Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject:
PostPosted: Sun Apr 29, 2012 9:33 pm 
Offline
Senior Member
User avatar

Joined: Wed Mar 17, 2004 4:11 pm
Posts: 554
Website: http://www.unixtastic.com
Location: Europe
Gig, You missed the point there somewhat. I can accept downtime because I expect it but DNS slaves and backup mail exchangers are not built to recover from a situation where their primary is misbehaving because the machine got p0wned and is stealing my email or giving out incorrect DNS records.

Obviously a power failure or network outage will only cause downtime, not a compromise of my systems.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 9:43 pm 
Offline
Senior Member
User avatar

Joined: Wed Mar 17, 2004 4:11 pm
Posts: 554
Website: http://www.unixtastic.com
Location: Europe
glg wrote:
nvm, just read post above, vonskippy said it better than me


That would that be the same vonskippy who was insulting people asking for ipv6 back when Linode didn't have it but other providers did.

He is so far in the pro-linode camp as to have lost all objective judgement.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 9:48 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
sednet wrote:
Gig, You missed the point there somewhat. I can accept downtime because I expect it but DNS slaves and backup mail exchangers are not built to recover from a situation where their primary is misbehaving because the machine got p0wned and is stealing my email or giving out incorrect DNS records.

Obviously a power failure or network outage will only cause downtime, not a compromise of my systems.


If you don't think that anything that you can access in linode manager can't be accessed in some fashion by a sysadmin, then I just don't know what to say. You signed up for a VPS product, you're putting some faith in the owner and admins.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:03 pm 
Offline
Senior Member
User avatar

Joined: Wed Mar 17, 2004 4:11 pm
Posts: 554
Website: http://www.unixtastic.com
Location: Europe
glg wrote:
If you don't think that anything that you can access in linode manager can't be accessed in some fashion by a sysadmin, then I just don't know what to say. You signed up for a VPS product, you're putting some faith in the owner and admins.


I am putting faith in them to behave legally. It would be strongly against their interests to do otherwise. Whatever happened to Linode is unlikely to be a result of linode itself behaving illegally. However as they won't give me any information whatsoever I can't be 100% sure.

I want clear information from people who know what happened. Argument and opinion from people that know no more than I do doesn't get anyone anywhere.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:06 pm 
Offline
Senior Member

Joined: Fri Jan 20, 2012 11:19 am
Posts: 100
Quote:
They may be legally unable to say anything


If that's the case then I'd love if they told us that. Hell, if that's not the case, they might as well tell us the same thing anyway, it would get us off their backs.

Either that or just don't say that you intend to communicate openly.

_________________
If all else fails, reboot...
PHP Tutorials and MySQL Tutorials


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:09 pm 
Offline
Senior Member
User avatar

Joined: Wed Mar 17, 2004 4:11 pm
Posts: 554
Website: http://www.unixtastic.com
Location: Europe
nehalem wrote:
Quote:
They may be legally unable to say anything


If that's the case then I'd love if they told us that.


I'd accept that as a perfectly valid reason for not telling us any more. Caker didn't even say that much though.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:10 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
nehalem wrote:
Quote:
They may be legally unable to say anything


If that's the case then I'd love if they told us that. Hell, if that's not the case, they might as well tell us the same thing anyway, it would get us off their backs.

Either that or just don't say that you intend to communicate openly.


Chicken/egg problem there. If a lawyer advised them to shut up, they lawyer isn't going to tell them to say that.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:10 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
I'm not sure I've weighed in on this thread, yet. I've previously criticised linode for the IPv6 policy (indeed, I'm still not happy with it). I eventually got sufficiently annoyed with Fremont that I moved the service to Dallas.

I'm not a "fan boy" by any means.

sednet wrote:
One side wants to know what happened


Which is an unreasonable request. In my day job (security professional at a Fortune "small-num" company) I do have the clout to beat up vendors. If they fuck up then I do get to get details. I currently have around 50 outstanding action items with one vendor. Thursday was shouting at IBM day. However, even my company doesn't really get to shout at the likes of Microsoft, simply because we have no leverage (what we gonna do, turn off 200,000+ desktops?). (personally, yes please... :-))

However, me as an individual customer of linode... I have no such leverage. Being a security professional I note that linode have gone above and beyond the minimal requirements needed by law. They have provided a level of detail that explains the attack vector. They have not provided a "root cause analysis" (who fucked up, and how). And I don't expect one.

I'm dealing with a small company; the risks and consequences of an individual staff member screwing up are that much higher. (I know small technical service companies; I've work for them, run technology for them; my girlfriend used to work for a linode competitor. I know how they can fuck up).

