Live data from Hacker News

DigitalOcean: Introducing Our London Region

digitalocean.com

51–60 of 64 posts

Re: DigitalOcean: Introducing Our London Region

#51
post #42
post #32

Earlier quoted context omitted.

Unfortunately we deal with a large amount of abusive and fraudulent signups which leads to a bunch of abuse on the network such as mining, port scanning, and flooding. We do everything we can to filter out abuse automatically and then determine whether or not a customer is legitimate outside of that but unfortunately that information isn't always available or conclusive. We'd love to hear suggestion on how we can imp…

Why is mining in particular disallowed? Aren't you allocating a set amount of CPU to a paying customer?

> Aren't you allocating a set amount of CPU to a paying customer?

I doubt they are. While DO boxes aren't bad, in terms of the "bad neighbor effect", I think they very much are oversold. Also, the virtualization tech is a continuum between complete and proper isolation of resources and time slicing of the CPU cycles on the one end, and Linux container style resource sharing on the other. Basically, the more isolated your VM is, the slower it will run. I don't believe DO is using any type of really strong isolation. Because of this, if you start mining BTC on your droplet, you will suck the CPU cycles from all the neighbors.

Re: DigitalOcean: Introducing Our London Region

#52
post #32

"We will need you to send us a high quality scan of a government ID or passport in order to verify your account. Please send the picture, or a link of the picture, to:" No thanks.

Unfortunately we deal with a large amount of abusive and fraudulent signups which leads to a bunch of abuse on the network such as mining, port scanning, and flooding. We do everything we can to filter out abuse automatically and then determine whether or not a customer is legitimate outside of that but unfortunately that information isn't always available or conclusive. We'd love to hear suggestion on how we can imp…

I don't understand why a scan of a passport or ID of someone signing up is required when it cannot be verified.

The reasons are this:

Banks are legally required to conduct some kind of Know Your Customer where an individual has to physically present themselves so their provided ID is matched against their physical person. So KYC is done by a bank. And I'm paying with a bank / credit card.

In the case of someone opening an account by using a fraudulent card, it is trivial to attach what looks like a mediocre scan of a passport or divers licence.

Notarised IDs are not requested, so there is no way to verify with a lawyer. And Notarisation is expensive, so it will turn almost all customers away.

Closing circle: If the name on the card matches the ID provided and it is not a case of a fraudulent transaction, the individual can be pursued via their bank. This is probably not worth it at a time vs reward level, unless the abuse of the network is such law enforcement should be involved, but is not something for you to do, but for your bank, as correspondent bank, to do.

While obviously a liability in terms of information security and the risk of a breach, requiring such personal information is a precedent: If all companies did so for low value transactions, then this information would end up in thousands of online repositories (and therefore of large scale, opposed to, say, a hostel seeing a handful of customers per day keeping paper records) which would surely have leaks. The risk becomes systematic. Which increases fraud.

Let the banks do KYC. Let the hosting company ensure the network is monitored in the way they desire.

Edit: Having worked in a couple of banks at a middle management level, and covering regulatory, compliance and information security roles, what really helps when regulators or general law enforcement audit or inspect a function, what really matters is showing both internal policies showing banking regulations are drilled into employees, and anticipative policies where regulations are not yet set in stone are also followed. If you don't have internal policy documents on how your network is monitored and a kind of minimum standards dashboard, make one and keep records, as it can be invaluable as defense against accusations nonfeasance, misfeasance or even malfeasance.

Re: DigitalOcean: Introducing Our London Region

#53

Earlier quoted context omitted.

How does SMS verification help ? You can just buy a prepaid phone.

How does using ID verification help? I can just use a borrowed/stolen/pilfered ID? At some point, you're hitting diminishing returns in your verification requirements.

I assume they look for name on ID that matches name on payment method. That's what I used to do when I worked in a hosting company ~10 years ago.

This way, if someone has a stolen credit card, there's a very good chance, they won't have a matching government ID with same name. Hence obvious fraud.

Re: DigitalOcean: Introducing Our London Region

#54

Earlier quoted context omitted.

How does using ID verification help? I can just use a borrowed/stolen/pilfered ID? At some point, you're hitting diminishing returns in your verification requirements.

I assume they look for name on ID that matches name on payment method. That's what I used to do when I worked in a hosting company ~10 years ago. This way, if someone has a stolen credit card, there's a very good chance, they won't have a matching government ID with same name. Hence obvious fraud.

Does a prepaid card name verification occur during an auth? Also, does Digital Ocean disallow prepaid cards from being used to pay for service?

Their pricing/billing page indicates they'll accept these cards if the payment is made through Paypal, which will shield them from payment fraud, but not if the card is prepaid but the users actions on the instance are malicious.

https://www.digitalocean.com/help/pricing-and-billing/

Re: DigitalOcean: Introducing Our London Region

#55
post #35

Earlier quoted context omitted.

