Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

91–100 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#91
post #86
post #56

Earlier quoted context omitted.

As a best practice, use a 'normal' name for your S3 bucket and then put Cloudfront in front of your S3 website. This way you are not limited by bucket names and you also avoid any SSL validation errors. Note: you can set Cloudfront's TTL to 0 if you don't need any caching.

This is certainly good practice as long as anyone contemplating this considers the cost implications versus serving from S3 directly.

Good point. It's actually generally cheaper to serve content through Cloudfront instead of S3 directly as bandwidth is less expensive with Cloudfront.

However you are going to pay for Cloudfront requests in addition to S3's. In the vast majority of cases, it's insignificant compared to the savings you can achieve on the bandwidth side. (And at a certain level you can ask AWS to waive CF request fees entirely).

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#92

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

[deleted]

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#93
I made the mistake of applying for a job there once. I was discriminated against. Despite being in a protected class, I was so surprised to be so obviously discriminated against by them. (I've interviewed a lot, I don't always get a follow up, this isn't sour grapes, this was very different.) But of course the HR people are careful to not say things that are overtly discriminatory. But when a company insists on a VIDEO call rather than a phone call (despite asking them to do the first one by phone since I was not in a location with good bandwidth at the time they wanted the call)... and then visibly reacts to your image when they first see it, and then pretty much blows you off, despite being well qualified for the position... yeah, it's not what they say.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#94

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

That's not why his account was closed. His account was closed not for discovering a vulnerability, but for exploiting it.

While his intentions might have been good (and I expect that they were!), that kind of behavior isn't.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#95
post #19

Earlier quoted context omitted.

Do you know of an alternative that can host an instance of FreeBSD?

I'm familiar only with AWS, and it supports FreeBSD.

"Supports" is a strong phrase. Colin Percival creates FreeBSD AMIs. They work mmmmmostly as you might expect, except there's no cloud-init (instead it uses a gizmo that cperciva wrote), but AWS doesn't support it--that's a community thing.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#96
post #79
post #41

Earlier quoted context omitted.

Same here. Please stay away from Linode. They used to be good. Now they are unprofessional and unethical.

I'm a new Linode user (as of this week) and have been happy so far. What are these problems you talk about? I'd like to know before I commit further.

There have been several critical issues. Search for 'linode hacked' on hn.algolia.com and see for yourself.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#97
post #6

This doesn't help my impression of Digital Ocean at all (even if I am a paying customer currently). A few years ago you could impersonate Digital Ocean staff on their support pages with no effort. They grabbed the username from your email, so whatever you put in front of the @ becamse your username on the forums, visible to everyone. And the avatar came from one of those email->avatar services where you can sign up a…

And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change.

I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it)

DO is one of the shadiest hosters I know.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#99

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services.

The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#100
post #94

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

That's not why his account was closed. His account was closed not for discovering a vulnerability, but for exploiting it . While his intentions might have been good (and I expect that they were!), that kind of behavior isn't.

He did not exploit it, he just provided proof. He did not make any money from the traffic and visitors just saw a white page.
Post reply on HN