3 ms·
The CEO has already stated that the private key had passphrase encryption, which is strong, and only stored in their heads. You have to take their word on that,
by scraplab 13y ago
The CEO has already stated that the private key had passphrase encryption, which is strong, and only stored in their heads. You have to take their word on that, but I don't see any proof of CCs being decrypted.
- leeoniya 13y agoi cannot imagine that a remembered passphrase would take too long to brute-force on a few multi-GPU setups. unless they did something meaningful like making it a long sentence rather than some short-but-complex-for-humans 15 char string. http://xkcd.com/936/ http://xkcd.com/936/
- eridius 13y agoSpecifically what they said is it isn't stored digitally. So maybe they have it written down on a piece of paper.
- threeseed 13y agoBased on what we've seen before I wouldn't give Linode the benefit of the doubt. The password is most likely cracked by now.
- nodata 13y agoIt's a passphrase, not a password.
- err_badprocrast 13y ago07:52 < HTP> the CCrypter class of the linode application context was accessable from outside the wwwroot using undocumented ColdFusion methods. i was fully able to decrypt the ccs using the in-memory privkey that they supplied the password for. From the 2nd pastebin'd IRC log, http://pastebin.com/7WXRDyAg http://pastebin.com/7WXRDyAg Note that he states all information was deleted. They had claimed earlier that CC info would be released on May 1st. note: temp account because I accidentally set noprocrast delay to 1 week. Whoops!