Live data from Hacker News

High-Memory Instances and $5 Linodes

blog.linode.com

61–70 of 175 posts

Re: High-Memory Instances and $5 Linodes

#61
post #48

Can we stop ignoring the fact that Linode has been hacked several times and responded terribly in every case?

In the current environment, I personally believe that it's safe to say that everybody has been hacked to some degree. Linode being open about it, even if not having the perfect response, strangely makes me feel better. Being a customer while this occurred and not feeling any impact makes me feel even better still. Having to go in and change my password is hardly an exceptional event on today's internet.

They were not open about it. When their ColdFusion system got hacked they didn't tell anyone until weeks after the fact.

When you search for "linode hack," Google suggests "linode hacked again." They were hacked in 2012. They were hacked in 2013. They were hacked in 2014. They were hacked in 2016. They will be hacked in 2017.

Re: High-Memory Instances and $5 Linodes

#62
post #38

Earlier quoted context omitted.

I would, however, love that price point. It would be nice if I could run a few light-weight services on a VPS for $2.50 a month and then put my websites and other projects on a beefier VM. I currently use Linode, but if DigitalOcean offered something at that pricepoint they would be getting $2.50 more from me a month than they currently do.

Pure guess, but I'd imagine that payment processor fees don't make it particularly profitable to offer price levels much lower than $5.

One thing that could help is having the ability to pre pay/load credits, so you could have a small discount that way

Re: High-Memory Instances and $5 Linodes

#63
post #38

Earlier quoted context omitted.

I would, however, love that price point. It would be nice if I could run a few light-weight services on a VPS for $2.50 a month and then put my websites and other projects on a beefier VM. I currently use Linode, but if DigitalOcean offered something at that pricepoint they would be getting $2.50 more from me a month than they currently do.

Pure guess, but I'd imagine that payment processor fees don't make it particularly profitable to offer price levels much lower than $5.

Make it so you have to buy at least 2 months then

Re: High-Memory Instances and $5 Linodes

#64
post #61

Earlier quoted context omitted.

In the current environment, I personally believe that it's safe to say that everybody has been hacked to some degree. Linode being open about it, even if not having the perfect response, strangely makes me feel better. Being a customer while this occurred and not feeling any impact makes me feel even better still. Having to go in and change my password is hardly an exceptional event on today's internet.

They were not open about it. When their ColdFusion system got hacked they didn't tell anyone until weeks after the fact. When you search for "linode hack," Google suggests "linode hacked again." They were hacked in 2012. They were hacked in 2013. They were hacked in 2014. They were hacked in 2016. They will be hacked in 2017.

> they didn't tell anyone until weeks after the fact.

Unfortunately, this is fairly standard practice in the industry. Companies want to make sure the vulnerability is closed, positively identify what was compromised, who was affected, what legal liability exists, and so forth.

Weeks is, frankly, pretty quick to go through that process.

> There's not much more to say -- they are dead.

Huh. Funny, I'm still hosting things there; their prices are competitive, there are no rumors of acquisition or shutdown... Seems quite alive to me.

> They will be hacked in 2017.

And, as I stated originally, I have no reason to think they will be unique in this.

Re: High-Memory Instances and $5 Linodes

#65
post #61

Earlier quoted context omitted.

They were not open about it. When their ColdFusion system got hacked they didn't tell anyone until weeks after the fact. When you search for "linode hack," Google suggests "linode hacked again." They were hacked in 2012. They were hacked in 2013. They were hacked in 2014. They were hacked in 2016. They will be hacked in 2017.

> they didn't tell anyone until weeks after the fact. Unfortunately, this is fairly standard practice in the industry. Companies want to make sure the vulnerability is closed, positively identify what was compromised, who was affected, what legal liability exists, and so forth. Weeks is, frankly, pretty quick to go through that process. > There's not much more to say -- they are dead. Huh. Funny, I'm still hosting th…

I don't think there's any reasonable arguments left to defend Linode with.

https://news.ycombinator.com/item?id=10845278

There's a clear, undeniable pattern of incompetence here.

