Linode hacked, CCs and passwords leaked
slashdot.org
slashdot.org
I've been living comfortably on Linode servers for over three years. This is like suddenly being evicted and having to pack my stuff up and find another apartment.
I have to wait for some sort of verification for this but if true then I have to leave Linode. I have client sites hosted here - not for cost reasons, just because I like Linode.
For the sake of $5 a month I can't even take the slightest risk of being criticised for using Linode. And this lack of transparency could be a nail in the coffin here.
I don't want to waste a couple of days on this but that's what's going to be involved if this is true.
I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions.
Linode customer support keeps saying they have "no comment" on this issue (which I suppose does make sense -- I'm assuming they've been ordered by law enforcement persons to not share details), so as we're not being given much information to work with... just treat this as a worst-case scenario (all names, addresses, credit card numbers, etc. have been compromised). Do operate now with the assumption that all of this data has been compromised and may very well be public soon.
I live on the internet. Put my credit card out on many services. Over the last 5 to 8 years I've had my credit card numbers taken I believe 4 times.
Never had to dispute it once. These Credit Card companies and Banks have a stake in not allowing your account to be drained.
I think it would be a waste of time to go out and cancel our CC until hearing from Linode that yes, CC information was taken.
With that said - almost everyone seems to feel comfortable handing out their credit card to random taxi drivers, waiters, sales staff - with no idea whether a copy of their information is being taken down. Heck - if you give them the Credit Card, they even get your CCV as well.
My advice is different, though. I notice that I tend to get lucky in places where people can have very aggravating experiences. I'd say that if you've had problems before, then anticipate problems this time around too. If you haven't, then don't bother.
Mine is not a CC or a debit card, it's a 'prepayed card' so liability is limited.
Still, I'm considering calling the lost/stolen line of the card.
Thank you for contacting us. We have no evidence at this time that any payment information was compromised."We appreciate the response, and we can assure you that we have implemented all appropriate measures to provide the maximum amount of protection to our customers."
Waiting for their own lawyers would be a particularly weak excuse. This is a priority, and they are responsible from conveying that urgency to their lawyers.
1. (offline) Boot new and old VM servers from live CD
2. old server: dd if=/dev/sda bs=8M | pbzip2 -c | netcat <newhost> <random high port>
3. new server: netcat -l <same port> | pbzip2 -cd | dd of=/dev/sda bs=8M
Compression: You can use something besides pbzip2, maybe pigz of if you only have a single core use bzip2 or gzip.
Security: You probably want to add encryption to this pipeline.For the record, I am a Linode customer and just got a new server to migrate a couple of sites into. My plans have not been altered at all by this. I have no data to suggest I should.
I understand your point about the idea that they may be unable to speak to the issue due to law enforcement efforts, but for the moment, acknowledgement would be satisfactory. I would be happy with, "We're aware of the rumors regarding the intrusion at Linode this past week. We are working with law enforcement and cannot comment on details at this time. However, we will provide a full postmortem once we are able to do so."
The problem is when the explanation never comes. It's OK if it's not this second, but tell us it's coming, and then follow through. Complete silence is frustrating.
>Thank you for your inquiry, and I certainly understand your concern. We are still conducting an active investigation and unable to disclose most information at this time. This being said, we do not yet have any evidence that any payment information of any customers have been compromised. We will be releasing further information regarding the incident soon, so please keep watch of our website and blog for said information. If you have any further questions, please feel free to ask.
That actually sounds pretty close to what you're asking for, although I have to say it didn't make me feel much better. It would be nice if they would make a public statement too.
Before it was the widespread hacking that resulted in Bitcoins being stolen. And users were never told exactly what happened and what was done about it.
People have every right to expect the worse with a company with a track record as poor as Linodes.
This from a Terry Pratchett book. Can't remember which one, but it's one of the earlier Discworld books.
I mean, if I was a linode customer I'd definitely be on the phone to the bank, but this guy presented no evidence I'm aware of that he had the kind of access he claims.
> 05:42 < ryan||> credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security
> 06:00 < ryann> They did try to encrypt them, but using public key encryption doesn't work if you have the public and private key in the same directory
http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Hello,
Thank you for reaching out. We appreciate and understand your concerns. At this time the evidence suggest that this activity was targeting a specific customer. We are unable to release any additional details regarding this incident at this time, as there is an ongoing investigation.
