Live data from Hacker News

Linode Security Advisory

blog.linode.com

91–100 of 119 posts

Re: Linode Security Advisory

#91

Earlier quoted context omitted.

I left a Glassdoor review about Linode that was removed because I mentioned an employee (anonymously) who rubbed his genitals on coworkers' keyboards as a joke. This was reported to and covered up by management because the employee was essential. Anyway, Glassdoor responded to ostensibly a Linode complaint by removing my review several weeks after I left it. So they do watch it. There's a lot more to the story, for s…

Employee Disclaimer: It's not 2011 and Mike is not working at Linode anymore. You really don't get what it's like working at Linode TODAY. I'm sure everything your stating was terrible for you but it's not an accurate representation of what the company has become.

Can you comment on Linode intentionally covering up security breaches? That's post-2011.

Re: Linode Security Advisory

#93

Earlier quoted context omitted.

> SHA-2 for password hashes They're moving on from them, but they're going to leave SHA-2s sitting there and wait until everyone logs in to upgrade to bcrypt hashes at rest. Not getting a super competent vibe off of these folks.

To add to that, bcrypt is not the best recommendation if choosing a password hash today. In theory they should be adopting Argon2 (or maybe scrypt). In practice, I suspect that either the bindings for Argon2/scrypt don't exist or aren't easily adoptable given their use of ColdFusion. They do exist in Python. Either way, it seems like a sub-optimal decision.

    they should be adopting Argon2
I'm saying this as a proponent of Argon2, who has invested a lot of time trying to improve the codebase[0].

It currently isn't ready in large production. Efforts to stabilise the API are being spearheaded by someone apparently outside the project[1]. If you're reading this @lucab, thank you.

In the meantime, my Ruby bindings have been broken on three separate occasions due to API changes. You could easily say "Don't track master", but the one release has a tag of 20151206, and it's just an arbitrary a tag as any particular commit id. There is no branch from which you could apply "bugfix only" updates.

Two separate commits broke compilation. This commit[2] was a shambles.

Most importantly, they have commits going in two days ago that change the test vectors[3]. That means if you update your library, verifying existing passwords breaks. The hash identifier doesn't change ( in the way that bcrypt had $2, then changed it to $2a then $2y when they changed the algorithm) which means you can't just write an "upgrade hash" function. I can't find any documentation relating to this change.

It's important to note that none of this means your passwords are easily broken, or that it's insecure, which is the implication I often see thrown around when discussing Argon2 being "new".

[0] https://github.com/P-H-C/phc-winner-argon2/commits/master?au... [1] https://github.com/P-H-C/phc-winner-argon2/issues/61 [2] https://github.com/P-H-C/phc-winner-argon2/issues/87 [3] https://github.com/P-H-C/phc-winner-argon2/commit/37e031213e...

Re: Linode Security Advisory

#94

Earlier quoted context omitted.

I feel DO's level of service is on-bar. I've gotten multiple discounts from DO for "annoyances" I wasn't even annoyed by.

This is because DO is desperate to retain customers. I don't know if it's still the case, but a year or so ago the CEO was personally handling customer service, responding via email and adding credits to people's accounts. If the CEO has that much time on his hands, to personally handle every customer dissatisfaction, then the customer base must be quite small. I think for me the largest red flag was DO not even havi…

DO aren't small: http://news.netcraft.com/archives/2015/05/01/digitalocean-be...

Re: Linode Security Advisory

#95
post #19
post #6

Update: also, read this comment right away. https://news.ycombinator.com/item?id=11136948 I find this update very hard to follow. Can someone tell me if I'm misreading it? I'm going to quote it twice, and then attempt to summarize: After examining the image from our July investigation, we discovered software capable of generating TOTP codes if provided a TOTP key. We found software implementing the decryption method…

Yeah, they really gloss over the fact they have no idea how the TOTP secret key was compromised, which worries me the most.