> I'd never use a Debit Card for foreign currency transactions though, they always seem to have fees involved. Nationwide used to have commission-free cash withdrawals on their debit cards abroad, but I think it was abused by people who had second homes in other countries so withdrawn a year or two ago. I believe they still offer a commission-free credit card though.

My impression was that the banks made a lot more money from the spread than they did from the commission, so I kind of find that surprising. In Canada it's easy to find commission-free cards. The spread is a hidden fee though, so the banks have hiked that up several times.

The commission-free withdrawals abroad were offered at the wholesale VISA rate. Nationwide didn't take any vig.

Their "Select credit card" still offers EUR and USD purchases with no surcharge and no vig.

Re: DigitalOcean: Introducing Our London Region

#56
post #52
post #32

Earlier quoted context omitted.

Unfortunately we deal with a large amount of abusive and fraudulent signups which leads to a bunch of abuse on the network such as mining, port scanning, and flooding. We do everything we can to filter out abuse automatically and then determine whether or not a customer is legitimate outside of that but unfortunately that information isn't always available or conclusive. We'd love to hear suggestion on how we can imp…

I don't understand why a scan of a passport or ID of someone signing up is required when it cannot be verified. The reasons are this: Banks are legally required to conduct some kind of Know Your Customer where an individual has to physically present themselves so their provided ID is matched against their physical person. So KYC is done by a bank. And I'm paying with a bank / credit card. In the case of someone openi…

I've requested scan of ID in the past for suspicious sign-ups, the reasoning is that almost all malicious people would just move on at that point to another target.

Re: DigitalOcean: Introducing Our London Region

#57
post #32

"We will need you to send us a high quality scan of a government ID or passport in order to verify your account. Please send the picture, or a link of the picture, to:" No thanks.

Unfortunately we deal with a large amount of abusive and fraudulent signups which leads to a bunch of abuse on the network such as mining, port scanning, and flooding. We do everything we can to filter out abuse automatically and then determine whether or not a customer is legitimate outside of that but unfortunately that information isn't always available or conclusive. We'd love to hear suggestion on how we can imp…

An idea to automate part of the verification process is to have a "fill as much as you can or want" form asking for public accounts (facebook, G+, twitter, github, personal web site, non-free email accounts etc) and then generating a confidence score used for a pass/no pass/id required. A service (API) for this is one of the multiple ideas I haven't acted on.

Re: DigitalOcean: Introducing Our London Region

#58
post #27

Earlier quoted context omitted.

At least one other region has had them for a while (Singapore I think).

If by "a while" you mean less than a month: https://www.digitalocean.com/company/blog/announcing-ipv6-su... . I am a customer of DO's but I am not a happy one since I have to muck around with 6in4 tunnels just to get this basic stuff working.

Long time customers have had access to it since early May.. https://assets.digitalocean.com/email/ipv6-grandfathered.htm...

Re: DigitalOcean: Introducing Our London Region

#59

Earlier quoted context omitted.

If by "a while" you mean less than a month: https://www.digitalocean.com/company/blog/announcing-ipv6-su... . I am a customer of DO's but I am not a happy one since I have to muck around with 6in4 tunnels just to get this basic stuff working.

Long time customers have had access to it since early May.. https://assets.digitalocean.com/email/ipv6-grandfathered.htm...

So a small number of customers had IPv6 access in one of seven data centers for just over two months. Sorry, but I don't see this as a big redeeming correction (though it is factual).

Re: DigitalOcean: Introducing Our London Region

#60

Earlier quoted context omitted.

I assume they look for name on ID that matches name on payment method. That's what I used to do when I worked in a hosting company ~10 years ago. This way, if someone has a stolen credit card, there's a very good chance, they won't have a matching government ID with same name. Hence obvious fraud.

Does a prepaid card name verification occur during an auth? Also, does Digital Ocean disallow prepaid cards from being used to pay for service? Their pricing/billing page indicates they'll accept these cards if the payment is made through Paypal, which will shield them from payment fraud, but not if the card is prepaid but the users actions on the instance are malicious. https://www.digitalocean.com/help/pricing-and-…

Here you see the complexity of the process in that anything that is added or used can be circumvented, including IDs and so forth.

In regards to pre-paid and debit cards we saw a very high incidence of abuse related to those cards specifically so we've had to put certain restrictions on them as well.

We're going to look for other layered approaches that can be created programmatically to increase the authenticity of a user and need to get that implemented asap because I'm in agreement that this ID request is a horrible workflow and also it still isn't fool proof so its just doubly bad.

Running the product prioritization meeting today so we'll bring up a couple of solutions and begin to prioritize and implement.

Post reply on HN