5 ms·
Surely something like this: https://blog.linode.com/2016/01/05/security-notification-and-linode-manager-password-reset https://blog.linode.com/2016/01/05/securi
by peterstjohn 11y ago
Surely something like this: https://blog.linode.com/2016/01/05/security-notification-and-linode-manager-password-reset https://blog.linode.com/2016/01/05/security-notification-and... doesn't inspire confidence?
- mindcrime 11y agoSure, but who hasn't been hacked at some point in time? The @tptacek post has an air of suggesting Something Is Really Wrong, like "Linode is a front of the NSA" or something. Would it be that much harder to say "Don't use Linode, they have a bad history security-wise and just got hacked again"?
- ryanlol 11y agoLinode has not only been hacked countless times. So many times in fact that it's hard to blame it on just incompetence, but on gross negligence on their part. Then there's the whole lying to cover up hacks, not investigating clear compromises when reported by customers and generally just avoiding any kind of negative press at all costs.
- fweespeech 11y agoI know for a fact ~7 providers around the same price range have had the exact same problems and were less honest about it. :p Hell, I know some in 2016 that are plain text offenders still. You get what you pay for, and unless you pay about double what Linode charges...you don't get much in the way of added security or protection.
- tptacek 11y agoYou should name them.
- fweespeech 11y agoI think you can figure out why I can't pretty easily.
- spdustin 11y agoJust so I understand: his claim, which doesn't constitute advice of any kind and doesn't ask for any action on the part of the reader, requires substantiation? But your claim, which does have a suggested course of action for the reader, does not require further elucidation? I do know who you are and I do have respect for your contributions, but my friend, it's seems like you're flaunting a sense of superiority when you issue a drive-by decree. It's only made worse when you choose to take the time you could have spent helping the readers whose opinions you're hoping to sway, and piss it away with grammar/spelling corrections and sarcasm. We routinely call out people in other public forums who give blatant non-answers, don't we? I thought your comment was helpful. Until you decided that only those who would take it on faith or on fallible googling would be worthy of your help.
- ryanlol 11y ago>Just so I understand: his claim, which doesn't constitute advice of any kind and doesn't ask for any action on the part of the reader, requires substantiation? But your claim, which does have a suggested course of action for the reader, does not require further elucidation? I'm not sure if tptacek implied the claim requires substantiation, but IMO naming and shaming is just the ethical thing to do when someone is covering up hacks.
- spdustin 11y agoFair enough. Tptacek named. "Shaming" strongly implies stating the actual flaw. FWIW, I am aware of the past issues Linode has had, and hope they do get their act together.
- fweespeech 11y agoYes, but not if you found out such from confidential information you agreed to keep confidential. But in all seriousness, I don't know a single provider that sells cheap VPSs [e.g. At Linode's price point] and actually has something resembling security.
- tptacek 11y ago@tptacek is some dude on Twitter that spends a lot more time thinking about his abs than I do. I'm @tqbf.