I also suggest reading this glassdoor review: https://imgur.com/sJd56AT

And this thread: https://news.ycombinator.com/item?id=11136743

Re: High-Memory Instances and $5 Linodes

#66

I used to use Linode for some projects, and really appreciated their speed and server quality, which seemed better than Digital Ocean at the time. But after using them for 12-18 months, and losing several days of data due to the 2015 DDoS, and reading about more and more security issues, I switched back to DO and haven't looked back. The performance differences aren't noticeable to me, and I'd rather have my hosting…

We moved >1K$ hosting per month from them to StormOnDemand because of the lack of transparency on security issues, particularly the PagerDuty incident.

This was heartbreaking because Linode's value (performance, reliability, support, price) is almost impossible to match if your requirements fit their VM configurations.

But in the end, we did not want to risk another security or DDoS fiasco. We estimated that the risk was high that they would be targeted again, we could not believe their promises to get better at face value considering previous transparency issues, and we did not want to tell our customers that a company that had experienced security issues for the past three years had suffered from another attack[1].

They seem to have invested quite a lot in their networking infrastructure (kudos!), but I believe they still use their old coldfusion applications.

[1] Non-technical customers often ask us why we are not hosting on Amazon because they heard it's where serious companies host their servers (!). We used to explain why Linode was a more cost-effective choice, but Linode was not a nice name to google in early 2016.

Re: High-Memory Instances and $5 Linodes

#67

I used to use Linode for some projects, and really appreciated their speed and server quality, which seemed better than Digital Ocean at the time. But after using them for 12-18 months, and losing several days of data due to the 2015 DDoS, and reading about more and more security issues, I switched back to DO and haven't looked back. The performance differences aren't noticeable to me, and I'd rather have my hosting…

DO isn't any better, just hasn't been targeted by any serious attackers yet.

until very recently, they didn't allow using a custom kernel (except via kexec hackaround) and were quite slow updating their kernel for security patches. they repeatedly gave random dates for implementation, then repeatedly pushed them back, then eventually just ignored users on this issue for years.

their images were also poorly sanitized, leading to the well-known problem of SSH host key duplication, which was the case for years.

Re: High-Memory Instances and $5 Linodes

#68
post #12

I recently switched from DigitalOcean to Linode and could easily shave off 20% bill. The migration of VM was much easier than I expected (use rsync - https://lowendbox.com/blog/how-to-migrate-a-hosted-server-in... ). My only complain is, I would like to take multiple manual backups even if it costed little extra.

VM migration between the cloud hosting services is a big pain. I hope someone comes up with an app to do that.

Re: High-Memory Instances and $5 Linodes

#69

Earlier quoted context omitted.

Pure guess, but I'd imagine that payment processor fees don't make it particularly profitable to offer price levels much lower than $5.

One thing that could help is having the ability to pre pay/load credits, so you could have a small discount that way

This is the same theory that NearlyFreeSpeech.net uses.

Re: High-Memory Instances and $5 Linodes

#70
post #46
post #6

In the past they kept changing their pricing. I was paying for the smallest one (static site and a few prototypes) around $150/yr. Then they advertised that per-use would be mandatory and cheaper for everyone. I kept the site there barelly receiving any hit, using 0% of cpu and network. Endedup paying well over $250 after 12 monthly charges.

Unless I'm mistaken, per-use means you aren't billed for the server when it's powered down . If the server is up, even if you use 0% CPU, you're getting charged. Per-use is a lot cheaper for people that spin up servers to meet demand and kill them once things slow down.

From Linode's FAQ:

"If My Linode is Powered Off, Will I Be Billed? If your Linode is powered off, but is still added as a service on your account, you will still be billed for it. This is because Linode maintains your saved data and reserves your ability to use other resources like RAM, transfer, etc. even when your Linode is powered off. You will be billed for any other active Linode service, such as Longview Pro or an extra IP, as well."

[0] https://www.linode.com/docs/platform/billing-and-payments

Post reply on HN