Live data from Hacker News

The story around the Linode hack

straylig.ht

1–10 of 175 posts

Re: The story around the Linode hack

#5
There is a lot of inside-baseball in this, but the one they keep talking about, is, "shred customer data" - as in,

" Recognizing their situation, we instead told them that if they acknowledged HTP in their analysis, we'd go ahead and shred their customer data anyway."

Do they honestly, for a single second, think that any LEA, corporation, or, well, anyone would believe that once the information was compromised, that there was no putting the genie back in the bottle? Also - I suspect there are probably disclosure laws that had to be followed by Linode anyways.

Re: The story around the Linode hack

#6

I am not familiar with the crackers' terms. So does this mean that name.com is not safe? All my domains are there...

The point is, when you're dealing with people of this level of supposed skill, they can just walk into pretty much any network. They're all vulnerable on some level if you're capable of actually breaking them yourself in novel ways.

The only real solution is either to not depend on any single network, or to make it clear that you will simply kill anyone who troubles you. Or just remain innocuous enough that nobody will care to.

Re: The story around the Linode hack

#8
post #4

That seems somewhat scary if they've compromised domain registrars and are intercepting login data from client sites that way.

It's more scary if they've compromised a SSL CA. A simple DNS attack won't stop your browser from displaying a broken certificate warning. (Though they can always not redirect from http to https and most users won't notice, sadly.)

Re: The story around the Linode hack

#9

There is a lot of inside-baseball in this, but the one they keep talking about, is, "shred customer data" - as in, " Recognizing their situation, we instead told them that if they acknowledged HTP in their analysis, we'd go ahead and shred their customer data anyway." Do they honestly, for a single second, think that any LEA, corporation, or, well, anyone would believe that once the information was compromised, that…

[deleted]
Post reply on HN