And this is how you should perform your risk analysis; small companies have a risk profile that is pretty consistent. Even it caker said "we've told our staff not to drunk remote into the admin systems using open access points", what have you learned? One potential attack vector might be mitigated, but the rest remain.

Would I like to know how linode was broken into? Sure! I'd love to know! I'd love to know how Global Payments was breached, as well! (They've been less forth-coming than linode have.)

Finally I'll note that linode staff (and caker, personally) monitor or is aware of each and every post made to these forums. That they haven't responded is telling; either they can't, or they won't. If you don't like it then take your money and leave. In the "can't" case, maybe linode will be able to get some recompense for lost income; if it's a "won't" case then this is a business cost they've chosen to take.

Either way, I don't expect any more information from linode. My risk analysis takes this into account.

Quote:
or simply to complain


Ah. Well, OK then. Maybe linode needs a "flame" sub-forum.

_________________
Rgds
Stephen
(Linux user since kernel version 0.11)


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:13 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
sweh wrote:
Thursday was shouting at IBM day.


You have those too, eh? ;)

I am amazed at times how pervasive the "we know better than you, Mr Customer, we're IBM!" attitude can be there.


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:13 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
nehalem wrote:
Quote:
They may be legally unable to say anything


If that's the case then I'd love if they told us that. Hell, if that's not the case, they might as well tell us the same thing anyway, it would get us off their backs.

Either that or just don't say that you intend to communicate openly.

If this was they case then they probably _can't_ reveal this information and may have been advised by lawyers to not say _anything_; anything they do say might be considered prejudicial to the case.

_________________
Rgds

Stephen

(Linux user since kernel version 0.11)


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:16 pm 
Offline
Senior Member

Joined: Fri Jan 20, 2012 11:19 am
Posts: 100
glg wrote:
nehalem wrote:
Quote:
They may be legally unable to say anything


If that's the case then I'd love if they told us that. Hell, if that's not the case, they might as well tell us the same thing anyway, it would get us off their backs.

Either that or just don't say that you intend to communicate openly.


Chicken/egg problem there. If a lawyer advised them to shut up, they lawyer isn't going to tell them to say that.


No, but they'll tell them to say that they can't comment on an ongoing criminal investigation.

_________________
If all else fails, reboot...

PHP Tutorials and MySQL Tutorials


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:19 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
nehalem wrote:
No, but they'll tell them to say that they can't comment on an ongoing criminal investigation.

Which would reveal that there _is_ an ongoing investigation; something that they may have been requested (or ordered; such orders to exist) not to reveal.

_________________
Rgds

Stephen

(Linux user since kernel version 0.11)


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:23 pm 
Offline
Senior Member

Joined: Fri Jan 20, 2012 11:19 am
Posts: 100
sweh wrote:
nehalem wrote:
No, but they'll tell them to say that they can't comment on an ongoing criminal investigation.

Which would reveal that there _is_ an ongoing investigation; something that they may have been requested (or ordered; such orders to exist) not to reveal.


Can they say: "trust us, we just can't tell you anymore"? :)

_________________
If all else fails, reboot...

PHP Tutorials and MySQL Tutorials


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:43 pm 
Offline
Senior Member
User avatar

Joined: Tue Apr 13, 2004 6:54 pm
Posts: 833
nehalem wrote:
Can they say: "trust us, we just can't tell you anymore"? :)

My mind just went through a tonne of confidence tricksters and even the snake from Disney's Jungle Book saying 'Trust me'.... :-)

Either ya do or ya don't. I doubt you're gonna get more information in the near future.

_________________
Rgds

Stephen

(Linux user since kernel version 0.11)


Top
   
 Post subject:
PostPosted: Sun Apr 29, 2012 10:53 pm 
Offline
Senior Member
User avatar

Joined: Sun Dec 27, 2009 11:12 pm
Posts: 1038
Location: Colorado, USA
sednet wrote:
That would that be the same vonskippy who was insulting people asking for ipv6 back when Linode didn't have it but other providers did.

Well, since this thread has long ago jumped the shark, lets discuss IPv6.

Care to share your ginormous IPv6 traffic charts for the last 6 months?

Boy, I can't imagine how you would have survived if Linode took longer then they did to roll it out.

So post away, I can't wait to see those IPv6 traffic numbers.

As to a Linode fanboy (although as VPS hosts go, Linode was in our top 3 list when we vetted vendors) - bwahahahahahahaha - not even close, I'm a huge fan of co-location (in big shiny locked cages with video surveliance and two-factor authentication to get in), and think VPS's are toys to be played with, not host serious work (but YMMV).


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group