Linode has been hacked at least 5 times¹ in the past decade, and EVERY TIME they try their hardest to downplay the incident and distract attention from it. Avoiding any public communications at all if possible.
This HN comment from a PagerDuty employee is also particularly damning https://news.ycombinator.com/item?id=10845985
I'm not saying I disagree. To prove that, for the record, I informed Linode leadership that ColdFusion admin being world-accessible was a bad idea several years before you and your 'team' were even aware of Linode, and I and another employee proposed replacing ColdFusion long before you flippantly suggested that it doesn't take years[0]. (Try running a hosting provider at medium scale.) I've been just as critical long after leaving Linode as an employee -- I saw oversights like mgreb:mgreb1221 being a full-admin user on world-accessible db1.linode.com for many years with the password in crons, for example -- so please don't interpret me as disparaging your opinion, only your trying to have it both ways with a very clear conflict of interest, and turning your takedown of Linode into a potential annoyance for me and thousands of other people. And yes, I know the key passphrase that you never recovered, despite your public assertions to the contrary.
I was successfully prosecuted for hacking coldfusion things in general, that list included Linode and over 50000 others. There was a pending investigation relating to Linode specifically, but I'm pretty sure that's hit the statute of limitations and can only assume that there's no intent to prosecute.
>Reading your comment with that context changes it slightly
You're right, it does. I considered linking directly to https://news.ycombinator.com/item?id=10845278 but figured I could deliver the information in a more concise manner, without quoting myself.
I made a mistake in not immediately clarifying my relationship here.
>given that since said prosecution you've taken every opportunity to speak negatively about Linode that you can
Since long before that actually.
>And yes, I know the key passphrase that you never recovered, despite your public assertions to the contrary.
What are you referring to? The credit card decryption key? I assure you we most definitely got that, if you want I might be able to dig up old IRC logs from police documents with plaintext credit card information of several linode customers. Jennifer Emick, Robert "xnite" Whitney and Ryan Cleary as I recall.
This is a significant exaggeration, but I'm not going to dox you. Suffice to say, I'm reading your case as we speak, so stop trying to mislead people. (Good luck with that visa.)
> What are you referring to? The credit card decryption key? I assure you we most definitely got that
Then name it. I have the one that protected the key you retrieved memorized on account of my duties (I had to enter it every time I restarted the application), and they've changed it since then, so it's a no-op. It's not brute forceable even by nation states, so you'd have had to extract it by means your entry vector did not give you. Hash it in your reply if you want.
I've always suspected you had former employee help, and I'm pretty sure I know not only exactly who, but also their motive for assisting you and "HTP". If you do have the passphrase to that key, I can almost promise it was from your assistance. I eagerly await your reply, since the passphrase is a sentence, and once you know it the gist of it is easily communicable without consulting logs.
It really isn't. The big number in that charge is referring to coldfusion shells the local CERT was supposedly able to "validate".
At best you could blame the prosecutor for exaggeration, which I entirely agree with, the court however accepted the prosecutors claims.
>Good luck with that visa.
Haven't actually had visa issues anywhere since then :) Good passport I guess.
>Then name it. I have it memorized, and they've changed it, so it's a no-op.
No clue, people within the group disagreed on carding so the person who got it didn't post it on the channel, only dropping the cards of "interesting" individuals. I guess I'll go looking for the logs though.
>It's not brute forceable even by nation states, so you'd have had to extract it by means your entry vector did not give you. Hash it in your reply if you want.
As far as I know someone wrote a quick coldfusion script to extract the decrypted key from memory.
>I've always suspected you had former employee help, and I'm pretty sure I know not only exactly who, but also their motive for assisting you and "HTP".
This was certainly not the case.
>If you do have the passphrase to that key, I can almost promise it was from your assistance. I eagerly await your reply, since the passphrase is a sentence, and once you know it the gist of it is easily communicable without consulting logs.
Don't know, and I'd assume getting coldfusion to spit out the decrypted key is much easier than the decryption passphrase that's only needed once.
And in any case your approach seems fundamentally flawed. Even in some parallel universe where we failed to extract the key, we'd still have been able to use your existing decryption code and the in-memory key to decrypt all the cards in the database.
I haven't typed it since 2011 and still remember it; it's a stupidly simple English sentence that is almost impossible to not memorize. I also note that you and your group were challenged for it in 2013 and declined to provide it. But sure, go consult logs. I'll hold.
> This was certainly not the case.
I know the network and channel where you two hang out, so OK. Keep lying to HN, I guess. (Why would you?)
>I know the network and channel where you two hang out, so OK.
Then spit it out, name the network and channel, don't make vague accusations. I'm open about my beef with Linode, but what's your beef with me?
If this is supposed to be more than a pathetic attempt at discrediting me with false accusations, please follow through.
Move on with your life. You hacked them, you got busted, and sitting around like this four years later is just indefensible.
Edit: I'm remaining vague so as not to dox you, given HN guidelines and my own personal ethics. I don't have any stake in discrediting you (you do a fine job of that yourself), but you're welcome to spin it that way. Also, your clock ran out on being uniquely positioned to comment in 2014. (As did mine, though sooner.)
Fair.
>(b) dumped everything you found online
Not even true. Neither Linode customer db or source code were publicly released.
>(c) spend your days in every Linode thread trying to shit on them while pulling wool over HN's eyes as some kind of moral high ground just "obligatory warning" a bunch of people about your own fucking actions.
Mostly not my actions, but I seem to be uniquely well positioned to give such advice given my that I've seen the insides of Linode.
>You are not the moral high ground. Please stop pretending to be as some kind of authoritative voice.
I'm certainly not the moral high ground, but I've certainly seen for my own eyes just how much of a mess Linode is.
>Move on with your life. You hacked them, you got busted, and sitting around like this four years later is just indefensible.
I don't really care about any of that. To be fair I'm more annoyed with a bunch of my time being wasted because some guy with a thick Australian accent (i.e. obviously not me) swatted them.
But this isn't my personal blog, hit me up on IRC and we can chat.