Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Take a look at this link re: pagerduty and how linode handled things there.

https://news.ycombinator.com/item?id=10845985

Doesn't it seem kind of crazy that folks get full root control plane on linode so frequently?



Hi. This is my comment you keep linking to. Your understanding of what happened is flawed. I do not have signs that Linode was rooted in that compromise. The signals I do have is that they had their database compromised, and likely secret key material. That allowed attackers to crack the hashes offline, and then authenticate using MFA.

IMO, it's plain wrong to categorize that one as "getting full root control plane", where it was instead the compromising of individual accounts that may have had no access to the resources on an account.




Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: