Earlier quoted context omitted.
The thing is that they wanted to stay private when i posted this so i immediately removed and now waiting for them. By the way i received that response after 2 hours of the topic opening. They weren't answering me at all before HN post
So did your server get owned? Or was the DDOS attack a result of a bug in your code? Also, why do you delete your posts on HN? Do you only keep posts that make your viewpoint look favorable?
Stop Using Digital Ocean Now: The Aftermath
41–50 of 102 posts
Re: Stop Using Digital Ocean Now: The Aftermath
#42Earlier quoted context omitted.
So did your server get owned? Or was the DDOS attack a result of a bug in your code? Also, why do you delete your posts on HN? Do you only keep posts that make your viewpoint look favorable?
I don't know the first question's answer and that's what i am trying to learn. Second it's my first time participating in a HN topic that much i didn't know the etiquette here sorry for that.
Well, if you don't claim to know all of the details then I'd say it's a bit disingenuous to make a blanket statement like "STOP USING X SERVICE". I thought the tech community was better than that...
Re: Stop Using Digital Ocean Now: The Aftermath
#43Earlier quoted context omitted.
So did your server get owned? Or was the DDOS attack a result of a bug in your code? Also, why do you delete your posts on HN? Do you only keep posts that make your viewpoint look favorable?
I don't know the first question's answer and that's what i am trying to learn. Second it's my first time participating in a HN topic that much i didn't know the etiquette here sorry for that.
You probably should have analyzed the issue before making a blog post about it. I have had servers hacked into in the past, but I wasn't about to defame a company over my own mistake of securing the server.
Re: Stop Using Digital Ocean Now: The Aftermath
#44On the other hand, here's my experience with Linode. Another host company claimed that one of my machines was doing port scan on their network. Linode opened a ticket and preemptively blocked all outgoing connections to the SSH port from my machine. I had enough time to see what's going on and chatted with a very responsive support. The aftermath is that I moved all my data to a new linode, waited to for the DNS prop…
Not all VPS service providers are treated alike. Linode is probably a mid-tier VPS. Their cheapest plan is $20, which is 4x more expensive than Digital Ocean's cheapest plan of $5 a month. I would guess that most of the ultra cheap VPS plans probably won't come with a network engineer to help you.
But if I'm running something that pays me money, there's no doubt that I'll choose the best provider. And the best provider, for my requirements, is only $15 more expensive.
Re: Stop Using Digital Ocean Now: The Aftermath
#45There is a problem on the Internet is that people demand things NOW. Really? How long will it take for stuff to happen in real life (especially if you are dealing with government).
Some stuff does happen immediately (like registering or purchasing something), but stuff which requires human intervention is obviously slow. And it requires time.
Yes, you can have 24/7 response. But only if you hire someone (probably 3 persons) working for you round the clock which will mean paying thousands of $$ per month and not $5/month.
Re: Stop Using Digital Ocean Now: The Aftermath
#46Hi, this is Ben, CEO and Co-Founder of DigitalOcean, we have received the document and will discuss the matter publicly. ----- All times are UTC. Our monitoring picked up a malicious UDP traffic pattern on 2013-09-08 00:58:23. A ticket was then opened with the customer at : 2013-09-08 01:05:55 roughly 7 minutes later. The customer informed us that it was a script that was crawling in the background. We informed the c…
Other than that i've no other activity or script that can generate that much traffic. Haven't you even considered that my droplet may be compromised or being attacked ?
Instead of letting me know what exactly happened or which processes were running at that time you just locked the account and accused me.
Couldn't you even look at the access logs or so to see which IPs login into the droplet and then take your action later instead of closing it instantly?
Re: Stop Using Digital Ocean Now: The Aftermath
#47Hi, this is Ben, CEO and Co-Founder of DigitalOcean, we have received the document and will discuss the matter publicly. ----- All times are UTC. Our monitoring picked up a malicious UDP traffic pattern on 2013-09-08 00:58:23. A ticket was then opened with the customer at : 2013-09-08 01:05:55 roughly 7 minutes later. The customer informed us that it was a script that was crawling in the background. We informed the c…
a.) pretty good evidence that DO did their due diligence and
b.) way more thorough investigation than I would have expected from a "value" vps provider.
Re: Stop Using Digital Ocean Now: The Aftermath
#48that's rough they obviously only care about conversion and not validating the user before hand in (any) way, so brutal. From verizon I got a similar answer they couldn't discuss my own account with me after me giving them my social and all that - wtf. i hung up and tried another service rep and they gave me too much of my own personal info with out verifying any of my personal details and anyone elses' on my plans, w…
Re: Stop Using Digital Ocean Now: The Aftermath
#49Hi, this is Ben, CEO and Co-Founder of DigitalOcean, we have received the document and will discuss the matter publicly. ----- All times are UTC. Our monitoring picked up a malicious UDP traffic pattern on 2013-09-08 00:58:23. A ticket was then opened with the customer at : 2013-09-08 01:05:55 roughly 7 minutes later. The customer informed us that it was a script that was crawling in the background. We informed the c…
May I ask what about the UDP traffic made it appear abusive?
Re: Stop Using Digital Ocean Now: The Aftermath
#50Hi, this is Ben, CEO and Co-Founder of DigitalOcean, we have received the document and will discuss the matter publicly. ----- All times are UTC. Our monitoring picked up a malicious UDP traffic pattern on 2013-09-08 00:58:23. A ticket was then opened with the customer at : 2013-09-08 01:05:55 roughly 7 minutes later. The customer informed us that it was a script that was crawling in the background. We informed the c…
Maybe if you guys charged more you wouldn't get these ultra-cheap customers who think they should get 24/7 support for paying $5 a month.