Live data from Hacker News

Taking Over DigitalOcean Domains via a Lax Domain Import System

thehackerblog.com

151–160 of 186 posts

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#151
post #97

Earlier quoted context omitted.

And the ban reminds me of the recent case, where DO invalidated the credits of many people within of 2 weeks with a simple TOS change. I had to pay 5€ to even be able to add the 100$ credit from the GitHub students pack to my account (for "verification purposes"), and then they – illegally – delete it just like that? (I never got to use any of it) DO is one of the shadiest hosters I know.

On one hand, the policy change was made a year prior. On the other hand, we didn't communicate it as well as we should have. I apologize for that. I consider myself as much responsible as anyone else on that. If you ever want that account credit back, please let me know. I'm an easy find on Google, or you can open a support ticket anytime. For what it's worth, we posted on our blog about just this. https://www.digita…

"Was made a year prior", that’s wrong.

I got the ToS change notification, and merely 2 weeks later my credit was invalidated.

I had had the credit on my account for over 2 years by that time, but hadn’t used it.

And I had opened a support ticket, and was advised to take legal action if I believed it was invalid or wanted it back.

No thanks, I’ve had enough.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#152

Earlier quoted context omitted.

On one hand, the policy change was made a year prior. On the other hand, we didn't communicate it as well as we should have. I apologize for that. I consider myself as much responsible as anyone else on that. If you ever want that account credit back, please let me know. I'm an easy find on Google, or you can open a support ticket anytime. For what it's worth, we posted on our blog about just this. https://www.digita…

I was affected by this - I lost some credit that I had remaining from the Github Student Pack due to it expiring with relatively short notice. If I open a support ticket, will I be able to ask to get that credit back?

Absolutely, please ask for me if you run into any trouble. You should not have any problem.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#153

Earlier quoted context omitted.

On one hand, the policy change was made a year prior. On the other hand, we didn't communicate it as well as we should have. I apologize for that. I consider myself as much responsible as anyone else on that. If you ever want that account credit back, please let me know. I'm an easy find on Google, or you can open a support ticket anytime. For what it's worth, we posted on our blog about just this. https://www.digita…

"Was made a year prior", that’s wrong. I got the ToS change notification, and merely 2 weeks later my credit was invalidated. I had had the credit on my account for over 2 years by that time, but hadn’t used it. And I had opened a support ticket, and was advised to take legal action if I believed it was invalid or wanted it back. No thanks, I’ve had enough.

The change was made a year prior. It was not communicated via email. That email you received was a reminder. We only put up a notification in the control panel. That was the communication failure, and I apologize for it.

At no point should anyone be advising you to take legal action to retain your credit, and I would be grateful for the opportunity to review the ticket in question.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#154

Earlier quoted context omitted.

"Was made a year prior", that’s wrong. I got the ToS change notification, and merely 2 weeks later my credit was invalidated. I had had the credit on my account for over 2 years by that time, but hadn’t used it. And I had opened a support ticket, and was advised to take legal action if I believed it was invalid or wanted it back. No thanks, I’ve had enough.

The change was made a year prior. It was not communicated via email. That email you received was a reminder. We only put up a notification in the control panel. That was the communication failure, and I apologize for it. At no point should anyone be advising you to take legal action to retain your credit, and I would be grateful for the opportunity to review the ticket in question.

> The change was made a year prior.

Why did I not receive any notification? A change in contract of that magnitude should have led to me being directly notified per email or other communication methods, so that I’d actually have a chance at still using the credit.

This way, you notified me right when the credit ran out, which was extremely shady, and I’ve met hundreds of others with the same issue in IRC when you invalidated it.

I can’t and won’t be able to assist you with an investigation to improve your public image, though, as I’m quite busy at the moment, and my time is better spent contributing to open source projects than discussing the wrongs of a hoster that won’t change anyway on HN.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#155

Earlier quoted context omitted.

"Was made a year prior", that’s wrong. I got the ToS change notification, and merely 2 weeks later my credit was invalidated. I had had the credit on my account for over 2 years by that time, but hadn’t used it. And I had opened a support ticket, and was advised to take legal action if I believed it was invalid or wanted it back. No thanks, I’ve had enough.

The change was made a year prior. It was not communicated via email. That email you received was a reminder. We only put up a notification in the control panel. That was the communication failure, and I apologize for it. At no point should anyone be advising you to take legal action to retain your credit, and I would be grateful for the opportunity to review the ticket in question.

> Why did I not receive any notification? A change in contract of that magnitude should have led to me being directly notified per email or other communication methods, so that I’d actually have a chance at still using the credit.

I agree with you completely. That is precisely why I refer to it as a communication failure. I had a year to ask "Why didn't we email about this?" I didn't ask that question. I failed. I'm sorry.

I understand that you're not interested in helping, but my offer stands, and I appreciate you and your feedback. We're all just people here trying to do what we think is right. I know I fall short, I make mistakes, but all I want is to own them and make them right.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#156

Bye bye digitalocean - account deletion request submitted 1178917. When you have reckless people like Cashan Stine (trust & safety specialist - WTF is that title? sounds like a road safety officer?) that close accounts due to a security report then it won't win any business from me or my clients.

I've reported multiple vulnerabilities to DigitalOcean before and they've fixed them rapidly, credited me for the effort, and gave me free time on their services. The difference is I didn't exploit 20 thousand domains to make flashy headlines and prove a point about something that isn't even a serious bug.

Mmmmm, smell that plastic grass.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#157
post #41

Earlier quoted context omitted.

Linode has had _far_ larger issues than DO ever has. That's why I switched to DO in the first place.

Same here. Please stay away from Linode. They used to be good. Now they are unprofessional and unethical.

Strange, I've tried several over the years and Linode is still the best in their price range.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#158

Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.

No one remembers how Linode tried to cover up getting hacked?

I never noticed anything like that.

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#159

Great article! I'm saddened by DO's response and further wronging a white hat by banning you. Let's remember Linode offers 2x the RAM.

Linode has an awful track record for security.

Been there for several years, no incidents, their support is fast and they are smart, odd huh?

Re: Taking Over DigitalOcean Domains via a Lax Domain Import System

#160
post #90

Earlier quoted context omitted.

Cloudflare does something similar to AWS. Each user gets different nameservers

Is that true? The nameserver I was given by CloudFlare is "nelly.ns.cloudflare.com". From some cursory searches, it seems like a large number of domains have that same nameserver. AWS nameserver hostnames have all kinds of numbers in them that seem a lot more like they're generated per user.

While you can generate unique hostnames of name servers per user you can't assign all of them unique IP addresses (at least in IPv4) as dns resolving doesn't have anything like vhosts (why should it?). So there will be overlap. Which is not a problem as long as the set of name servers for one users doesn't overlap the set of name servers for another user for a single domain.

So you confirm that a set of name server belongs to a user by verifying that its domain record has those name servers configured. You then don't allow another user to control the same name servers for that domain as long as the domain record still points to them. New users can then freely create new name servers but the domain still uses the servers assigned to by the domain owner.

What DO does is that it allows any user to control the name server for a domain if the previous owner gives up control of them. It should only do that, once the domain records start pointing anywhere else.

Post reply on HN