5 ms·
Regarding #1, an update from Linode was just posted: "Our investigation has revealed a customer support interface was used to access your account. The compromi
by stevenbrianhall 15y ago
Regarding #1, an update from Linode was just posted:
"Our investigation has revealed a customer support interface was used to access your account. The compromised credentials have been restricted and we are discussing policy changes to prevent this from recurring."
- mmaunder 15y agoI'm a Linode fanboy, but we need maximum transparency on what occurred and what's being done. What support interface? How compromised? Who's credentials, etc.
- ErneX 15y agoMe too, I've been recommending them a lot and really like their service. I just checked our 2 boxes uptimes just in case.
- redthrowaway 15y agoHopefully they're working on it, and will give a post mortem once they get it sorted out. I'm inclined to show patience and not demand they do anything other than ascertain the scale of the breach, alert those affected, and secure their systems at this point. Later, they can get into what happened and how they will avoid it in the future.
- marshray 15y agoWe can't wait for a full postmortem before Linode says anything. Linode can't just leave us all wondering about our own security while pouring over over someone else's Pastebins.
- lawnchair_larry 15y agoWhere are you reading this? The status page and the blog have no mention of the incident.
- ErneX 15y agoIt's from his e-mail conversation with Linode support: http://pastebin.com/UW7iT5fj http://pastebin.com/UW7iT5fj
- nbpoole 15y agoThat update had already been released when I made my original comment (hence why I said "a customer service interface was compromised via stolen credentials"). It doesn't reveal how the credentials were compromised, nor how the attacker managed to use them to log in.