TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Verelox Wiped by Ex-Admin

241 pointsby jonmarkgoalmost 8 years ago

24 comments

tgtweakalmost 8 years ago
This exact thing happened to realitychecknetwork hosting about 6 years ago (now rebranded to serverstack and digitalocean).<p>There was 250+ dedicated servers, 2-3 weeks of restoring week-old backups (thankfully they had these weekly intervals kept offline). Mass exodus of clients.<p>&quot;Ex-employee&quot; used root keys and a boot zerofill drop and rebooted every server resulting in severe data loss. Their online backup systems were also using these keys and we&#x27;re not spared.<p>They said they would have to shut down the company as a result, but ended up securing capital and eventually launching what would become digitalocean.<p>They said it was highly probable that it was an ex employee and that the FBI was investigating buy nothing was released about it.<p>Good cautionary tale for segregation of credentials and proper user key management.
评论 #14527839 未加载
评论 #14528025 未加载
treyfittyalmost 8 years ago
This may be an unpopular opinion, but I want to preface this by saying: &quot;before passing judgement, context is always necessary.&quot;<p>Mario Savio was a Free Speach Activist and organized a protest to protect the Freedom of Speech at Berkeley around the 60s. In his speech to protestors, he says &quot;there&#x27;s a time when the operation of the machine becomes so odious... that you can&#x27;t take part... and you&#x27;ve got to indicate to the people in charge that unless you&#x27;re free, the machine will be prevented from running at all!&quot; Applied to free speech, this notion of disrupting the functioning of an organization was lauded, because freedom of speech is just that important.<p>But let&#x27;s shift to employment. Without employment, it&#x27;s very hard to survive. And here&#x27;s a situation where the people in charge has the upper hand in every arena- hiring, pay, work Place behavior... etc. How do we know that the ex-admin wasn&#x27;t blackmailed by the CEO to come back to work for free to fix something, or future references will be negative? Why are we so quick to side with the employer in this matter when we know nothing of the situation at all? Why do we start calling the employee a felon? He hasn&#x27;t even been charged yet.<p>My point is, context is important. Fine, corporations have the power to ruin your life as a deterrent to keep you from acting against their interests, and that&#x27;s just the way society is. And fine, We&#x27;re not all rational at every instance of life. The calculus of establishing status quo equilibrium of those two conditions&#x2F;constraints is hard, but without context to the situation, who are we to decide who&#x27;s right or wrong? Would you label Mario Savio wrong for protesting and urging protestors to prevent the operation of the college from functioning in the name of preserving Free speech wrong? No, because you&#x27;ve learned the context.
评论 #14526204 未加载
评论 #14526230 未加载
评论 #14526040 未加载
评论 #14526034 未加载
评论 #14534100 未加载
评论 #14526830 未加载
评论 #14526057 未加载
评论 #14525952 未加载
评论 #14526100 未加载
yardiealmost 8 years ago
So in addition to the criminal side of things I guess the ex-admin wants to work in manual labor or fast food. There is no way in hell he&#x27;d have the references or pass the background.<p>BTW, we had a netadmin interview a few months ago. Guy was really smart, aced the technical and group interview. We were really looking forward to hiring him, and only needed to pass a background and reference check. HR told us in no uncertain terms to run the other way. They didn&#x27;t share what was in his check but it wasn&#x27;t good.
评论 #14523775 未加载
评论 #14526274 未加载
评论 #14525912 未加载
评论 #14526211 未加载
评论 #14525463 未加载
评论 #14523732 未加载
评论 #14527675 未加载
评论 #14523906 未加载
评论 #14526248 未加载
评论 #14523713 未加载
评论 #14523903 未加载
preinheimeralmost 8 years ago
Wayback Machine link if you want to know who they were:<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20170603212121&#x2F;https:&#x2F;&#x2F;verelox.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20170603212121&#x2F;https:&#x2F;&#x2F;verelox.c...</a>
评论 #14523274 未加载
评论 #14523712 未加载
评论 #14523862 未加载
pmarreckalmost 8 years ago
This is so stupid. If you have a problem with your employer, either you quit or they fire, you move on, full stop. If you&#x27;re in a relationship and someone isn&#x27;t happy enough with you and breaks up with you, the dignified response is NOT to key their car. I see employment relationships mostly the same way. Either it works (for both) or doesn&#x27;t (for either or both ends).<p>And having switched jobs quite a few times, the next one is always better for you, regardless.
评论 #14525024 未加载
评论 #14524952 未加载
wilhilalmost 8 years ago
Other than treating staff well, how would you go about stopping something like this?<p>As my own company is growing, we fully trust all employees, (limiting only what is essential), but, a dev ops guy if he was so inclined could technically do something like this... It always scares me.
评论 #14524110 未加载
评论 #14523398 未加载
评论 #14523299 未加载
评论 #14523338 未加载
评论 #14524743 未加载
评论 #14523876 未加载
评论 #14524455 未加载
评论 #14525545 未加载
评论 #14523813 未加载
评论 #14524115 未加载
yangthemanalmost 8 years ago
Proper exit procedure should have disabled all access from this ex-admin..., unless s&#x2F;he had some sort of cron job or launched some process that would execute commands at certain time? I am very curious to know how it was done.
评论 #14523404 未加载
评论 #14524762 未加载
评论 #14525758 未加载
评论 #14524207 未加载
评论 #14528383 未加载
评论 #14526053 未加载
评论 #14523406 未加载
stevenhalmost 8 years ago
