Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Outside of the standard SSD drives, DO has not had any major data breaches that I'm aware of. That's a pretty big one. At this point recommending Linode to a company I work for seems borderline negligent considering their security history.


DO had the issue where you could delete a droplet without scrubbing the disk. So the next person to create in that area could read the disk and recover any data from it.


To me that doesn't seem comparable to clear text passwords being stolen at all.


And recent events make recommending to use TLS and OpenSSL seem borderline negligent too, considering their security history, right?


That's a slippery slope. By that logic no company can be critiqued for security failures. Linode was storing their shell passwords in clear text. To me that's where I draw the line.

On the other hand, if there were good alternatives to OpenSSL the community probably would be talking about considering them right now.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: