6 ms·
If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and
by ConceitedCode 13y ago
If this is true then all the trust that Linode has built up over the years was just thrown out the window. According to the hacker they've known for 2 weeks and made a deal with the hackers. Ultimately, they were as far from transparent as it gets and on top of that they did a horrible job with their security.
Hopefully, they own up and start being transparent.
If this is true then what alternative hosts should I look at, besides AWS?
- pibefision 13y agoDon't be so logical please. This can happend to anyone in the industry.
- ConceitedCode 13y ago"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.
- dubcanada 13y agoWhat are they supppose to say? Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked??? It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COMPANY for all we know and looking to scare people off Linode) should be taken with a grain of salt.
- rscale 13y agoThey could say "We have hired matasano security to help us investigate the breach."
- chc 13y agoIf the information he offered is accurate (e.g. the public and private keys were stored together on the webserver), that wouldn't take a long time to confirm.
- zoul 13y agoThey are supposed to say that they would never ever store the CC numbers this way. Otherwise their customers (like me) have really no better option than to block their cards, which is quite an inconvenience. This is exactly the trouble I was hoping to avoid by not using a cheap VPS hosting.
- gtrubetskoy 13y agoThe key thing (that "ryan" mentions not) is whether the private key was password-protected.
- pjscott 13y ago"Logical" is not a fancy synonym for "severe" or "unforgiving", and is probably not the word you wanted here. There are sometimes good, logical arguments that you can make for cutting people some slack.
- clarkdave 13y agoTwo alternatives often mentioned on here are DigitalOcean and RamNode. I've only used DigitalOcean. My anecdotal experience from running a Chef Server on a 1GB instance has been pretty mixed. The price is good, but network and CPU performance feels very variable to me. A month ago their Amsterdam servers were unable to be resized, and there was nothing about it on their status page. I tweeted and was told they'd be working "some time later today". Doesn't fill me with much confidence in general. I'd still choose Linode for anything of importance - their long reputation is well earned in my opinion. But, if this breach is true, I hope they handle it well.
- vladikoff 13y agoYeap same experience here with DigitalOcean CPU performance. If CPU power is important to you, Linode's CPUs are a LOT better.
- sk3tch 13y ago>But, if this breach is true, I hope they handle it well. That is unfortunately the problem though. If this is true, they have already handled it terribly as it has already been 2 weeks since the attack.
- lalc 13y agoYeah, I just migrated from Linode to Ramnode (just in time!) and I'm quite happy with the performance. Great network connectivity.
- Hilyin 13y agoI am using digitalocean, check them out.
- rozap 13y agoI've been using digitalocean for a hobby project, and am planning on launching a more serious project with them. For the past two months I've used them (so, not much experience, but some) I haven't had any issues, and they are very reasonably priced.