From what HTP said on IRC, the credit card numbers were decrypted within the application context, which would be consistent with what you said. But during the IRC conversation, HTP willingly gave out the last four digits of people's CC#s, but ignored any request for digits before that, which would be more consistent with what Linode is stating.
It's all a very confusing world where nobody has a definite answer. Just 2 cents, don't act like I'm sharing a fact or anything
There's no inconsistency. Linode said "Credit card numbers in our database are stored in encrypted format... Along with the encrypted credit card, the last four digits are stored in clear text..."
It's all a very confusing world where nobody has a definite answer. Just 2 cents, don't act like I'm sharing a fact or anything