Live data from Hacker News

Linode Manager Two-Step Authentication

blog.linode.com

81–87 of 87 posts

Re: Linode Manager Two-Step Authentication

#81
post #59

Earlier quoted context omitted.

Or it means you didn't bother to delete the public key (since, hey, free backup at the cost of not typing rm) when you generated the keypair.

You're assuming a single piece of information has a single key-pair. E.g.: 1. Obtain sensitive information 2. Generate a new key-pair 3. Encrypt with public key 4. Store encrypted info 5. Delete public key 6. Use private key to decrypt when reading the data It's also likely they they were using one key-pair to encrypt all of their data (or all of a specific type, e.g. one key-pair to encrypt all passwords). In this c…

No, I was thinking the latter, but the data should in that case be encrypted with the public key, which can be copied to the web-facing servers.

Re: Linode Manager Two-Step Authentication

#82
post #66

Earlier quoted context omitted.

Because obviously nothing ever improves.

They certainly aren't improving their transparency.

Their transparency hasn't been awful; it should be better. I am for now giving the benefit of the doubt that they'll be releasing further details as they become more certain of them and/or investigations conclude.

Re: Linode Manager Two-Step Authentication

#84
post #4

I was hoping for Yubikey support. But I'll take this for now. I'll have to see if the Google Authenticator app shows up on all of my iDevices linked to my Apple account and whether the code from any of them will work (from the setup process, I don't see why not). Does anybody know? If the app will work from any of iDevices, it would not be secure enough for a service storing bitcoins :) because the second factor shou…

it would not be secure enough for a service storing bitcoins Linode was hacked twice (once where Bitcoins were stolen) in recent times and was shown to have the worst security practices I've ever seen. They have never been secure enough for storing Bitcoins.

Are you serious??

What you were doing is the equivalent of living your wallet in a public place unattended, and then shouting and screaming it got stolen. You are putting your bitcoin wallet on a public accessible server, you should know the risks of this by now.

Don't leave your wallet in a public place unattended, that includes your bitcoin wallet.

Let me guess, you didn't bother to encrypt your wallet either, didn't you?

Don't blame others for lack of security, if you can't even figure out your own security best practices...

Re: Linode Manager Two-Step Authentication

#85
post #11

This will do absolutely nothing if Linode themselves are hacked, which is what happened the past two (100% of the) times.

The only to prevent it, is to implement the two-facotr authentication on protocol-level instead of application-level. This brings you to smartcard-authentication, or VPN solutions (using smartcard or RSA tokens)

But if they would implement that, everybody will start screaming that they have to pay for a smartcard or rsa-token...

Be honest here, how many of you would actually want to pay for that?

yeah, thought so...

Re: Linode Manager Two-Step Authentication

#86

Earlier quoted context omitted.

it would not be secure enough for a service storing bitcoins Linode was hacked twice (once where Bitcoins were stolen) in recent times and was shown to have the worst security practices I've ever seen. They have never been secure enough for storing Bitcoins.

Are you serious?? What you were doing is the equivalent of living your wallet in a public place unattended, and then shouting and screaming it got stolen. You are putting your bitcoin wallet on a public accessible server, you should know the risks of this by now. Don't leave your wallet in a public place unattended, that includes your bitcoin wallet. Let me guess, you didn't bother to encrypt your wallet either, didn…

Are you replying to the right person ?

I don't own Bitcoins. And if I did I would never, ever host them on a Linode server.

Post reply on HN