We have no comment regarding ryan*'s comments in #linode. You are of course free to take any steps you deem prudent or necessary to ensure the integrity of your online presence.
I am sorry that we cannot provide more information at this time. As always feel free to contact us at any time with any future concerns.
Regards,
QuintinIf you believe this Ryan guy, credit cards stored on the same server as the key to decrypt them, Lish passwords stored in plain text, they've known for some time and lied about what actually happened and now they're saying "we won't do anything about it" via email?
"You are of course free to take any steps you deem prudent or necessary to ensure the integrity of your online presence."
Unbelievable.
Edit: not to mention they "made a deal" with the hacker not to tell anyone? What the hell?
That's a rather key assumption. If you don't believe him, then all you have is a trolling (or at least self-aggrandizing) hacker whose credentials consist solely of logging into an IRC channel, refusing to identify who he was working with, and offering no tangible proof of having compromised any CC info.
On the other hand, it's conceivable that if ryan managed to get into the files a customer was hosting on Linode, and that customer was improperly storing CC info, then their customers' info would have been vulnerable, and ryan's claims would be sort of half-true. Even so, that wouldn't directly affect other Linode customers or put liability in Linode's lap.
But I just checked and my credit card haven't been used anywhere I didn't use it.
"Where are the keys?"
"In the locks."
The 'lower' your level, the easier the PCI audits are. If you are level 1 you have mandatory external audits. If you are level 2 you have a 'self assessment' which is basically a checklist which says "Yes, I promise I'm in compliance".
If you have a confirmed breach, you are upgraded to Level 1 merchant audit requirements. This is generally quite costly as the external audit is extensive and must be paid for.
† We are not one of those.
But if the things he claim in there is even half way true, nobody involved with linode should ever be allowed to be in business every again.
Its also why we invoice and take wire payments rather than storing CC details. There's just so much to go wrong.
Also PKI is shit for this sort of thing. As demonstrated, the moment that public key is gone, then the whole system falls like a house of cards. For the non believers of this fact, why else would there be a certificate revocation list and root CA updates for windows periodically...
Card vaulting as a service: https://spreedly.com/ ($10/mo for up to 5000 cards)
Also I do not think, but I am not sure, that fraudulent wire payments/transfers are reversible.
Wire transfers often are not able to be undone once they happen (and are accepted by the other bank). This is the reason why there's so much verification that happens in wire transfers. (I helped develop 2nd factor authentication used for authenticating wire transfers for a financial company)
Credit card charges can be reversed.
Poor show Linode. (edit: worth noting I use the card with other things too, I have no confirmation it was leaked through Linode other than the compromise happening at the same time these supposed leaks happened).
My day job had some Google Apps account compromises last month, and this is making me paranoid that the database that contained hashed/salted passwords for our Intranet hosted on Linode was the culprit. The time frame doesn't seem to line up, but we didn't see any evidence of phishing or compromised desktops being involved.
(Don't want to spread fear - I haven't been able to find any evidence our Linodes were compromised either.)
I'm normally huge a Linode evangelist, but I'm severely disappointed with the lack of transparency on this. I'm debating right now whether to rebuild all our nodes from scratch as I'm not sure they can be trusted.
also a twitter feed for the customers page ?
Visa has a zero liability program for debit card - http://usa.visa.com/personal/security/visa_security_program/...
These are the FTC's rules [1], I'm not sure if Visa or Mastercard can make them 'better' (give you a larger window). They have an interesting tidbit below their chart -
>If someone makes unauthorized transactions with your debit card number, but your card is not lost, you are not liable for those transactions if you report them within 60 days of your statement being sent to you.
Isn't it free to get a new card? That'd be the easier way than worrying.
[1] http://www.consumer.ftc.gov/articles/0213-lost-or-stolen-cre...
Wouldn't hurt just to ask your bank to re-authorise it anyway? It will change the three digits on the back.
a good practice that bankers constantly tell me is to have a separate credit card for online purchases for the fact alone that it is one step removed from your checking account.
Not that having your account drained doesn't suck, but your worst case scenario there isn't terrible unless you fail to check stuff and be responsible.
Hopefully, they own up and start being transparent.
If this is true then what alternative hosts should I look at, besides AWS?
I've only used DigitalOcean. My anecdotal experience from running a Chef Server on a 1GB instance has been pretty mixed. The price is good, but network and CPU performance feels very variable to me. A month ago their Amsterdam servers were unable to be resized, and there was nothing about it on their status page. I tweeted and was told they'd be working "some time later today". Doesn't fill me with much confidence in general.
I'd still choose Linode for anything of importance - their long reputation is well earned in my opinion. But, if this breach is true, I hope they handle it well.
That is unfortunately the problem though. If this is true, they have already handled it terribly as it has already been 2 weeks since the attack.
That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.
Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked???
It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COMPANY for all we know and looking to scare people off Linode) should be taken with a grain of salt.
If I had these, I would immediately cancel my Linode-specific CC# and reissue a new one. I would not have to worry that my other recurring bills will go unpaid, or spend hours dealing with tracking them down and changing them.
Paypal at one time provided this service as well, but it doesn't seem to anymore [3]
1: https://www.bankofamerica.com/privacy/accounts-cards/shopsaf...
2: https://www.citibank.com/us/cards/gen-content/messages/van/i...
3: https://www.paypal.com/va/webapps/mpp/security/general-freet...
> Set your Valid through date for up to 1 year in the future
I'd really like it to be up to the expiration date of my card. It's probably worth doing anyway, I suppose. Thanks for the heads up. Given the zero-liability status, I'm surprised that banks don't promote this feature more visibly.
I wonder how hard would it be to make a startup like this.
Do some research on "virtual account numbers". I haven't used them myself, so I can't verify how well they work.
Is it a legal requirement to prevent merchants without the CCV from using the credit card?
...oh wait
In that case, specific Bitcoin users were targeted.
It's pretty much why I don't trust Linode.
You can't trust a company which puts random AMI BIOS files on the main index directory on the main web site. You can't trust a company that can't even lock down their own Linode customer service portal (which could lead to a breach of each and every customer's VPS).
Perhaps history is fuzzy for people when new announcements come out or low prices are around.
You really really don't have to. Any payment processor that isn't horribly incompetent does the unique token authorization scheme.
Storing CC #s for recurring payments is solely the domain of incompetents who have no business accepting payments from anyone.
It's never cool to be actually- or quasi-locked into a vendor.
Otherwise you just ask customers to re-authenticate. Often you have a few months headway for a switch like that.
Stripe (and probably others) has functionality like this where the seller's server never sees the CC number, and developers can store a unique token to re-charge the customer at a later date.
You then put your trust in the gateway/processor to store the credit card. Which I assume is most likely behind the best possible security stuff money can afford. Since that's their entire business. One screw up and their gone.
e.g: Acme, Inc. sends Stripe your CC#, Stripe sends them some unique token, and they store that; correct?
So Stripe still has your CC#, and is at risk.
So this is really just risk mitigation; what I think TP is suggesting we need is unique authorizations at the banking level.
Something on the order of virtual credit cards, or temporary tokens, which are ultimately verified by your bank [or in other words: the lender(s) making anti-fraud guarantees, etc.]
(e.g: this token is authorized for 24 hours up to this limit; this token is authorized indefinitely up to $xx/mo.; this token is authorized for 1 year; etc.)
Edit: yes Stripe has your number, but since their sole business is about securing that information, they probably do a better job of it than your typical online merchant.
I think that Linode did a big mistake here. Let's wait for a formal communication.
But this is the moment to support them. Yes, maybe sounds crazy.
When you host on any third party datacenter, you take risks that something like this could happen. So, deal with it. Check your credit card, if your receive something wrong, call to your card and that's all. But we need to support also the good work, and this guys do great work in the hosting business. Just my opinion.
I can think of two good reasons why you should flee Linode. It remains to be seen if either are actually true, and until indications say yes, then panic is unwarranted:
1. If it becomes apparent that Linode is far more vulnerable to hacking than other hosting providers. But one hack alone does not prove this.
2. If Linode grossly mishandles the situation. There have been a couple of allegations to that effect so far, but nothing substantial. I don't see any reason to claim that they've done this yet.
The alleged hacker has made serious and specific claims, and Linode has done jack shit; without more information, how should I proceed? I don't want to call my bank and waste time getting a new credit card (not to mention replacing a million and two services) without a confirmation and I can't get a confirmation because Linodes people are having a circle jerk (or whatever the hell they do).
There was an email notification a few days ago.
Linode's handling of the Bitcoin incident last year was sub-optimal. This too has been sub-optimal, given that credit cards were exposed but all we heard on Friday was to change our passwords, and even that was claimed to just be a super-careful precaution.
