I've now heard from a number of people using Linode that have suspicious activities on the cc which they used with Linode.
I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions.
Linode customer support keeps saying they have "no comment" on this issue (which I suppose does make sense -- I'm assuming they've been ordered by law enforcement persons to not share details), so as we're not being given much information to work with... just treat this as a worst-case scenario (all names, addresses, credit card numbers, etc. have been compromised). Do operate now with the assumption that all of this data has been compromised and may very well be public soon.
It depends on how sophisticated the identify theft is. I had a good friend who was taken for about $9000 in credit card fraud in 1998/1999, with Well Fargo. It took him the better part of six months, and endless correspondence with WF to prove all of the purchases were not his. There are lots of stories of people who were financially wiped out, to the point of bankruptcy, because of Credit Card/Identify fraud.
With that said - almost everyone seems to feel comfortable handing out their credit card to random taxi drivers, waiters, sales staff - with no idea whether a copy of their information is being taken down. Heck - if you give them the Credit Card, they even get your CCV as well.
That makes me wonder why the credit card system is so insecure in the first place. Why are credit card systems not secured with a password that the merchant never gets to see? Yet at the same time credit card suppliers keep bragging about how "secure" their cards are.
Funny that you mention that. After a few bouts with fraud (because as i mention I have my CC out to many services), I was wanting a way to track down the offending service.. I was thinking something along the lines of a vendor-specific set of numbers to be run through.
I even wrote a blog post about it. I probably don't know what I'm talking about, but these were my thoughts at the time:
Wishlist – A Method to Pre-Approve and Track Credit Card Transactions
The issue:
A business using a credit card doing business with a relatively small number of vendors wanting to first avoid credit card fraud (stolen numbers) and secondly wanting to easily track down the offending business.
The idea:
The business would like to approve particular vendors to use the credit card with number 0000-0000-0000-0000 with each individual business pre-approved to run the transaction with a 5th set of identifiable numbers, so something like 0000-0000-0000-0000-0001.
If the credit card is used to make a fraudulent transaction, then ideally, they would have had to have used the 5th set of identifying numbers. This 5th set of identifiable numbers would then allow for easy tracking of the offending vendor, which would allow the business to either re-think doing business with them, or to serve as a starting point discuss security issues with the vendor’s credit card transaction processes.
Summary:
Basically, I believe there may be a need for a new or value added credit card type service. This transaction type would require a 5th set of numbers which have been assigned to pre-approved vendors. This 5 number set (ie. 0000-0000-0000-0000-0002) credit card transaction would most likely prevent theft right off (because the vendor is pre-approved and should provide their own private key (ie. CCV) to put through the transaction). Secondly, if and when the credit card number is stolen and used to make a fraudulent purchase, then, at least with the 5th number set a vendor can be identified and security policy with them can be re-evaluated.
> Why are credit card systems not secured with a password that the merchant never gets to see?
My bank in Sweden requires MasterCard SecureCode for all online transactions on their debit cards. Stores that don't support it simply won't work with the card.
So, it's up to the bank how secure they want it to be. The technology is there.
I've had roughly the same experience: in the last 8 years, I've had suspicious activity on my CC about 5 times. Each time, the bank caught and trapped it before I noticed and issued me a new card quickly. I've only had to fill out paperwork for a disputed charge once, and it was a 2-page, 2 question, sign-and-mail-it-in deal.
My advice is different, though. I notice that I tend to get lucky in places where people can have very aggravating experiences. I'd say that if you've had problems before, then anticipate problems this time around too. If you haven't, then don't bother.
Wow, four times? You should probably be more careful about who you give your number to. Personally, I usually get a new card every 3-5 months. If someone ever sat on my card number, it's useless to them now. Never had any issues either.
@kansface It's not bad for your credit rating. A number is simply a representation of the account. The account doesn't change. It's not like getting a whole new item of credit issued. Just the means to access it.
Also, great idea. But a pain, because most of my bills - cell, internet, insurance(s), etc all go through my credit cards. Is a gigantic pain to change the numbers.
I can be in some cases. I got mugged and my card was used to pay for parking garages for 1.5 years until it expired even though it was canceled and blocked by the issuing bank. They said that for some transactions, the blocking mechanisms are so expensive its more economically sane to them to refund whatever was drawn.
I also do that, but it's because I'm scared of recurring subscriptions that I've forgotten about, especially those that decide to sneak into my pocket after I've deliberately canceled them.
He's not tearing down and setting back up the entire credit line, just the card number associated with it. It won't be reflected on any credit reports.
