Live data from Hacker News

Slicehost Forum User database compromised

rackspace.com

1–10 of 16 posts

Re: Slicehost Forum User database compromised

#2
First Linode and now Slicehost. What's happening to quality VPS these days?

Just a wild guess here, but perhaps the same person who compromised Linode's customer service portal was also trying to see if any of his targets were reusing their Slicehost account credentials in the forum?

Re: Slicehost Forum User database compromised

#3
post #2

First Linode and now Slicehost. What's happening to quality VPS these days? Just a wild guess here, but perhaps the same person who compromised Linode's customer service portal was also trying to see if any of his targets were reusing their Slicehost account credentials in the forum?

Probably someone leaking from the inside due to money/incompetence? That makes their PR go worst though. There's a myriad of scenarios.

They can only be upfront and show how well they respond to the situation including mitigating future security issues.

Re: Slicehost Forum User database compromised

#4
post #2

First Linode and now Slicehost. What's happening to quality VPS these days? Just a wild guess here, but perhaps the same person who compromised Linode's customer service portal was also trying to see if any of his targets were reusing their Slicehost account credentials in the forum?

Hosting providers being compromised is nothing new.

Re: Slicehost Forum User database compromised

#5
You probably adhere to Internet best practices

Bringing up this point might be a better thing to close with, after you communicate what happened. This is the real world, miles from best practices.

They really need to provide a few more details as to why they believe the database was compromised, not much of an explanation offered here.

Re: Slicehost Forum User database compromised

#6

You probably adhere to Internet best practices Bringing up this point might be a better thing to close with, after you communicate what happened. This is the real world, miles from best practices. They really need to provide a few more details as to why they believe the database was compromised, not much of an explanation offered here.

> You probably adhere to Internet best practices

To me that read like an attempt to shift a bit of blame and some subtle framing.

Re: Slicehost Forum User database compromised

#7

You probably adhere to Internet best practices Bringing up this point might be a better thing to close with, after you communicate what happened. This is the real world, miles from best practices. They really need to provide a few more details as to why they believe the database was compromised, not much of an explanation offered here.

> You probably adhere to Internet best practices To me that read like an attempt to shift a bit of blame and some subtle framing.

Second only to: "Simple, you just revert to your most recent complete backup"

Re: Slicehost Forum User database compromised

#8
I'm not sure if I've been sensitised to PR weasel-wording that these things tend to gather (and get blasted for in HN comments), but it's quite refreshing to see something as blunt as "We apologize for our failure to maintain an adequate level of security on our public Slicehost forum, and for any inconvenience this may cause you."

No "mistakes were made", or "We're sorry if you're unhappy about this issue" or any of the other Non-apology apologies[1]

[1] https://en.wikipedia.org/wiki/Non-apology_apology#The_Perfec...

Re: Slicehost Forum User database compromised

#10
post #8

I'm not sure if I've been sensitised to PR weasel-wording that these things tend to gather (and get blasted for in HN comments), but it's quite refreshing to see something as blunt as " We apologize for our failure to maintain an adequate level of security on our public Slicehost forum, and for any inconvenience this may cause you. " No "mistakes were made", or "We're sorry if you're unhappy about this issue" or any…

Note the use of "Slicehost" though. This is a Rackspace forum, installed, managed, and administered by Rackspace engineers.

If you read that release on any other website, you would have no clue whatsoever that this was a Rackspace forum.

Post reply on HN