Live data from Hacker News

Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

news.ycombinator.com

21–30 of 81 posts

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#21
post #5

AWS would reimburse this if it was the first time. Maybe some hope for MS to do the same?

I had an incident where a SaaS product went haywire and ran up a $10k bill. I was quite shocked when AWS didn’t write it off and pursued me for the money. You can’t necessarily assume a cloud provider will have your back in these situations.

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#23
post #20

I'm not sure why you would be liable for fraud

To play the devil's advocate, why would Azure be liable for OP's security lapse? This would've been much easier if someone stole your credit card and bought things with it (the CC company would help with the chargeback).

Because it wasn't OP who was hacked? The victim of the crime is Azure, not OP. If I have an Xbox account and someone hacks it and buys a bunch of games, it is the criminal who is deceiving Microsoft into thinking they are someone else. Microsoft trying to charge me for something someone else did would just be a second incidence of fraud. I could leave my Amazon account open on my desk and, assuming I could prove it with security camera footage, someone could walk up and order something and it still would be them defrauding Amazon, not them defrauding me.

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#24
post #19

This is a conundrum. On one hand, I understand how frustrating something like this can be. But on the other hand, your cloud provider did provide those services that you're being billed for. So they did incur costs, why would they just eat those costs? Unless they're somehow at fault by exposing your credentials or making it easier for hackers to log in without 2FA or something of that nature. If you're using a credi…

> why would they just eat those costs?

Beacuse the public indignation directed at cloud companies who don't always eat the costs in these situations vastly outweighs the cost of simply eating these costs, at least for cloud companies at the top tier of economies of scale (AWS, GCP, Azure, etc)

If AWS didn't always eat costs like this, startups might think twice before using AWS, etc, etc.

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#25

Don't pay it. Send them notice, by registered letter, that the charges are fradulent. If a credit card was charged, try to initiate a chargeback/fraud claim. Once you pay it, you lose all leverage. You're much less likely to ever get any money back. Probably consult with a lawyer. Cloud hosting charges are basically all profit for the hosting company. They didn't really lose anything except a bit of electricity. In m…

If your business is dependent on Azure, what happens when they shut down your services for lack of payment? This seems extremely risky.

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#27
post #5

AWS would reimburse this if it was the first time. Maybe some hope for MS to do the same?

I know of one startup that failed due to a bill not being forgiven after they were attacked. There is no guaranteed safety net with cloud costs. This is why it'd be good if you could put a hard limit on your account usage.

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#28

Please setup billing alerts, know what your daily spend should be, add a little for if things grow a little unexpectedly. But you should absolutely be getting alerts if your spend is out of the ordinary for > 2 hours.

Please, demand what you can have a hard limit on spending for the service/account or just a banal pre-pay.

It's amazing what I can have a pre-paid account for a VPS hosting in Nicaragua, yet Amazon doesn't have this as an option.

/rant

Re: Ask HN: One of our Azure accounts was hacked – how to negotiate the bill?

#29
post #15

When that happened to us, we found an article showing Tesla got hacked the same week as us (was aws) and they got the money back, so why not us? We got the money back and fired the guy who had a jenkins opened without password, granting terminal access to anyone.

It's a shame you failed to learn a lesson about how security is something the entire team is responsible for, and how a mistake like deploying something without a password is a failure of your processes rather than a failure of any one person. By firing the guy all you've done is made everyone paranoid which will slow you down; similar mistakes are still just as likely to happen again.
Post reply on HN