If I ran a hosting company and all of my servers were compromised by ring -3 malware exploiting the Intel AMT vulnerability, the first thing I&#x27;d do is privately inform Intel that I intend to go public with the story and sue for damages, after which Intel would perhaps offer a very generous bribe for my silence and a week-long window to replace all of the server processors for free, on the one condition that I bury the truth by fabricating a story about an imaginary ex-employee who improbably was both smart enough to gain an administrative position in a large company while also being stupid enough to risk decades in prison for petty revenge over workplace drama.
评论 #14526420 未加载
评论 #14526373 未加载
评论 #14527276 未加载
评论 #14526691 未加载
bobbob1921almost 8 years ago
Lots of comments are interpreting &quot;ex-admin&quot; as someone who was fired and <i>then after</i> went and did this. Just want to float the possibility that &quot;ex-admin&quot; could also mean someone was employed there, <i>then did this</i> and is now no longer employed as a result of doing this.<p>(Btw, IMO there is no excuse or justification for any admin or exadmin to ever do this. Among many other issues is the fact he deleted the data&#x2F;work of individuals who had nothing to do with whatever &quot;problem&quot; he has with Verelox )
评论 #14531975 未加载
tw04almost 8 years ago
It&#x27;s always interesting watching startups learn the lessons that thousands of enterprise learned along the way. &quot;Why would you ever want offline tapes sitting in iron mountain, how inefficient&quot;.<p>Nothing is foolproof, but anytime you&#x27;ve got constant network access to every last copy of your data, you&#x27;re begging to lose it. It&#x27;s the reason why people who think one copy (redundantly dispersed or not) in AWS S3 is sufficient scares me to death. Is it unlikely Amazon would get hacked and have the entire thing blown up? Sure... but if we go to war with China I wouldn&#x27;t want to bet my company on it.
评论 #14529428 未加载
评论 #14528019 未加载
pavementalmost 8 years ago
I would expect to see some kind of police report, and prosecution of an individual charged with a crime, no?
评论 #14523537 未加载
评论 #14523367 未加载
jlduggeralmost 8 years ago
Been waiting for a company to announce shutdown after this was posted: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14476421" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14476421</a><p>Possibly related?
评论 #14524796 未加载
评论 #14523339 未加载
zokieralmost 8 years ago
Wiped by ex-admin, or by the ineptitude of current admins that can&#x27;t maintain proper exit procedure?
评论 #14523734 未加载
评论 #14523399 未加载
评论 #14523835 未加载
评论 #14524493 未加载
评论 #14523396 未加载
jacquesmalmost 8 years ago
This is why you have the backups stored under a different account than the primaries and you make sure that nobody has access to both accounts.
cannonpralmost 8 years ago
A lot of &#x27;managed&#x27; hosting providers are pretty bad with security, there still is a major provider that just gives root credentials to all servers to all techs not just admins, doesn&#x27;t audit who accesses which credentials, and doesn&#x27;t rotate credentials, doesn&#x27;t rate limit dumping credentials... That&#x27;s before we go into more interesting issues with their security. Frankly I am surprised this sort of thing doesn&#x27;t happen more often ? In some ways it both restores some of my faith in people while reducing some of it at the same time in a different vector.
keithpeteralmost 8 years ago
<a href="https:&#x2F;&#x2F;www.lowendtalk.com&#x2F;discussion&#x2F;116329&#x2F;what-s-up-with-verelox-being-down" rel="nofollow">https:&#x2F;&#x2F;www.lowendtalk.com&#x2F;discussion&#x2F;116329&#x2F;what-s-up-with-...</a><p>Some posts from Verelox staff towards bottom third of this forum page search for user name Verelox
CM30almost 8 years ago
This is why a hosting company needs to both segregate credentials to only what an employee needs for their job, as well as to revoke them the minute they leave the company.<p>Otherwise while the vast majority of your staff will be decent people and not cause problems like this, it just takes one angry ex staff member with a grudge to cause problems.<p>They also need to revise their backup system too. There should rarely if ever be a risk that any data is &#x27;unrecoverable&#x27;, yet their update says some data will just be impossible to get back.<p>As for the employee involved... well I hope they like the inevitable lawsuit their selfish, stupid actions will bring them. I don&#x27;t care what you think of a company you worked for, there&#x27;s no excuse to destroy their business through actions like this. Also, good luck getting any jobs in the industry after too. Because with this on your track record, no one will touch you with a ten foot bargepole.<p>So yeah, what a disaster all round.
ceejayozalmost 8 years ago
Yooooowch. They appear to be VPS and dedicated host.
评论 #14523434 未加载
gaiusalmost 8 years ago
Who even knows it was an ex-admin? Could be the current one fat-fingered it and is trying to shift the blame! We just don&#x27;t know.
评论 #14527205 未加载
quicksilver03almost 8 years ago
The thread title should be changed to &quot;Verelox allegedly wiped by ex-admin&quot;: we only know one side of the story.
svakacastalmost 8 years ago
Anyone of us know what is the best way to get refunded? My Company lost 20.000€ for this joke.
评论 #14527266 未加载
antfarmalmost 8 years ago
I wonder whether the ex-admin was already an ex-admin at the time he wiped the servers.
kashifalmost 8 years ago
Use Vault from Hashicorp where possible.
评论 #14523556 未加载
评论 #14523784 未加载
Sir_Substancealmost 8 years ago
Dick move from the ex-admin, but I&#x27;m curious to know what would compel an ex-employee to take such a brazenly criminal and traceable yet damaging action.<p>I&#x27;d like to know more, I think...
评论 #14525759 未加载
评论 #14523316 未加载
评论 #14525117 未加载