Linode needs to start giving us some frank talk ASAP. They've already burned through a very generous helping of benefit-of-the-doubt.
If that's even true.
This is not a mistake/technical issue, it's becoming an ethics/service one.
This sounds very very bad, and as a customer it's very off-putting.
"No comment."
If the allegations are true, then Linode was keeping encrypted CC numbers, with the decryption key in nearly the same place.
Trying to make the analogy more sufficient by incorporating this type of fact would only make the carjacking analogy more absurd. At the end of the day, an analogy is not needed.
Edit: Groan, here's their clarification. It's starting to look like they don't know what the heck they're talking about:
"Thanks for getting back to us. To be extra cautious it would not hurt to regenerate your Linode API key. You can do that in your user profile. Please let us know if you have any other concerns we can address."
The Lish password is set to a random string by default, however we would still recommend resetting this password even if you had not set one manually previously.
I had expected that if the password was not set, then password auth was disabled. I've told them that's what I want and have asked when it will be implemented.I will probably be moving away from Linode after this. The poor response to this and lack of full disclosure, plus reading that they're using ColdFusion (wtf?), means I don't feel I'll be able to trust them any longer. It's a shame because their UI and service is generally fantastic.
Besides, it's not the reason I'm leaving - it just makes me question them. I'm not after glitzy. If anything, I'd have expected Linode to have been written in Perl or something.
The Debit Card was used in a Credit transaction, so Visa's general protections still apply. You can dispute any of the transactions if they were done through credit (which online ones are nearly 100% of the time).
06:07 < ryannn> They say there's no 'central weak point'
06:07 < ryannn> Yeah there is, there's the developers
06:08 < ryannn> There's been bugs in the client that have allowed the blockchain to split previously
06:08 < ryannn> One could just backdoor the bitcoin client binaries, not the source.
06:08 < ryannn> Nobody would figure it out until it's too late
http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
A month later, spend 30 minutes on the phone with CC company only if strange transactions appeared.
Not the end of the world. The CC industry is set up well to handle this kind of thing.
If even an iota of what I read in the abridged IRC log is true, Linode doesn't seem to care much about security or protecting Linode customer data. I mean, storing "encrypted" card numbers alongside private/public keys? Really.
I will happily dismiss this breach, not because they didn't make some amateur crypto mistake, or because they weren't using freaking ColdFusion, or because they were storing data in some nice compartmentalized form, I reject because this happens every single day and has done for decades, and there is an entire sub-industry built around its after-effects. If you don't understand this you shouldn't own a credit card.
If you type a credit card number in online not expecting to recuperate any damage caused from your card company, call them up now for clarification or cancel the damn card. That's equivalent to stuffing cash in an envelope and posting it to Nigeria because some prince promises he'll keep it in a safe for you. It's 90% the reason you should be using credit cards in the first place. Think.
Linode should not be rubbished here. They've got one of the largest VPS installs around, so they most likely know their shit. They make an ultra-common CC mistake that has happened daily for almost 20 years now, by companies large and small, got pwned due to a bug in someone else's software, and you think I'm going to play along with the righteous indignation bullshit here? GTFO.
Let he without sin cast the first stone. Despite 20+ years' experience I still cannot cast that first stone. I make bullshit mistakes like this every day, and despite your grandiose delusions you probably do too.
As for whiners complaining about their data suddenly being insecure, well, data security 101: you're making the same bullshit mistake Linode are making, and despite that you're complaining about it. If you care about data security in the "cloud", hosting it on a freaking VPS is not the way to do things.
Kind of sucks to have to spend hours doing that for someone else's oversight. It's not the end of the world, but it paints a clear picture about where a company's priorities are.
If the hacker's claims are true (Would appear so, the directory listing checks out) then Linode really need to address this ASAP. Passwords are one thing but to have CC details leaked is even worse. I'm not familiar with CC processing but it seems like bad practice to store the encryption keys on the web server.
"This hotfix resolves a vulnerability that could be exploited to impersonate an authenticated user (CVE-2013-1387).
"This hotfix resolves a vulnerability that could be exploited by an unauthorized user to gain access to the ColdFusion administrator console (CVE-2013-1388)."
http://www.adobe.com/support/security/bulletins/apsb13-10.ht...
> 05:05 < ryan_> manager.linode.com was breached with a coldfusion exploit
...
