4 ms·
Counterpoint: Linode is incompetent at security. $228,000 worth of bitcoins were stolen because Linode's admin interface was compromised by an attacker. The rea
by sillysaurus 13y ago
Counterpoint: Linode is incompetent at security. $228,000 worth of bitcoins were stolen because Linode's admin interface was compromised by an attacker. The reason you probably haven't heard about it is because Linode never publicly acknowledged that it happened, as far as I know. Those are two serious black marks against the credibility of Linode. Use at your own risk.
http://arstechnica.com/business/2012/03/bitcoins-worth-228000-stolen-from-customers-of-hacked-webhost/ http://arstechnica.com/business/2012/03/bitcoins-worth-22800...
- grey-area 13y agoOut of curiosity, what's your preferred vps provider?
- dchuk 13y agoWhile the security breach is a big problem, it seems like storing $228,000 worth of bitcoins on a server that can be attacked from the internet is a bad idea.
- sillysaurus 13y agoIt was a bitcoin trading platform. Many bitcoins had to be accessible by a sever. It wasn't the platform's fault that they lost the bitcoins. Linode's admin interface was the attack vector. This is roughly equivalent to getting robbed because your landlord left your apartment's master key under a doormat.
- gtCameron 13y agoTo continue that analogy, its roughly equivalent to keeping $200k cash in a briefcase the floor of your apartment instead of in a safety deposit box at the bank.
- sillysaurus 13y agoThat analogy is completely invalid. It was a trading platform. How do you propose they trade bitcoins without those bitcoins being accessible by the server?
- ewillbefull 13y agoBitcoin trading platforms do not need bitcoins accessible by remote servers. They should have a huge portion of the coins in cold storage (not available from remote servers). Also, the storage and attribution of coins to accounts should be done by a server under physical possession/control, so that authentication cannot even be forged in the event of a frontend breach. There are a lot of things you can do to protect your bitcoins. Having them all on linode servers is the worst thing possible. http://en.wikipedia.org/wiki/Air_gap_%28networking%29 http://en.wikipedia.org/wiki/Air_gap_%28networking%29
- ericd 13y agoYeah, that's one of those applications that you really need to colo and secure yourself with outside security verification, or at the very least go with a host that has a reputation for ironclad security. Hosting that kind of thing on a low-cost VPS is ridiculous.
- ceol 13y agoFrom what I remember, it was a 17 year old kid who built and ran the site, and it was his first time ever handling financial transactions (there was another bitcoin-related hacking around the same time, so I might be confusing them.) It was a recipe for disaster.
- sillysaurus 13y agoIt's incredible how much people are willfully ignoring Linode's gross incompetence in this matter.
- 13y ago
- grey-area 13y agoHosting bitcoins on any vps is not a good idea. I'd be hesitant to store just a few, but trying to run an exchange on one is like trying to run a bank on a vps. I agree linode's response was not ideal and they should learn from that and be far more transparent (see recent twilio billing issues for a good example of the way they should have responded), but hosting digital money which can be stolen on a shared vps is not a good example of a failure solely down to linode - those bitcoins wouldn't be safe on any vps long term, and their presence sounds like it caused this targetted hack in the first place.
- opendais 13y agohttp://status.linode.com/2012/03/manager-security-incident.html http://status.linode.com/2012/03/manager-security-incident.h... 3/1/12 - 9:43pm, before the article was written. They didn't acknowledge the amount but if you are expecting them to disclose their customer's information [even things like amounts of Bitcoins stolen] that is in violation of any reasonable privacy policy. :/
- geuis 13y agoValid counterpoint. Your level of security measures should scale to the importance of the application. I've never been a big fan of web-based consoles for VPS (where you can login to the server even if you screw up your ssh certs for example). However, that ability saved my bacon a few times early on when I was learning how to configure my server on Slicehost. Now, I really wish I could disable it. The one thing to be remembered is that as customers, we are only as loyal as the company is. When they start doing things that affect us in negative ways, we move to newer pastures.
- ceol 13y agoEvery hosting service will have at least one security breach, especially if someone is doing something reckless like storing $230,000 worth of digital money on one of their servers. Leaving a provider because of a breach just means you're in an endless game of VPS musical chairs. The way they handled the breach is another thing, though.