7 ms·
Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my de
by AlexMuir 13y ago
Ah this is so shit. I want to support Linode, I've had nothing but a good experience. But I just had to check my credit card to be sure they hadn't lost my details. I've NEVER had to do that before with anyone - they've got to respond fast here because if I don't trust them with my CC then I can't leave five-figure contracts at jeopardy hosted on their servers.
I've been living comfortably on Linode servers for over three years. This is like suddenly being evicted and having to pack my stuff up and find another apartment.
I have to wait for some sort of verification for this but if true then I have to leave Linode. I have client sites hosted here - not for cost reasons, just because I like Linode.
For the sake of $5 a month I can't even take the slightest risk of being criticised for using Linode. And this lack of transparency could be a nail in the coffin here.
I don't want to waste a couple of days on this but that's what's going to be involved if this is true.
- thenomad 13y agoQuite. I like the company and their servers are good - but we need a detailed response, and we need one now.
- kyrra 13y agoI'd say support tickets or posting on their forum[1] may help try to get a response. But based one one of the support ticket responses posted in the comments in this HN story already, it sounds like Linode isn't allowed to release that kind of information yet. They may be waiting on the police and/or their lawyers to allow them to talk publicly about it. And if that isn't the gating factor, they are probably trying to determine what they are required and should share about the incident. [1] http://forum.linode.com/viewtopic.php?f=20&t=9978 http://forum.linode.com/viewtopic.php?f=20&t=9978
- chintan 13y agoits a recursion! the forum points back to here
- dbecker 13y agoThey may be waiting on the police and/or their lawyers to allow them to talk publicly about it. Waiting for their own lawyers would be a particularly weak excuse. This is a priority, and they are responsible from conveying that urgency to their lawyers.
- clicks 13y agoI've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode. I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions. Linode customer support keeps saying they have "no comment" on this issue (which I suppose does make sense -- I'm assuming they've been ordered by law enforcement persons to not share details), so as we're not being given much information to work with... just treat this as a worst-case scenario (all names, addresses, credit card numbers, etc. have been compromised). Do operate now with the assumption that all of this data has been compromised and may very well be public soon.
- deleted 13y ago[deleted]
- eridius 13y agoI would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.
- clicks 13y agoThere's baseless speculation and then there's I have some information speculation. I'm operating on heuristics which rely on information that is handily available. Yes, in the end you're right, I'm just speculating. But hey, it's better to err on the side of caution.
- jbraithwaite 13y agoIf it is indeed true that credit card numbers were compromised, it would behove Linode to tell their customers quickly so they can take the proper action. With this lack of transparency, I feel like I had no choice but to block my card.
- windsurfer 13y agoAnyone know of any good way to export linode images to other VPS providers? Seems like I'll have to be doing it manually.
- jdboyd 13y agoGenerally speaking, this is one example where having a good deployment system starts to look extremely valuable (along with tested backups and restores for non-deployed data).
- windsurfer 13y agoI'd have to agree with you, but I didn't figure creating such a system for my hobby projects was worth it.
- voidlogic 13y agoIf your using lvm you can create a snapshot to do this while online, if not just read from your disk (assuming sda here): 1. (offline) Boot new and old VM servers from live CD 2. old server: dd if=/dev/sda bs=8M | pbzip2 -c | netcat <newhost> <random high port> 3. new server: netcat -l <same port> | pbzip2 -cd | dd of=/dev/sda bs=8M Compression: You can use something besides pbzip2, maybe pigz of if you only have a single core use bzip2 or gzip. Security: You probably want to add encryption to this pipeline.
- windsurfer 13y agoWoah woah woah isn't this just transferring the contents of /dev/sda in the clear over the wire? Shouldn't you at least do this over SSH?
- voidlogic 13y ago>>Shouldn't you at least do this over SSH? Yeah, I mentioned that at the bottom of my post. Using ssh or some other inline encryption would be a good idea if it is a system you care about. If you have a site to site VPN tunnel between your systems, you can skip adding the encryption.
- chatmasta 13y agoPlease do realize: lack of suspicious charges on your credit card is not evidence that it was not stolen.
- epo 13y agoAah!, the self-fulfilling nature of paranoia.