I'm still amazed how quick people are to forget what happened with Linode.
Massive security issue (i.e. Bitcoin incident) where hackers got root access to any Linode VPS at the click of a button. Loyal customers were the last to hear about it (through their website no less) and absolutely no proper explanation was or has been given as to what happened, what was done about it and whether it will happen again.
You look at how Cloudflare handled their issue and it's night and day. Linode are one of the least transparent providers going around IMHO.
I've complained about this via their support channels a few different times. They're in the middle of a what seems like a very big security fixing phase right now relating to "something provided by one of their vendors". When I asked about it I was basically told to go away.
They really offer a very good service over all, but their transparency is atrocious.
They actually recently released information about this - there were multiple vulnerabilities in xen.civwould assume they were trying to keep the information quiet until the issue was fully resolved.
If you read the specific vulnerabilities that were released you'd see an embargo was in place. According to Xen.org, Linode is on the predisclosure list. Seems they got the information, fixed the issue, and were able to announce it once the Xen guys did.
I forgot just how opaque linodes acknowledgement of the issue was. Basicly just a head nod saying "yes, there was an issue." with no follow up or anything. Makes me really appreciate the heroku outage post. Makes me kind of sad to realize just what we'll put up with when things are out of sight. An issue analogous to this at a normal colo would be a HUGE deal.
I always thought highly of linode and their service, been using them for production and recommending others to do so.
And then the bitcoin incident happened, after that they just can't be trusted with any client data.
3 weeks ago, backups stopped for no obvious reason, I noticed after a few days and raised a ticket.
It was escalated to the "backup team"; who've proceeded to achieve nothing in almost 2 weeks towards fixing my backup issue. "They're working on it" does not inspire me with any hope.
So now I can't trust the backups, the support team, or really any part of the platform to perform as advertised or be fixed in a reasonable timeframe if it fails.
I'm a Linode customer. More than year (14 months) without any problem, super support, good documentation and friendly community - it's MUCH more important than one hack incident.
Comments
I'm still amazed how quick people are to forget what happened with Linode.
Massive security issue (i.e. Bitcoin incident) where hackers got root access to any Linode VPS at the click of a button. Loyal customers were the last to hear about it (through their website no less) and absolutely no proper explanation was or has been given as to what happened, what was done about it and whether it will happen again.
You look at how Cloudflare handled their issue and it's night and day. Linode are one of the least transparent providers going around IMHO.
> Loyal customers were the last to hear about it
I'm a Linode customer, your message is the first time I've heard anything about it.
I'm considering linode for my next launch, and heard nothing of this as well. Thanks?
Ditto, I've been using Linode for over a year and haven't heard of this.
I've complained about this via their support channels a few different times. They're in the middle of a what seems like a very big security fixing phase right now relating to "something provided by one of their vendors". When I asked about it I was basically told to go away.
They really offer a very good service over all, but their transparency is atrocious.
They actually recently released information about this - there were multiple vulnerabilities in xen.civwould assume they were trying to keep the information quiet until the issue was fully resolved.
http://blog.linode.com/2012/06/13/xen-security-advisories-an...
If you read the specific vulnerabilities that were released you'd see an embargo was in place. According to Xen.org, Linode is on the predisclosure list. Seems they got the information, fixed the issue, and were able to announce it once the Xen guys did.
If anyone else is like me and wondering what he's talking about, here's a description from one of the victims:
http://bitcoinmedia.com/compromised-linode-coins-stolen-from...
I forgot just how opaque linodes acknowledgement of the issue was. Basicly just a head nod saying "yes, there was an issue." with no follow up or anything. Makes me really appreciate the heroku outage post. Makes me kind of sad to realize just what we'll put up with when things are out of sight. An issue analogous to this at a normal colo would be a HUGE deal.
s/heroku/cloudflare
I always thought highly of linode and their service, been using them for production and recommending others to do so. And then the bitcoin incident happened, after that they just can't be trusted with any client data.
I have an entry level Linode with backup service.
3 weeks ago, backups stopped for no obvious reason, I noticed after a few days and raised a ticket.
It was escalated to the "backup team"; who've proceeded to achieve nothing in almost 2 weeks towards fixing my backup issue. "They're working on it" does not inspire me with any hope.
So now I can't trust the backups, the support team, or really any part of the platform to perform as advertised or be fixed in a reasonable timeframe if it fails.
My single data-point.
I've been a customer of theirs for a couple years and have only learned about this now?! I've always thought highly of Linode otherwise.
I'm a Linode customer. More than year (14 months) without any problem, super support, good documentation and friendly community - it's MUCH more important than one hack incident.