Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I’m really struggling to see how “the company’s response to security breaches was inappropriate” logically leads to “staff might be stealing Bitcoin.”

It’s a baseless and unfair attack and I think you should consider deleting your original comment.



When you're in Linode's position, running people's private and infrastructure, you have a very finite amount of grace. Individual employees at linode had an incentive to violate the company's security. When security violations happened that could plausibly have come from employees following their incentives the company consistently failed to assure customers it was making sure the security issues were being addressed. In my opinion this at least shows a wild disregard the well-being of customers and I think it's pretty normal to treat that kind of wild-disregard as malicious (even though it may not be).


Linode would sit on reports for months or not investigate root control plane hacks.

https://wptavern.com/wp-engine-identifies-cloud-infrastructu...

This followed the pagerduty hack. We don't know who else was getting hacked either - these were to high profile ones.

So this just raised the question - what's up that they don't take serious issues seriously? With bitcoin there have been a ton of insider issues with how "trusted" infrastructure providers and exchanges handling bitcoin so that was the question.

Even if external hackers, they just got hacked over and over.


If the known facts are consistent with your staff stealing Bitcoin and the reason it can't be confirmed whether or not this happened is because your staff fell short of industry-standard security practices, I think it's entirely fair to say that that might be what happened. Put it this way: from the perspective of someone on the outside, if your staff were stealing Bitcoin this is exactly what it would look like.


I wouldn't say it "logically leads to", but it does seem to be a fair question to ask.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: