Also hey lbotos, hope you're doing well!
Also hey lbotos, hope you're doing well!
I remember that rash of Bitcoin thefts and it was all careless behavior by the Linode owner becoming a secondary consequence of a primary employee compromise, I think. As in what happened to Twitter. Think “admin panel compromised, external actor searches for Linodes known to participate in Bitcoin, methodically compromises them one by one, finds poorly stored wallets and drains them”. That intruder very obviously knew what they were after, if memory serves, but this was almost ten years ago.
Seriously. Linode did one thing well and it was hire (mostly) good people. The comms around security incidents could always use improvement, and I think that led to the loss of trust you’re seeing here. I don’t think it’s just Linode, either, I think a lot of the industry is overly discreet when it comes to what to say publicly about events like this. We see the same with journalism: a lot of methods in reporting are trade skills and most people don’t understand the news gathering process, which leaves room to fill in the gaps with conspiracy. So it is with security, too.
I’d back your speculation, Tim: there were maybe two people, definitely one, maybe two, who could both perform the crime and hide it. One’s an unsavory person to interact with if he doesn’t like you but ultimately ethical and a force for good at his core. The other runs the company. Convince me that either of them did that and you may as well convince me the Earth is flat.