Linode hacked again?
vpsboard.com
vpsboard.com
Should you decide to switch to another VPS provider I strongly recommend you cite the security problems when they ask you why you're closing your account. The only reliable way to get the security message across to technical managers and business people alike is to make it about money. That said the fact that this has happened, in this way, again to Linode is a very bad sign.
Having been in meetings, advocated for taking security seriously, and heard the rationalizations for a lax approach I can only say that as a customer if your desire for security isn't made crystal clear you have no hope of getting it. It has to be a deal breaker or not only will companies like Linode not learn, but their competitors who stand to gain from their loss won't either.
<gallaeaho> zectorpt: no
<gallaeaho> zectorpt: nothing was "hacked", but old stuff got posted
<gallaeaho> again
Of course, Digital Ocean has had its own problems lately with not properly scrubbing decommissioned VPS containers... so to some degree, data security is not a Linode specific problem. And for that matter it is not just because someone is recycling passwords (bad), but because it is by nature one of the most fundamental and pervasive security challenges with any VPS hosting. Your AWS node might be perfectly secure, but it might be sharing a physical rack with a Russian botnet and you'd have no way to know.
Bottom line, if you are using a shared environment there is always some risk of having bad neighbors, experiencing disruption at the supervisory layer or of your data bleeding over into an untrusted location. Your application security design should be planned accordingly, and the choice of VPS host is only one part of that equation.
what really made me move away from linode is really their inability to accept paypal.
Luckily, digitalocean accepted paypal. Also their $5 servers cannot be beat.
Sure, linode has some good panels but it was more than I can chew and more than I needed. Digitalocean also had a good amount of docmentation to do everything I needed without filing a ticket.
How could this affect a VPS provider? Say a customer hosts a porn site, or a gun-selling site, or something else PayPal disagrees with. PayPal shuts the merchant's account down for it. Now the merchant's funds are frozen for an indeterminate amount of time till the issue can be resolved, if at all, and there's nothing they can do about it short of appealing to PayPal.
I am very sympathetic to anyone not wanting to use paypal for these reasons.
It is too big a risk, especially for something like a VPS provider that needs the recurring payments.
Something doesn't add up here. Surely Linode can't be that careless.
These things are happening often enough for them to be a competitive strategy between rival VPS hosting companies.
(I happen to have servers hosted at Linode, Digital Ocean and a local provider, and always find it amusing to tally the amount of "happy customers" that pop up in comment threads like this)
Update: I've gathered from chats on IRC here and there that this is a legitimate concern.
Also: curl http://ra.pe/linode2.sql | grep --only-matching -E ".{8}your credit card number.{8}"
My guess is that this is an old development DB that was left on a server that may have been forgotten about.
Seems to have some logs of the linode channel today.
Also: Can we please stop taking comments on IRC as a credible source of information?
That said, it seems to be a pretty poor choice of a password at the very least...
Obviously if you don't have the experience in this, your susceptible to this kind of leak.
Also, looking through the post data on there, it's all from 2003. And I can't find any of the posts listed in this sql dump on their active DB. I see nothing exciting here.