Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Their blog answer most of your questions.

https://blog.linode.com/2013/04/16/security-incident-update/

You can't prevent 0 days, and the informations hacked were encrypted.



Remember that was the 2nd or I believe 3rd time the same management UI was hacked. And that post was done days after the incident occurred e.g.

http://www.webhostingtalk.com/showthread.php?p=8646073

The issue here is not the 0 days occurred but how you deal with them and what systems you have in place to prevent them. Linode has consistently been sloppy at notifying customers and their auditing systems are/were clearly inadequate since their positions changed over the few days. Sure their data is encryptable but if you are sloppy about the process you're likely pretty sloppy about the implementation. It's trivial to decrypt data if you haven't encrypted it properly.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: