Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can't understand why ANYONE is still using Linode after their disgraceful behaviour at the start of this year.

For those that don't remember they were hacked and a sizeable sum of Bitcoins were stolen from a number of VPSs after their customer service app was hacked.

The problem is that (a) customers were the last to hear about it having to find out the news from Reddit, (b) we still don't know exactly what happened, (c) we don't know whether it affected other VPS or whether it is still an issue, (d) what they've learnt/changed.

Compare this to Cloudflare which was transparent and open with everyone and clearly learnt a lot of lessons. Trying to hide your mistakes at every turn is NOT how you run a service company.



OK, let's be sensationalist for a moment: I should stop using Google, Dropbox, Microsoft, Apple, Sony, Amazon... They have all been hacked at one point or another and very rarely do we get details of what actually happened. Ohh yea, I should give up my US citizenship as well. I hear about the US gov getting hacked all the time and they don't let us know whats going on either.

People love hating on hosting companies, and touting their own horror or success stories. When will people realize that mistakes are inevitable. To me, one mistake every once in a while is forgivable. Perhaps I could also careless about bitcoins (they seem about as worthless as Second Life money). Linode did mention publicly that only 8 accounts were compromised and no credit card info or passwords were available to them.


Also, while I'm not commenting on Linode's response to the incident, ultimately the security of your information is up to you. The owner of the stolen Bitcoins has publicly stated that he learned a lesson: encrypt your data.

Your server, your data, your information is only as safe as you make it. Even if everything is fully encrypted and all a hacker could do to mess with you is delete your instance, you should have offsite backups of your important stuff. Always assume you're going to lose everything. Whether it's hardware failure, hacking, or a simple mistake, treat a gun like it's loaded.

Encrypt your important data. Use two-factor authentication on privileged accounts. If you want Bitcoins to be a currency, then read up on Payment Card Industry regulations and really understand how to keep a currency secure.Hire an auditor if need be. Everyone is going to be hacked, everyone is going to be embarrassed, and your data is never secure unless you make it secure.


encrypting your data doesn't help when it is inside memory and somebody else has root.

the attack was a hypervisor intrusion, linode's VM setup was hacked, none of these recommendations would have helped at all in this case.


Linode does offer basic two-factor authentication, which was one of the things I mentioned. You have the ability to set up IP address whitelists. If you try to log in from an address not on the whitelist, you get an email to confirm you are who you say you are. If I know the attack correctly, the hacker reset (or otherwise gained) the password via the support console and used that to log in. With two-factor, he could get the right password but would still need access to the email account as well. Unless you've majorly fucked up, there is no way anyone besides you is getting root.

You sign no SLA with Linode. They make no guarantees. That leaves it up to you to make sure you're secure, and fortunately they give you the tools needed to make this a reality.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: