|
|
|
|
|
by socillion
4774 days ago
|
|
Worth noting it was a coldfusion 0day manufactured for that attack, and the story from the hackers (HTP) is that Linode was forced to announce it by the FBI despite being blackmailed with their customer credit card database. Of course, they could have handled security internally better but I suspect other VPS providers appear more secure only because nobody has gone out of their way to target them. |
|
The takeaway is that now, while I don't know if I can trust other VPS providers or not, I know I can't trust Linode. (Hell, to some extent, I trust HTP more than Linode now -- I haven't seen a dump of the Linode data on pastebin or a .ru forum yet.)
How a business handles disclosure of a compromise is as important to me as the fact that they were compromised. Notably, this is the second time they screwed up disclosure, after being raked over the coals for it the first time. I was willing to let the first one slide since Linode is so awesome in every other regard, and hope that they would handle the next incident more gracefully. Unfortunately, they didn't.