They changed the 2FA to use a microservice, so whatever the vulnerability was before, if the 2FA is now on an isolated server, that vulnerability shouldn't have access to the new 2FA key.

Re: Linode Security Advisory

#96
post #19

Earlier quoted context omitted.

Yeah, they really gloss over the fact they have no idea how the TOTP secret key was compromised, which worries me the most.

They changed the 2FA to use a microservice, so whatever the vulnerability was before, if the 2FA is now on an isolated server, that vulnerability shouldn't have access to the new 2FA key.

But given that they don't know what the vulnerability is, there's no way of knowing that.

When it comes to the security of who's hosting my servers, I want a little more reassurance than they shouldn't have access. I need to know that they don't.

Re: Linode Security Advisory

#97

Not sure what to think about Linode anymore, on the one hand from a pure reliability point of view they have been bullet proof, had a few issues during the DDoS in December and I've always found their support to be good (the few times I've used them in 7 years). On the other hand they've had security issues fairly regularly and their response to the DDoS was pretty poor. That said if I was a cynic I'd say they probab…

I have to be fair about Linode's performance. My Argon2 test suite averaged around 45 seconds on my Linode. I've relocated my VPS to AWS following these recent discussions around security, and the same test suite now runs between 5 and 20 minutes, presumably based on what my neighbours are doing at the time. It's a frustrating tradeoff.

That's not a particularly useful comparison without at least stating the instance types you were using on each provider.

Re: Linode Security Advisory

#98

Hey There, I'm a PagerDuty employee and am the same individual who made this post on the last HN thread: * https://news.ycombinator.com/item?id=10845985 Unfortunately, there are some facts in Linode's post that are not correct. >On July 9 a customer notified us of unauthorized access into their Linode account. The customer learned that an intruder had obtained access to their account after receiving an email notifica…

[deleted]

Re: Linode Security Advisory

#99

Earlier quoted context omitted.

I left a Glassdoor review about Linode that was removed because I mentioned an employee (anonymously) who rubbed his genitals on coworkers' keyboards as a joke. This was reported to and covered up by management because the employee was essential. Anyway, Glassdoor responded to ostensibly a Linode complaint by removing my review several weeks after I left it. So they do watch it. There's a lot more to the story, for s…

Employee Disclaimer: It's not 2011 and Mike is not working at Linode anymore. You really don't get what it's like working at Linode TODAY. I'm sure everything your stating was terrible for you but it's not an accurate representation of what the company has become.

The same people are running the company who did then, who were responsible for setting the culture of the company, covering for employees who did unspeakable things (worse than what I've said here), and pretty much instructing employees to lie to customers.

Also, all the people who quit Linode and ran to this coast after I left have kept me very apprised of what working at Linode is like TODAY. I still communicate with your colleagues quite regularly, too.

It is important to reiterate here, as I have before, that I wish Linode no ill will. I'm becoming more comfortable with calling spades spades, but I do not wish Linode to fail. I actually hope a lot of this stuff can be fixed, whatever that entails, but I have a serious gripe with some events that have transpired since 2011, from security to personal. If Linode would start being a little more honest about their gaping security troubles, and not rely upon people like me and Tim who actually know the truth to just shut up about it (I'm getting braver as Tim does, and I appreciate how willing he is to not let PagerDuty be tossed around by Linode's deceit), I'd be a bit happier. We're crossing into knowingly compromising the safety of the Internet, PII, and a number of production infrastructures that still run on Linode in some cases, and I do care about that.

And again, that tone of deceit is set from the top.

Re: Linode Security Advisory

#100
post #70

Earlier quoted context omitted.

This is very helpful information. Can you say if you've moved to a different provider or if you're now racking your own machines? And if you do have a new provider, can you say who you are and how you evaluated them? I have been doing some research in my (limited) spare time to try to find a new provider, but I still have not made the switch from Linode.

If you follow the link he posted, you'll see they switched away from Linode almost immediately after the July breach.

[deleted]
Post reply on HN