Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Wed Sep 11, 2013 10:51 am 
Offline
Junior Member
User avatar

Joined: Wed Sep 11, 2013 10:45 am
Posts: 28
Website: http://www.fierydragonlord.com
I'd like to see a list of recent login attempts (whether successful or failed) into the Linode Manager under my username, so that I can tell whether someone has attempted to gain unauthorized access to it. Yahoo! and Google provide this feature, so it would be great if Linode would implement it as well.

_________________
House of DragonLord, powered by openSUSE


Top
   
PostPosted: Thu Sep 12, 2013 12:33 pm 
Offline
Junior Member
User avatar

Joined: Mon Jun 20, 2011 8:54 am
Posts: 44
The only downside of that I can think of offhand is if the Manager page gets hammered with login attempts, your list may suddenly bloom oneday! :lol:

But I'm sure Linode has protection for that, so I would agree that it would be a good feature that should take a minimum of effort to integrate. </2cents>


Top
   
PostPosted: Fri Sep 13, 2013 3:14 am 
Offline
Senior Member

Joined: Sun Apr 26, 2009 3:37 am
Posts: 72
Website: http://wiggenhorn.org/
If you turn on IP whitelisting, you get an email whenever a user from an unknown IP tries to log in to your account.


Top
   
PostPosted: Fri Sep 13, 2013 9:23 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
dcraig wrote:
If you turn on IP whitelisting, you get an email whenever a user from an unknown IP tries to log in to your account.


That's only after a successful login though, right?


Top
   
PostPosted: Fri Sep 13, 2013 9:45 pm 
Offline
Senior Member

Joined: Sun Apr 26, 2009 3:37 am
Posts: 72
Website: http://wiggenhorn.org/
glg wrote:
That's only after a successful login though, right?


In this case, the log in attempt is not successful because the IP is not on the whitelist.

If the log in is successful because the IP has been added to the whitelist, no email is sent.


Top
   
PostPosted: Fri Sep 13, 2013 10:01 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
dcraig wrote:
glg wrote:
That's only after a successful login though, right?


In this case, the log in attempt is not successful because the IP is not on the whitelist.

If the log in is successful because the IP has been added to the whitelist, no email is sent.


No, I meant the email is only sent if the correct user/password are entered, but IP is not on whitelist, right?


Top
   
PostPosted: Fri Sep 13, 2013 10:38 pm 
Offline
Senior Member

Joined: Sun Apr 26, 2009 3:37 am
Posts: 72
Website: http://wiggenhorn.org/
glg wrote:
No, I meant the email is only sent if the correct user/password are entered, but IP is not on whitelist, right?


Oh, I understand now... Yes, that's correct.


Top
   
PostPosted: Sat Sep 14, 2013 12:20 pm 
Offline
Junior Member
User avatar

Joined: Wed Sep 11, 2013 10:45 am
Posts: 28
Website: http://www.fierydragonlord.com
I don't use IP whitelisting because I don't have static IP addresses, and I would end up having to whitelist a whole bunch of IPs that would only be used temporarily. I do use two-factor authentication with Google Authenticator, though.

While this requires manual review, a list of recent login attempts (with geolocation for the IPs) is more useful that an IP whitelist for people with dynamic IP addresses.

--DragonLord

_________________
House of DragonLord, powered by openSUSE


Top
   
PostPosted: Sat Sep 14, 2013 1:56 pm 
Offline
Junior Member

Joined: Sun Jun 24, 2012 4:27 pm
Posts: 29
Out of interest, how useful would this be? What would you do with this information?


Top
   
PostPosted: Sat Sep 14, 2013 2:05 pm 
Offline
Junior Member
User avatar

Joined: Wed Sep 11, 2013 10:45 am
Posts: 28
Website: http://www.fierydragonlord.com
This information can be used to detect unauthorized login attempts. Yahoo! already provides this kind of information.

--DragonLord

_________________
House of DragonLord, powered by openSUSE


Top
   
PostPosted: Sat Sep 14, 2013 2:11 pm 
Offline
Junior Member

Joined: Sun Jun 24, 2012 4:27 pm
Posts: 29
Ok, so you learn that someone has been trying to get into your account, and you have a list of a few IPs, and the number of failures per IP. What would you do with that?


Top
   
PostPosted: Sun Sep 15, 2013 12:07 am 
Offline
Junior Member
User avatar

Joined: Wed Sep 11, 2013 10:45 am
Posts: 28
Website: http://www.fierydragonlord.com
Well, you can change your password or take other action to secure the account.

--DragonLord

_________________
House of DragonLord, powered by openSUSE


Top
   
PostPosted: Sun Sep 15, 2013 4:18 am 
Offline
Senior Member

Joined: Sun Apr 26, 2009 3:37 am
Posts: 72
Website: http://wiggenhorn.org/
How would changing your password make the account more secure? If the attacker had the (old) password, he'd be in already.


Top
   
PostPosted: Sun Sep 15, 2013 5:18 am 
Offline
Junior Member

Joined: Tue Jan 31, 2012 6:17 am
Posts: 42
Website: https://www.serverfruit.com/
Location: Denmark
fierydragonlord wrote:
I don't use IP whitelisting because I don't have static IP addresses, and I would end up having to whitelist a whole bunch of IPs that would only be used temporarily. I do use two-factor authentication with Google Authenticator, though.

While this requires manual review, a list of recent login attempts (with geolocation for the IPs) is more useful that an IP whitelist for people with dynamic IP addresses.

--DragonLord

So? I use whitelisting and Google Authenticator (well, with Authy). And I tend to log in from various places depending on where I am. Is it hassle? Yes!

But security should be a hassle. Like I have a Yubikey - I never let it sit in my computer - I use it and take it back out.

To be frank, if it was all easy, and no hassle with security, I wouldn't trust the security. When you have to check your email for 20th time that day to get your current IP whitelisted or when you have to reach out for your phone to get the Google Authenticator code for the 25th time that day, that's when you start having decent security.

_________________
lakridserne
Serverfruit - shared and managed VPS hosting, SSL certificates and domains
Awesome servers rented from Linode!


Top
   
PostPosted: Fri Sep 27, 2013 12:59 am 
Offline
Senior Member
User avatar

Joined: Wed Jun 26, 2013 1:53 am
Posts: 118
glg wrote:
dcraig wrote:
If you turn on IP whitelisting, you get an email whenever a user from an unknown IP tries to log in to your account.


That's only after a successful login though, right?


Any time there's a login attempt, an email is sent. This is because you use that email to authorize the IP address that tried to log in, if it fact it was yours.

_________________
Homepage www.sturmkrieg.com
Social network Gamernet
Development website Sashaweb Development
Imageboard img.sturmkrieg.com
WikiHub free wiki host Community Wiki


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 1 guest


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group