Live data from Hacker News

Rely your web startup on Rackspace Cloud? Think again

bencheng.net

21–30 of 83 posts

Re: Rely your web startup on Rackspace Cloud? Think again

#21
What should happen here is this...

When a server is 'shut down' for phishing or spam, a firewall blocks all incoming/outgoing except for traffic to/from a pre-determined IP address along with the notice that the server is being quarantined.

Site owner/admin can then access the server, perform any investigations or deletions necessary, notify data center, then data center opens traffic again.

Alternatively, something like a web-based shell allowing access, but all other traffic denied, would be acceptable.

I've had servers shut down for 'abuse' which was one complaint from someone at 1am local time for me. I supposedly got a call from xxxxxx at 2 am, notifying me that action would be taken, and my server was taken offline at 3am. I wasn't awake until 7am, and couldn't get things resolved until about 10am. I was told I needed to 'rectify the situation', but how can I do that when access to the server is blocked? It's a ridiculous execution of policy, and only serves to heighten everyone's frustration. A private web-shell or single IP in the firewall to allow access would resolve most of the ill-feelings site owners caught in this situation have had.

Re: Rely your web startup on Rackspace Cloud? Think again

#23
post #16

this will happen at any responsible web host. If you are hosting phishing sites, expect to get taken down. This trickles up. if you run a hosting company, and you get enough complaints that you don't deal with, then yeah, you will get shut down or asked to leave. That said, I think especially for higher-priced services, a phone call would be nice. (Note: I don't call my customers, though this is a policy I've conside…

I don't think the issue is that he was hosting an active phishing site. The main issue here is the amount of time he was given to fix the problem was too small. You think Rackspace's upstreams would shut the pipes down if there were a bunch of phishing sites that set up shop? Doubtful. Usually they only get involved when there is a MASSIVE DDoS.

Well, from my experience in industry, big providers of bandwidth do apply pressure (up to and including the threat of disconnect) to large hosting companies in an effort to get them to clean up their act, even when it comes to things like spamming and phishing that are less outright destructive to the network than DDoS activity. You are right that a million dollar customer will get a lot more slack than a twenty dollar user... but, uh, to me that should be expected. Dealing with abuse is very expensive. Some places I've worked that has been the majority of support costs.

Re: Rely your web startup on Rackspace Cloud? Think again

#24
post #8

Earlier quoted context omitted.

Everyone hate spam. I don't object Rackspace to shut down an account that is obviously phishing/spam, but not take down as soon as they think there is an abuse. Grace period must be given, so the the site holder can respond. I don't think it is possible for few-man startup can responds in 1 hours for 24x7. I would choose to use an alternative hosting that give a longer gracing period.

> Grace period must be given, so the the site holder can respond. Unfortunately, during that grace period, numerous people may be receiving spam emails directing them to the site, and some of those people may be naively entering their information ... I really dislike the way most service providers and the like handle spam, but unfortunately, I too must side with Rackspace on this one. They simply can not afford to "w…

It seems like it would be an improvement to either:

1. Keep the very short notification period but also try to reach the site owner via phone or IM

2. Lengthen the notification period if using email only

(Note that I have no problem with short notice and email only if the customer was given the option of providing an emergency contact method but chose not to, and that I otherwise generally agree with the response.)

It seems like the real flaw here is the combination of lack of communication and lack of warning.

Re: Rely your web startup on Rackspace Cloud? Think again

#25
post #20

Rackspace (and others) need to call their clients on the phone in these situations. They feel it is so important that it must be taken care of in one hour, yet they use email. Not exactly fair to the client....

Isn't the rackspace cloud their cut-rate service? would they have called if it was a slicehost (premium price) customer?

Still, I think it is a good idea, and one I ought to implement in my own service. The problem is that we all hate dealing with the phone, but that sounds to me like a lazy answer.

On the other hand, really, if you are an abuse problem, honestly, I don't want you as a customer.

Re: Rely your web startup on Rackspace Cloud? Think again

#26
post #14
post #12

Earlier quoted context omitted.

The reality is that each minute the phishing site remains up, another account may get its information stolen. Imagine if you are the person that had your bank account information stolen and drained during the "grace period" for the company to respond to the takedown notice. This is the kind of thing where a customer who gets their information stolen while Rackspace is waiting for the grace period to expire might have…

Do you think that it is reasonable if someone creates a phishing website on heroku, and all servers on heroku got shut down by amazon in an hour?

No, and that's a strawman argument. That's like asking if it were reasonable for Level 3 to pull the plug on Rackspace if Level 3 got a phishing complaint.

If Amazon got complains about Heroku then I'd certainly expect them to be investigated, and in Heroku's case I'd expect Heroku would take over and shutdown the phishing site.

Re: Rely your web startup on Rackspace Cloud? Think again

#27
post #13

What is missing from this article (and comments so far) is a more comprehensive analysis of available options. If I lease a server from linode or AWS or theplanet or serverbeach or ${your favorite hosting provider}, would the situation be any different? I understand the article's author frustration with Rackspace, but it's a single data point hence hardly enough to be a basis for an intelligent choice of hosting prov…

Your last two lines sum up the problem nicely.

Everywhere, the more you pay, the more effort they will put in to helping you clean up your messes rather than shutting you down right away, which makes sense, because helping you clean up your mess is an expensive business to be in.

Re: Rely your web startup on Rackspace Cloud? Think again

#28
All this talk about how Rackspace should be treating startups make me think, "Why?"

I understand startups may not have the personel to react as fast as a larger company with dedicated personel, and I understand that there might be a very large percentage of startups on Rackspace which might account for a nice chunk of revenue.

But what makes startups different from my personal website or a larger corporation? If Rackspace receives a complaint about a phishing site hosted on their servers, they should do what they can to correct that, regardless of which client is using the server that has the phishing attack. The startup should get the same treatment from Rackspace as the large corporation and the guy with some simple homepage.

Re: Rely your web startup on Rackspace Cloud? Think again

#29

What should happen here is this... When a server is 'shut down' for phishing or spam, a firewall blocks all incoming/outgoing except for traffic to/from a pre-determined IP address along with the notice that the server is being quarantined. Site owner/admin can then access the server, perform any investigations or deletions necessary, notify data center, then data center opens traffic again. Alternatively, something…

My policy is that I shut down the server, I create a fresh server for the user and then I attach the old disk read-only to that server, in case the user needs to retrieve data.

The problem is that there is no way to 'clean up' after a break in without booting from trusted media. Otherwise, there is no way to know if you have closed all the backdoors the attacker left.

Re: Rely your web startup on Rackspace Cloud? Think again

#30
post #5
post #2

I'm thinking Rackspace might well have been in the right on this one. If the customer was in fact phishing, Rackspace was well within their rights to shut down the account. It's really up to the application creator to prevent that abuse. That said, it's good to have a reminder of the risks of outsourcing your hosting. I still think the tradeoff is worth it for experimental products where you don't want to invest too…

I agree. Hosting providers usually reserve the right to shutdown your server if it has been hacked, and phishing is often more directly harmful to people.

Agree. This wasn't a simple DMCA issue-- phishing is an active, criminal activity. Even one hour notice is generous.
Post reply on HN