> 05:33 < Ruchira> ryan||: give us the link to cold fusion vulnerability that you are talking about
> 05:34 < ryan||> Ruchira: 0day
> 05:34 < ryan||> linode staff apparently failed to deduce it themselves and relied on chmodding CFIDE to 000
http://www.carehart.org/blog/client/index.cfm/2013/1/2/serio...
The basic overview is this: CF servers have an administrative portal at /cfide/. A bug in the scheduler code (think cron) allowed remote attackers to upload arbitrary code to the server and then execute it. Savvy attackers could upload their own backdoors directly into the administrative folder on the site and then execute that code to gain additional access.
As a Linode customer (admittedly only for a small VM I play around with) I have to say I've been impressed with their service and their prices of course, and I'm waiting for further confirmation about the depth of this hack. I was unaware Linode was using ColdFusion. It should be pointed out that CF is a very mature language, akin to ASP.NET. It is actively maintained by Adobe and used by a huge number of websites globally.
Source: I'm a long time ColdFusion developer.
As someone who still maintains a very old CF application, I am sure to lock down access to the admin site via IP restrictions.
http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
--------- 05:43 < ryan||> Well linode also had terribly configured coldfusion
05:57 < ryann> <cfif ListLen(cgi.script_name, "/") gt 2 AND ListGetAt(cgi.script_name, 2, "/") eq "linode" AND NOT ListFind("index.cfm,linode_edit.cfm,linode_resize.cfm,label.cfm,cancel.cfm,dc_choose.cfm,su.cfm,pastdue.cfm", ListGetAt(cgi.script_name, 3, "/"))> <cfinclude template="/members/linode/common/dsp_topNav.cfm"> </cfif>
05:57 < ryann> this code
05:57 < ryann> It's so dirty I feel bad reading it
Also if you check out my reply below I've C&P'ed the chat logs where he claims it is a zero day:
https://news.ycombinator.com/item?id=5552992
Plus another commenter has linked to a security advisory for exploits in CF that was issued a few days ago.
http://arstechnica.com/business/2012/03/bitcoins-worth-22800...
http://forum.linode.com/viewtopic.php?f=20&t=8509
I had really hoped that they had changed their stance on incident management. If it's true that they suppressed information about a possible wide-scale compromise where customer data could have been affected, then despite everything else about their service that's so great, there's no way anyone should want to continue to be a customer there.
Given Linode's past behavior and the information provided in the IRC chat, I think there's reasonable suspicion that customers' password hashes were stolen and Linode wasn't completely honest in their recent email to customers.
Nevermind the security concerns. These guys aren't using version control!
This could very well be the hackers own submission to /. trying to get more attention for his hack by claiming he has CC numbers which I doubt he has.
Alas, they have not.
I just blocked my credit card, and Linode will not get anymore of my money. Too bad, i enjoyed my stay very much, but no matter what their response will be, I doubt I will be able to believe them. =/
Also, the attaker could also change the account email. Neither tokens nor email confirmation would help.
The biggest problem is for people that used the same password on Linode and any other important service. (And, of course, all the CC stuff...)
I don't know though... will wait until more details are available but will be keeping an eye on CC statements / VPS alternatives.
Doesn't sound very plausible to me.
I think it was just an unfortunately timed third phase of their upgrade plan.
Now if we could only stay the torches and pitchforks for a while before this gets sorted out...
[edit] Just looked at twitter, this tweet doesn't look good: https://twitter.com/Jamiesingleton/status/322730588459114500
But it may just be random coincidence.
[edit again]
Links from slashdot article:
IRC chat: http://turtle.dereferenced.org/~nenolod/linode/linode-abridg...
Link in IRC chat (i think it is of linode.com's web directory): https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc
Credit card information continues to be stored in our database in an encrypted format, and the decryption key is not stored electronically. We are working on a process on remove the credit card details of past customers on request and can handle this for you soon if you would like. If you have any further questions or concerns please let us know.
(It appears the answer is no, but given they haven't been forthright in the actual details of the hack, possibly not)
I thought Linode was different but based on their lack of transparency in this matter, I'm seriously considering just moving all of my sites to DigitalOcean, Rackspace or even AWS instead. This makes me wonder who originally cleared them for PCI compliance in the first place. This is a huge violation of trust and now I've got to keep my eyes focused on my credit card statement for fraudulent transactions, the bank I am with ANZ however has great fraud detection systems and considering I'm in Australia any transaction should be easily reversible, but the fact there is a possibility my card could be fraudulently used saddens me.
