Earlier quoted context omitted.
The same thing happened to me a few years ago. I used DigitalOcean's Docker image and it had some message about UFW in motd, so I assumed it works with Docker. So I created a container with passwordless mongodb and it got wiped in a few hours. And DO still have this in motd for newly created droplets: Welcome to DigitalOcean's 1-Click Docker Droplet. To keep this Droplet secure, the UFW firewall is enabled. All ports…
So the makers know of the security issue, but still leave it in by default? That's bad. Either fix the issue, or put warnings all over the place that cannot be missed to inform the user. This is just what another poster commented on, sacrificing security for ease of use.
DigitalOcean Support Thursday, March 15, 2018 9:53 PM
Hello,
Thank you very much for bringing this to our attention.
I will create an internal escalation to our images team to review this. :)
[...]