Live data from Hacker News

Rely your web startup on Rackspace Cloud? Think again

bencheng.net

41–50 of 83 posts

Re: Rely your web startup on Rackspace Cloud? Think again

#41
post #6

@matrix, I think overall direction is correct, Rackspace should try their best to notify their customer if they received complaints. However the ridiculous point of this case is totally shutting down all servers of a startup in just 1 hour, which is really horrible. Instead I believe they should at least give 12 - 24 hours for a startup to react and investigate before taking down all their services? Is that really on…

> they should at least give 12 - 24 hours for > a startup to react and investigate

By which time the phisher has already done the damage and moved on.

Re: Rely your web startup on Rackspace Cloud? Think again

#42
post #34

How was this construed as "phishing"? Did the customer simply set up a form that asks for a user's email address? because if so that describes tons of other services out there... e.g. Wufoo, Google Documents (but I guess they are not hosted on Rackspace!)

FYI, my phishing form @wufoo: http://rickmak.wufoo.com/forms/phishing/ Look professional? ;) Similar form on pandaform will make pandaform shutdown entirely.

it looks like it got taken down. what was it?

Re: Rely your web startup on Rackspace Cloud? Think again

#43
imo the biggest mistake here was in PandaForm trusting all of its user-generated content.

It seems like they should have been doing some sort of verification of the UGC. Alternately, if they really wanted to go with a fully laissez-faire no-security-checks approach, they shouldn't have picked a hosting company (in this case, Rackspace) that requires customers to sign an agreement that has strict anti-phishing rules.

Re: Rely your web startup on Rackspace Cloud? Think again

#44
post #26

Earlier quoted context omitted.

No, and that's a strawman argument. That's like asking if it were reasonable for Level 3 to pull the plug on Rackspace if Level 3 got a phishing complaint. If Amazon got complains about Heroku then I'd certainly expect them to be investigated, and in Heroku's case I'd expect Heroku would take over and shutdown the phishing site.

I think everyone agreed on that the service provide have to investigate and take action on any abuse claim. But what is questioning now is that is it reasonable to shutdown a suspect case of abuse without giving time for the service provider to investigate and respond to this case?

is it reasonable to shutdown a suspect case of abuse without giving time for the service provider to investigate and respond to this case?

Yes, if there are enough complaints and harm that may come from it is serious enough.

Re: Rely your web startup on Rackspace Cloud? Think again

#45
post #28

All this talk about how Rackspace should be treating startups make me think, "Why?" I understand startups may not have the personel to react as fast as a larger company with dedicated personel, and I understand that there might be a very large percentage of startups on Rackspace which might account for a nice chunk of revenue. But what makes startups different from my personal website or a larger corporation? If Rack…

It is like asking why we need special facilities in building for the disables. Why didn't we treat everybody the same and don't provide any special facilities for disable? I do think that site owner of any scale IS responsible to abuse complains, but the scale of the company do make a different. The influence and harmfulness of a fake shop in Amazon is not same as a fake shop in a very-small-online-shop. Thus people…

Rackspace shutting down your site might have done you a favor.

If they hadn't it's possible law enforcement could have gotten involved, you could have been arrested, all your business records and source code confiscated and have been offline for months. If you'd been using your own hardware that might have been taken away, too.

There are plenty of cases where that kind of thing has happened before.

Re: Rely your web startup on Rackspace Cloud? Think again

#46
post #26

Earlier quoted context omitted.

No, and that's a strawman argument. That's like asking if it were reasonable for Level 3 to pull the plug on Rackspace if Level 3 got a phishing complaint. If Amazon got complains about Heroku then I'd certainly expect them to be investigated, and in Heroku's case I'd expect Heroku would take over and shutdown the phishing site.

I think everyone agreed on that the service provide have to investigate and take action on any abuse claim. But what is questioning now is that is it reasonable to shutdown a suspect case of abuse without giving time for the service provider to investigate and respond to this case?

According to http://archive.nyu.edu/bitstream/2451/15020/2/Infosec+BOOK_T... “experimental studies have shown that the bulk of victim credentials are collected within 24 hours of mailing the bait messages.”

Once a phishing form is “in the wild,” every minute counts.

The burden is on the service (your site) to prevent or quickly act to rectify a situation, but if your provider determines that it must intervene, then it is well within it's right to.

Re: Rely your web startup on Rackspace Cloud? Think again

#47
post #5
post #2

I'm thinking Rackspace might well have been in the right on this one. If the customer was in fact phishing, Rackspace was well within their rights to shut down the account. It's really up to the application creator to prevent that abuse. That said, it's good to have a reminder of the risks of outsourcing your hosting. I still think the tradeoff is worth it for experimental products where you don't want to invest too…

I agree. Hosting providers usually reserve the right to shutdown your server if it has been hacked, and phishing is often more directly harmful to people.

The problem here is Rackspace as a infrastructure provider judging on behalf of service provider. They give no explanation of the complaint details or why it is justified.

Many comments here take the phishing as "a fact", their terms might grant them the power to shut any server down but this is a threat I think every startup should learn if they use Rackspace Cloud or consider to. And we learnt that.

24 hrs is not just for respond to remove the content, it is also for the server providers to verify the complaint and react responsibly.

Re: Rely your web startup on Rackspace Cloud? Think again

#48
I am really not a fan of all the defending RackSpace here. They pulled the plug unreasonably without proper notification.

If you're going to pull the plug or even thinking about it... email simply isn't going to cut it. You need someone to call the owner and make contact to explain what's going on or how to resolve it. I've had my servers compromised, I've had phishing content setup before, I have never had the plug pulled. I've had hosts contact me, give me appropriate amounts of time to handle it and some of them even offered to help secure my box or look into how it got compromised in the first place.

Re: Rely your web startup on Rackspace Cloud? Think again

#49
post #2

I'm thinking Rackspace might well have been in the right on this one. If the customer was in fact phishing, Rackspace was well within their rights to shut down the account. It's really up to the application creator to prevent that abuse. That said, it's good to have a reminder of the risks of outsourcing your hosting. I still think the tradeoff is worth it for experimental products where you don't want to invest too…

May be technology can help a bit here? I think the issue in this case was more about the granularity of "takedown". If there was some kind of an API contract between the infrastructure provider and the application service provider - an API that lets you shutdown a single subdomain, an email service and so on, the situation would be more tolerable.

Re: Rely your web startup on Rackspace Cloud? Think again

#50
post #16

this will happen at any responsible web host. If you are hosting phishing sites, expect to get taken down. This trickles up. if you run a hosting company, and you get enough complaints that you don't deal with, then yeah, you will get shut down or asked to leave. That said, I think especially for higher-priced services, a phone call would be nice. (Note: I don't call my customers, though this is a policy I've conside…

What do you think about granularity of filtering: do not take all your customers' servers down, just filter the offending pages/services at network level until they sort it out.
Post reply on HN