4 ms·
"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security" That's just poor secu
by ConceitedCode 13y ago
"credit cards were encrypted, sadly both the private and public keys were stored on the webserver so that provides 0 additional security"
That's just poor security and 100% they're own fault. I accept that there are security issues with every platform, but basic security measures and being transparent is still expected. My biggest issue with them in all of this is not being transparent.
- dubcanada 13y agoWhat are they supppose to say? Looks like someone who likes attention on some random IRC channel who is apparently a hacker may have hacked our system and we don't know who/when/where/why/how or what they may have got. Nor are we sure we were even hacked??? It takes time for people to investigate stuff. It's not just a couple hours. Also some random guys words on IRC (who could very well own INSERT RANDOM HOSTING COMPANY for all we know and looking to scare people off Linode) should be taken with a grain of salt.
- rscale 13y agoThey could say "We have hired matasano security to help us investigate the breach."
- chc 13y agoIf the information he offered is accurate (e.g. the public and private keys were stored together on the webserver), that wouldn't take a long time to confirm.
- zoul 13y agoThey are supposed to say that they would never ever store the CC numbers this way. Otherwise their customers (like me) have really no better option than to block their cards, which is quite an inconvenience. This is exactly the trouble I was hoping to avoid by not using a cheap VPS hosting.
- gtrubetskoy 13y agoThe key thing (that "ryan" mentions not) is whether the private key was password-protected.