I would be utterly shocked if nobody using Linode had suspicious activity on their CC. Linode has lots of customers, and at any given time, some of them probably have suspicious activity going on.
There's baseless speculation and then there's I have some information speculation. I'm operating on heuristics which rely on information that is handily available. Yes, in the end you're right, I'm just speculating. But hey, it's better to err on the side of caution.
Credit card numbers are of pretty low value. Like way less than a buck in medium volume and still just a few bucks for the super premium ones. And there is way, way more inventory of them than interested buyers. The likelyhood of a coordinated break in of a large hosting service with the intention of stealing credit cards is pretty low, and the chance that they'd be exploited so quickly is even lower.
Unless the attacker dumped them all (semi) publicly, the more likely explanation is that the breakin caused people to check their accounts and a statistically normal percentage of them showed fraud from another origin. But anybody who sees it will be sure to get online and find others in a similar situation.
Everybody would be doing themselves a big favor if they stopped treating CC info as the #1 scary OMG data theft. The banks programmed you to care because congress made sure they're liable instead of you. Theoretically you might owe $50 due to fraud but practically you never pay a dime. Sure it's a bit of a pain in the ass to get resolved, but it's not worth stressing about until it happens.
I'd be way more concerned if my hoster lost my contact info, ip logs and identity challenge questions & answers.
I contacted Linode support and they've said in clear terms that they have no evidence that payment information of customers was accessed. I initially signed up for Linode because my friends spoke highly of the tech people working at Linode. Right now amidst all the commotions it's ryan's words (some anonymous dude who joined #linode/irc.oftc.net) vs. an established company's. I'm just going to now stop worrying and get back to my work.
If it is indeed true that credit card numbers were compromised, it would behove Linode to tell their customers quickly so they can take the proper action.
With this lack of transparency, I feel like I had no choice but to block my card.
There's no lack of transparency here. Linode expressly said in their blog post that no CC details were leaked.
> In addition, we have found no evidence that payment information of any customer was accessed.
The question isn't transparency, but trustworthiness. Either Linode is telling the truth, and this anonymous IRC person with a pastebin is trolling everyone, or Linode is lying (or alternatively, Linode is incompetent and simply didn't detect the CC access). At the moment I'm going with Linode is telling the truth, because honestly, am I going to believe an anonymous person on IRC over a company I do business with?
I'm thinking here why Linode holds CC data on its servers in the first place. Anyone care to weight in here?
Secondly, if they hold that data, it's possible one day someone will find a security breach and will access that data. The best solution is to never hold that data.
Since I don't trust most of the systems I use AND Linode has not denied it holds that data... I'm more inclined to believe in this anonymous IRC guy and err on the side of caution.
If Linode had come out and said "Look, we don't hold your CC number in our database" then I think there would be very little reason to be concerned. However...
No weird activities on mine either but I will give a call to my CC company anyway. I have had to cancel the card I use on linode twice in the past few months because of suspicious activities. I just didn't think it would be coming from Linode
I asked about the security measures and they answered with:
"We appreciate the response, and we can assure you that we have implemented all appropriate measures to provide the maximum amount of protection to our customers."
Yeah I did the same thing, but new card takes 5-7 days in my case. Very disappointed that I had to find out about this incident here, imagine all the customers who dont happen to look on slashdot or hacker news.
If it's a debit card that can be used as a credit card (and it must be, otherwise it couldn't have been used to pay for Linode), then it enjoys the same protection as regular credit cards when it's used as one.
Very true. If your bank gives you a separate savings account you can transfer the bulk of your money there and just use the card from the current account to limit your exposure.
What about for people who did not use a credit card to pay for linode but instead relied on PayPal. Should they follow the same steps? What about other cautious steps?
I've got a PayPal business mastercard which is connected to PayPal Smart Connect. They may not allow PayPal proper but you could pay using PayPal by way of their card. I use my PayPal card hooked into Smart Connect for a good number of recurring payments like this.
So I guess the answer would be, if you ended up hooking your PayPal account up to Linode in the way I described, yeah follow the same steps as other cards, otherwise it's not even possible to have a problem.
I just called up my bank to tell them to 'block' it as a precaution (I will now have to give them a visit later today to get a new card). I encourage all other Linode customers to do the same, because it'll be easier to just spend half an hour doing this instead of spending hours upon hours disputing specific transactions.
Linode customer support keeps saying they have "no comment" on this issue (which I suppose does make sense -- I'm assuming they've been ordered by law enforcement persons to not share details), so as we're not being given much information to work with... just treat this as a worst-case scenario (all names, addresses, credit card numbers, etc. have been compromised). Do operate now with the assumption that all of this data has been compromised and may very well be public soon.