the Linode advisory, I posted a screenshot of an apparent Linode employee claiming that they lie to their customers regarding security issues. (Which is a claim I am willing to personally back up)

Yea, you're totally not trying to stir the pot...
Post reply on HN