Live data from Hacker News

Rely your web startup on Rackspace Cloud? Think again

bencheng.net

11–20 of 83 posts

Re: Rely your web startup on Rackspace Cloud? Think again

#11
post #7

To be fair, a service the size of Rackspace Cloud is bound to screw up at least a few times. Then again, no one ever got fired for switching to Linode.

First of all, what is up with Linode's London datacenter? I barely press enter on commands and they've already been carried out. Seriously, it installs packages before the text from the server reaches me, and I get 15 ms latency on it (the SSH echo feels faster than my local PC).

Is it just me, or are their other datacenters slower than their London one? It might be the latency, as I was actually in London, but the one I have in Georgia doesn't seem to have that fast disk accesses... Bottom line, though, the London datacenter is just time-traveling fast.

Re: Rely your web startup on Rackspace Cloud? Think again

#12
post #8
post #2

I'm thinking Rackspace might well have been in the right on this one. If the customer was in fact phishing, Rackspace was well within their rights to shut down the account. It's really up to the application creator to prevent that abuse. That said, it's good to have a reminder of the risks of outsourcing your hosting. I still think the tradeoff is worth it for experimental products where you don't want to invest too…

Everyone hate spam. I don't object Rackspace to shut down an account that is obviously phishing/spam, but not take down as soon as they think there is an abuse. Grace period must be given, so the the site holder can respond. I don't think it is possible for few-man startup can responds in 1 hours for 24x7. I would choose to use an alternative hosting that give a longer gracing period.

The reality is that each minute the phishing site remains up, another account may get its information stolen. Imagine if you are the person that had your bank account information stolen and drained during the "grace period" for the company to respond to the takedown notice.

This is the kind of thing where a customer who gets their information stolen while Rackspace is waiting for the grace period to expire might have a legal cause of action against Rackspace.

Ultimately, I think Rackspace did exactly the right thing here. If you are operating a service that would potentially allow fishing, then you are bearing the risk of policing your users. Asking Rackspace and affected users to give you a grace period is asking them to bear the risk instead. I 100% agree with the decision to immediately shut the site down.

Re: Rely your web startup on Rackspace Cloud? Think again

#13
What is missing from this article (and comments so far) is a more comprehensive analysis of available options.

If I lease a server from linode or AWS or theplanet or serverbeach or ${your favorite hosting provider}, would the situation be any different? I understand the article's author frustration with Rackspace, but it's a single data point hence hardly enough to be a basis for an intelligent choice of hosting provider.

I'm not even sure if I sympathise with him. You can argue whether 1 hour notice before disabling a server is enough or not but there is an obvious conflict of interest.

The interest of the person hosting server, who can potentially be a phisher himself, is for the site to stay up as long as possible.

The interest of the public is served by terminating the server as quickly as possible.

Re: Rely your web startup on Rackspace Cloud? Think again

#14
post #12
post #8

Earlier quoted context omitted.

Everyone hate spam. I don't object Rackspace to shut down an account that is obviously phishing/spam, but not take down as soon as they think there is an abuse. Grace period must be given, so the the site holder can respond. I don't think it is possible for few-man startup can responds in 1 hours for 24x7. I would choose to use an alternative hosting that give a longer gracing period.

The reality is that each minute the phishing site remains up, another account may get its information stolen. Imagine if you are the person that had your bank account information stolen and drained during the "grace period" for the company to respond to the takedown notice. This is the kind of thing where a customer who gets their information stolen while Rackspace is waiting for the grace period to expire might have…

Do you think that it is reasonable if someone creates a phishing website on heroku, and all servers on heroku got shut down by amazon in an hour?

Re: Rely your web startup on Rackspace Cloud? Think again

#16
this will happen at any responsible web host. If you are hosting phishing sites, expect to get taken down. This trickles up. if you run a hosting company, and you get enough complaints that you don't deal with, then yeah, you will get shut down or asked to leave.

That said, I think especially for higher-priced services, a phone call would be nice. (Note: I don't call my customers, though this is a policy I've considered implementing.) I'd be interested in what other people think about other notification systems.

Re: Rely your web startup on Rackspace Cloud? Think again

#17
I second this. Not a fan of Rackspace.

Some may argue having your own hardware is more expensive to maintain, but there is a definite advantage to controlling your physical hardware.

Rackspace is helpful until you have a real problem, and you are left to fend for yourself.

Re: Rely your web startup on Rackspace Cloud? Think again

#18
post #16

this will happen at any responsible web host. If you are hosting phishing sites, expect to get taken down. This trickles up. if you run a hosting company, and you get enough complaints that you don't deal with, then yeah, you will get shut down or asked to leave. That said, I think especially for higher-priced services, a phone call would be nice. (Note: I don't call my customers, though this is a policy I've conside…

I don't think the issue is that he was hosting an active phishing site. The main issue here is the amount of time he was given to fix the problem was too small. You think Rackspace's upstreams would shut the pipes down if there were a bunch of phishing sites that set up shop? Doubtful. Usually they only get involved when there is a MASSIVE DDoS.

Re: Rely your web startup on Rackspace Cloud? Think again

#19
post #14
post #12

Earlier quoted context omitted.

The reality is that each minute the phishing site remains up, another account may get its information stolen. Imagine if you are the person that had your bank account information stolen and drained during the "grace period" for the company to respond to the takedown notice. This is the kind of thing where a customer who gets their information stolen while Rackspace is waiting for the grace period to expire might have…

Do you think that it is reasonable if someone creates a phishing website on heroku, and all servers on heroku got shut down by amazon in an hour?

If heroku got enough complaints (relative to it's size) they would get shut down or asked to leave. Now, heroku has a lot more than two servers, so it's going to take more than one or two complaints to take them out, and they are probably going to get more than an hour of notice, but if you provide a hosting service, you need to make sure that your users and customers are not using your service to host phishing sites.
Post reply on HN