4 ms·
They changed the 2FA to use a microservice, so whatever the vulnerability was before, if the 2FA is now on an isolated server, that vulnerability shouldn't have
by SomeCallMeTim 11y ago
They changed the 2FA to use a microservice, so whatever the vulnerability was before, if the 2FA is now on an isolated server, that vulnerability shouldn't have access to the new 2FA key.
- madeofpalk 11y agoBut given that they don't know what the vulnerability is, there's no way of knowing that. When it comes to the security of who's hosting my servers, I want a little more reassurance than they shouldn't have access. I need to know that they don't.
- KaleidoscopeFan 11y agoI think it's fairly important to note that they're NOT currently using the microservice for the 2FA, and they're NOT using bcrypt right now. The blog post states they're "working towards" these changes, they're not currently in place. It's fairly unlikely that they're using the same secret key as the one they found on the server, but it's fair to assume that they are still using salted SHA-2 for your passwords and the same 2FA setup right now. They likely won't roll out the major changes until they roll out the "new and improved" Linode dashboard they're coming up with.
- monster2control 11y agoThe article didn't state that. The article stated they are rolling out soon. The new dashboard will be an open source project. So you'll know when that gets released. There is no link to the project yet so assume that part isn't started yet. So the microservices should be released in a timely manner. Let's hope with the new focus on transparency if there are any delays they will keep us posted.
- KaleidoscopeFan 11y agoIsn't that exactly what I said? o.O I said they will "likely" get rolled out with the new dashboard, not that the article said they would lol. But, they never stated when it would happen anyways, so "delays" aren't really a thing when there's no deadlines.