I've complained about this via their support channels a few different times. They're in the middle of a what seems like a very big security fixing phase right now relating to "something provided by one of their vendors". When I asked about it I was basically told to go away.
They really offer a very good service over all, but their transparency is atrocious.
They actually recently released information about this - there were multiple vulnerabilities in xen.civwould assume they were trying to keep the information quiet until the issue was fully resolved.
If you read the specific vulnerabilities that were released you'd see an embargo was in place. According to Xen.org, Linode is on the predisclosure list. Seems they got the information, fixed the issue, and were able to announce it once the Xen guys did.
Comments
I've complained about this via their support channels a few different times. They're in the middle of a what seems like a very big security fixing phase right now relating to "something provided by one of their vendors". When I asked about it I was basically told to go away.
They really offer a very good service over all, but their transparency is atrocious.
They actually recently released information about this - there were multiple vulnerabilities in xen.civwould assume they were trying to keep the information quiet until the issue was fully resolved.
http://blog.linode.com/2012/06/13/xen-security-advisories-an...
If you read the specific vulnerabilities that were released you'd see an embargo was in place. According to Xen.org, Linode is on the predisclosure list. Seems they got the information, fixed the issue, and were able to announce it once the Xen guys did.