Live data from Hacker News

Stop Using Digital Ocean Now: The Aftermath

serdardogruyol.com

81–90 of 102 posts

Re: Stop Using Digital Ocean Now: The Aftermath

#81
post #59

I use DO for a messing around on a small web app I'm developing. Within 24 hours of having my droplet up the root password was guessed and my machine was used for some DDoS. Granted I was an idiot for not changing the password immediately but I definitely felt like DO should just use ssh key validation like AWS does right off the bat. That deters attackers from even trying brute force attacks in the first place. Anyw…

[deleted]

Re: Stop Using Digital Ocean Now: The Aftermath

#82
post #70

Earlier quoted context omitted.

I was also tremendously happy with DO and their service. But what if you get your production apps down without even any notification and proper reasoning ? That's the thing which makes you feel insecure.

They did notify you. >Our monitoring picked up a malicious UDP traffic pattern on 2013-09-08 00:58:23. A ticket was then opened with the customer at : 2013-09-08 01:05:55 roughly 7 minutes later. Also, you should do a better job securing your server. It seems like the server was compromised.

That statement doesn't say that they notified the customer of the problem. Unless the notification to the customer said "malicious UDP pattern", the customer wasn't notified.

Re: Stop Using Digital Ocean Now: The Aftermath

#83

Earlier quoted context omitted.

I don't know the first question's answer and that's what i am trying to learn. Second it's my first time participating in a HN topic that much i didn't know the etiquette here sorry for that.

I'm guessing that most people who run a server may not even realize when they get hacked. These people (you included) probably should not run their own servers and stick to PaaS solutions like Heroku or Google App Engine. It happens all the time to guys who think they can install & maintain Wordpress themselves. You probably should have analyzed the issue before making a blog post about it. I have had servers hacked…

You miss the point here. It's not about getting hacked or so. It's their way of handling it. Like i said they kill it first and then tell you the reason why. What's the point in it ?

Re: Stop Using Digital Ocean Now: The Aftermath

#84

Earlier quoted context omitted.

Hello Ben, thanks for the response. Fırst of all at first ticket i told that the only possibility of having an UDP outgoing is that script that i wrote. Other than that i've no other activity or script that can generate that much traffic. Haven't you even considered that my droplet may be compromised or being attacked ? Instead of letting me know what exactly happened or which processes were running at that time you…

I was also tremendously happy with DO and their service. But what if you get your production apps down without even any notification and proper reasoning ? That's the thing which makes you feel insecure.

If you have a production app, it would make sense for you implement HA, then you wouldn't have to worry about a single server getting hacked.

What proper reasoning do you need? If your server is hacked, it makes sense to shutdown the server, or disconnect it from the network completely. You can extract the data at a later time.

What if your server was hacked, then started serving up child porn? Would you be okay with having the server continue running?

Re: Stop Using Digital Ocean Now: The Aftermath

#86
post #45

And now after nearly 10 hours or so i still haven’t heart from DO. There is a problem on the Internet is that people demand things NOW. Really? How long will it take for stuff to happen in real life (especially if you are dealing with government). Some stuff does happen immediately (like registering or purchasing something), but stuff which requires human intervention is obviously slow. And it requires time. Yes, you…

10 hours is unreasonably long for someone who is running an application that other users need to access. People are not going to be happy if Farmville is suddenly not remembering all the cows they milked last time they were logged in. This is about keeping customers happy down the chain. That said, I actually really like DO and I've only had prompt, helpful responses from their customer service. I don't build apps bu…

If you're paying $5 a month, don't expect to have support turn around times under 1 day. If you're running Farmville, I would hope that you're paying more than $5 a month for your server.

Re: Stop Using Digital Ocean Now: The Aftermath

#87
post #28

Sorry but I must be blunt... What do people expect for Something has to give. Yes we've all built and sold products and believe in providing an impeccable service worth far greater than the sum of its parts. Because we're in it to please everyone and build a reputation. But hosting is different. There are real costs for not taking action (upstream null routing, blacklisting, chargeback fees, fraud, abuse, etc). I'm d…

Abuse is expensive for a cloud service provider. Being thorough about it helps keep prices down.

Re: Stop Using Digital Ocean Now: The Aftermath

#88

Earlier quoted context omitted.

You know what they stopped answering my ticket after first response. If it wasn't HN post gaining this much traction i'm pretty sure that they won't respond to me.

They notified me what? They closed my account first and then mailed me after? It's like killing a man first and then saying the reason why.

Suspending account is an action reversable with sufficient cause, killing him is not.

Re: Stop Using Digital Ocean Now: The Aftermath

#89

Earlier quoted context omitted.

You know what they stopped answering my ticket after first response. If it wasn't HN post gaining this much traction i'm pretty sure that they won't respond to me.

They notified me what? They closed my account first and then mailed me after? It's like killing a man first and then saying the reason why.

If the account can reasonably be considered to be abusive (whether intentionally or because it was compromised), DigitalOcean has an even greater obligation to protect their network and the other network that's being targeted. Immediately suspending the account is the correct first step.

If DigitalOcean's support wasn't clear about their reasons for suspending the account, or if you feel that you weren't getting a helpful response from them, then post the communications you had with them to prove it.

Re: Stop Using Digital Ocean Now: The Aftermath

#90

Earlier quoted context omitted.

I'm guessing that most people who run a server may not even realize when they get hacked. These people (you included) probably should not run their own servers and stick to PaaS solutions like Heroku or Google App Engine. It happens all the time to guys who think they can install & maintain Wordpress themselves. You probably should have analyzed the issue before making a blog post about it. I have had servers hacked…

You miss the point here. It's not about getting hacked or so. It's their way of handling it. Like i said they kill it first and then tell you the reason why. What's the point in it ?

The point is that your system may be actively attacking another system, and it's their responsibility to immediately stop the attack first and then contact you after.

If they don't do this, then they run the risk of having their netblock(s) blackholed by upstream providers or other networks, which is bad for all of their customers.

They aren't responsible for making sure your system is secure, you are. You're a sysadmin now; it's not just a toy, there's responsibility too.

Post reply on HN