Earlier quoted context omitted.
And there are a million stories of startups who build the wrong thing, don't achieve product-market fit, etc. You can't dot every I, cross every t and also build a compelling product as a 2 person shop.
Then maybe you shouldn't be building that product with a 2 person shop.
"DigitalOcean Killed Our Company"
411–420 of 620 posts
Re: "DigitalOcean Killed Our Company"
#412Earlier quoted context omitted.
I agree that we're not getting the full story. On the other hand, completely shutting down all their services without a quick conversation...
Having been on the receiving end of terribly broken "pipelines" at startups wanting to hammer away at my resources, the right response is terminate first discuss later. I know of a company that explicitly had a "call us to discuss first" clause in their contract with a smaller cloud provider. Everyone was on holiday and not answering the phones while their hacked account was being used to spin up dozens of boxes laun…
Re: "DigitalOcean Killed Our Company"
#413Earlier quoted context omitted.
You'll be surprised how many companies are "all in" on AWS or Google Cloud, including ALL backups.
I agree. Who are all these people that pull backups, that maybe GBs or TBs in size for offline storage? How does that even work in practical terms in disaster scenarios like this where resolution times are expected within hours and not days?
Re: "DigitalOcean Killed Our Company"
#414Re: "DigitalOcean Killed Our Company"
#415As DigitalOcean's CTO, I'm very sorry for this situation and how it was handled. The account is now fully restored and we are doing an investigation of the incident. We are planning to post a public postmortem to provide full transparency for our customers and the community. This situation occurred due to false positives triggered by our internal fraud and abuse systems. While these situations are rare, they do happe…
Thanks for the replies. Let me try to address a few of the things I have seen here. We haven't completed our investigation yet which will include details on the timeline, decisions made by our systems, our people, and our plans to address where we fell short. That said, I want to provide some information now rather than waiting for our full post-mortem analysis. A combination of factors, not just the usage patterns,…
The real “mess up” here was the bit where you blocked the account with no reason given and no further communication - other than the one-liner your intern wrote for the email.
I’m expecting you to sit down with your legal team and rewrite your TOS to be more customer-focused and less robotic.
Re: "DigitalOcean Killed Our Company"
#416Some people on HN hate Linode because of their past security screwups (which is valid), but having used both DO and Linode quite a lot, the support on Linode is way, way, way better than DO's. DO's tier 1 support is almost useless. I set up a new account with them recently for a droplet that needed to be well separated from the rest of my infrastructure, and ran into a confusing error message that was preventing it f…
Re: "DigitalOcean Killed Our Company"
#417Earlier quoted context omitted.
Access to your data should never be denied. Ever. It was not DigitalOcean's data. If you are a hosting provider, you can't ever hold customer data hostage or deny them access to it in any way.
Again, I must disagree. If DO genuinely believed that you were doing something malicious and that data was harmful or evil for you to own (e.g. other people's SSN, etc) then they are in the "right" to deny access to it. DO should not be forced to aid bad actors. And, regardless of what DO should or should not do, they can do whatever they want with their own hard drives. You should structure your business accordingly…
If there is no police report, then they are trying to act as police themselves, which I think is unacceptable. It is not their data.
Your argument that they can do whatever they want with their hard drives is indeed something I will take care to remember — I definitely would not want to host anything with DO.
Re: "DigitalOcean Killed Our Company"
#418Earlier quoted context omitted.
I've been on Linode for 8+ years now (moved there from Slicehost when Rackspace swallowed them up) and their service (not necessarily customer support) has significantly degraded. Not sure I blame them though. They've become far more popular since I started with them and are probably doing their best to grow... but I no longer recommend them as I used to. Just my experience though.
Could you give some concrete examples on how their service has degraded? I've been using their service for years for light stuff, and I haven't had any problems.
I suspect as they've increased in popularity they've become a bigger target for DDOS attacks.
I've also noticed that in the past year there's been a lot of data centre outages... like every couple months. Hasn't been a deal breaker for us, since our traffic is generally fairly low outside of season, but the ones during seasons really hurt.
Also I'd like to add that they do give you the heads up when there are issues, which is a big plus in my book compared to some other hosts.
I really do think it's just growing pains, and I don't mean to disparage them. Just being honest that I wouldn't recommend them for high availability services. Since I consider them a low budget host that's probably unfair though. We've just outgrown them is all.
This is all anecdotal of course.
Re: "DigitalOcean Killed Our Company"
#419Earlier quoted context omitted.
Why would DO be upset about spinning up 10 VMs then spinning them down again? Isn't this exactly the point of cloud providers? This is what they bill me for, right?
I guess it depends on what each of those VMs is doing. I don't trust the Dev's explanation tbh. > to make it faster we execute it in parallel on multiple droplets ~10 that we set up only for this pipeline and shut down once it’s done. Tildes preceding numbers means "approximately". Why doesn't he know exactly how many VMs he spun up? Was he actually spinning up 1 VM per record and only allowing 10 VMs to be running c…
Random speculation of one possibility: each of those 10 instances were suddenly doing something unexpected and spammy with the network. Maybe sending 500k+ emails (one per row of data claimed by the developer) over SMTP in a very short period, or jumping to massive spikes in torrent traffic, or crawling sites to scrape data (maybe each row of 500k is just a top-level domain name, and they crawl every URL on those domains, possibly turning 500k rows into hundreds of million of http requests).
The postmortem will be interesting. If DO is truly at fault here, that email after the second lockout saying the account is locked after review, no further details required... bad.