Linode needs to come clean about this situation now.
I've noticed before that stuff from the HN frontpage appears on /. one to three days after, but I've never seen it for links to slashdot :-)
Also off-topic: I've noticed that as well with Slashdot, which is why I lurk HN pretty regularly now. Plus, some of the front page material on /. does more to insight angry discussion, and the community has become increasingly more vitriolic.
At least here, even if someone's brash, they're fairly honest about it (in general). I've even seen a number of disagreements that have been respectful and cordial. It's sad to say, but that's a rare thing these days.
----------------------
dportalatin 30 minutes ago Hello,
Thanks for getting into contact with us about this. Linode has found no evidence that payment information of any customer was accessed. We have implemented all appropriate measures to provide the maximum amount of protection to our customers. If you have any other concerns we can address, please let us know.
Regards, Dolores
http://linode.com/googledebcc14d3c9f777a.html and http://linode.com/y_key_57284cb2de704e02.html
If not, it seems likely that he did have read access to the main website filesystem at least
Customer: "hello, i forgot my password and linode's email reminder service doesn't work. i checked spam box but there's no email from linode." Linode Guy: "ryannn: can you give him the password?"
E-mails and logins are also out it seems.
* mode/#linode [+m] by tjfontaine
<tjfontaine> this is what I'm going to say, as a network representative
<tjfontaine> regardless of what has or has not happened with linode, OFTC cannot tolerate release of sensitive information with itself as that mechanism
<tjfontaine> this channel is moderated until staff determines otherwise
Since Linode has proven in the past that they aren't the worst at communication, I can only assume some entity really has them over a barrel, considering the curt and callous responses there.
It's hard to get angry at anybody but Linode needs better auditing around sensitive data so they can tell people one way or the other.
I resigned to the fact that I'd find it easier to change my card details in 30-odd online shops than it is fight my bank to get my money back. Now I can't make any purchases for 7-10 days.
From: "Linode" <support@linode.com>
Date: Sat, 13 Apr 2013 00:11:09 -0000
Precedence: bulk
Return-Path: 6723614.1706014@e2ma.net
Message-ID: <knuab.c9dae.xxx@e2ma.net>
List-Unsubscribe: <http://e2.ma/optout/c9dae/xxx>
X-Test-Mailing: no
Dear Linode customer,
Linode administrators have discovered and blocked suspicious activity on th=
e Linode network.=C2=A0 This activity appears to have been a coordinated at=
tempt to access the account of one of our customers.=C2=A0 This customer is=
aware of this activity and we have determined its extent and impact.=C2=A0=
We have found no evidence that any Linode data of any other customer was a=
ccessed.=C2=A0 In addition, we have found no evidence that payment informat=
ion of any customer was accessed.
We have been advised that law enforcement officials are aware of the intrus=
ion into this customer=E2=80=99s systems. We have implemented all appropria=
te measures to provide the maximum amount of protection to our customers. O=
ut of an abundance of caution, however, we have decided to implement a Lino=
de Manager password reset. In so doing, we have immediately expired all cur=
rent passwords. You will be prompted to create a new password the next time=
that you log into the Linode Manager. We also recommend changing your LISH=
passwords and, if applicable, regenerating your API key.
The following represent best practices in creating new passwords:
-- Avoid using simple passwords based on dictionary words
-- Never use the same password on multiple sites or services
-- Never click on 'reset password' requests in unsolicited emails - instead=
go directly to the service
We apologize for the inconvenience. If you have any questions, please do no=
t hesitate to contact our support team at support@linode.com.Essentially: I am a linode customer. My cc details were somehow leaked. Adds a data point here.
The purported "evidence" is a list of supposed entries in a public_html directory.
https://bin.defuse.ca/hq0Ay8RzpKdR6vQwYxnmhc
Has anyone seen any evidence that this is not simply a hoax?
http://linode.com/MyAddress.class http://linode.com/y_key_57284cb2de704e02.html http://linode.com/ispcheck http://linode.com/k5_3
etc.
I await for more data and hopefully an official response from Linode.
If the worst case is true, what are some good alternatives for Linux VPS hosting?
"One bit of good news from all this hubbaloo: more space will be opened on the new E5 hosts from customers leaving \o/"Here is their response:
Thank you for reaching out to us. We do archive customer credit card details. At this point there is no evidence that customer credit cards have been decrypted.