Please don't use Linode. If you are using it now, make immediate plans to switch. If you have friends who have things built on Linode servers, tell them to switch.
Please don't use Linode. If you are using it now, make immediate plans to switch. If you have friends who have things built on Linode servers, tell them to switch.
Feel how dickish this sounds without giving any reason whatsoever?
Please explain why.
Saying that would make you a dick.
The linode comment doesn't make tptacek a dick.
Why?
Because it's trivial to figure out why he's saying that by simply typing "linode" into google, but as of right now googling starfighter doesn't immediately bring up any reasons to avoid them.
Edit: Didn't mean to imply that parent was a dick.
If he argumented the reasons before he could had just put a link. Sincerely, it's too much to ask?
(2) I'm comfortable with the fact that my suggestion sounded "dickish" to you, whatever that means. It is meant seriously, though.
At this point, I am bored of people asking for citations on hacker news for things that are should be part of our tribal knowledge.
https://www.google.com/search?q=linode+hacks&ie=utf-8&oe=utf... About 2,810 results (0.34 seconds)
I definitely agree that there is a huge amount of that type of thinking on HN (of course), reading the amount of people who used github but didnt know the different between it and git and were commenting today was a personal education.
Of course, you can judge it differently, but following that link convinced me that the claims are probably not "baseless smearing", that it's a well-intentioned advice. Just from the link itself I wouldn't know on what grounds tptacek came to his conclusion, and I wouldn't heed his advice without further research, BUT I'm 99% sure that if I researched I'd find many well-documented arguments in favour of tptacek opinion/advice. I'd even bet on this: you say it's baseless, I say I can easily find the reasoning and arguments behind what tptacek said. Want to bet?
Oh, by the way:
> Sincerely, it's too much to ask?
Let's turn it around: a person with a lot of experience offers an advice on the matter he's experienced with. Is it too much to ask the readers to first, at least, google a bit before commenting? Why do you think you are entitled to receive even more of that person's attention and time?
If you can't even manage one small teensy link, what respect does that show for your audience?
The only value comes from the ptacek brand, and the trust I have in him through context. But that's generally not a strong foundation to build an argument on.
To be clear: I trust him, but it's not his best post. And op was not out of line for speaking up.
Edit: sorry ryanlol I didnt mean you, but tptacek. It was perhaps too strongly worded. Didn't mean to attack anyone, just wanted to show support for yomism's point.
I consider myself a HN regular, but I dont read everything. Linode posts I subconsciously skip, as they don't interest me. This was honestly news to me. "Incomplete information", I believe that's called ;)
(2) Nobody is entitled to detailed comments from anyone on HN, and keeping comments terse simply isn't disrespectful.
I appreciate that it is annoying to have to make decisions with incomplete information, but that's life.
http://www.urbandictionary.com/define.php?term=dickish
I have read the horror stories thanks to ryanlol's posts but next time please post a link if you don't want to waste time re-explaining. Let's use the HTML powers!
There's links elsewhere on this thread and Linodes security fuckups are a recurring subject of discussion on HN
This doesn't mean anything. I could get horror stories about any cloud service provider via Google yet we're only being told not to use Linode. Providing some context makes all the difference.
Anyway, personally, I choose to still stick to Linode because their customer support is extraordinarily good. I'm speaking about my experiences in the last 5 years.
Concerning their handling of ddos attacks - I think with this changes made things should be much better.
I think you should ask HD and Fyodor again what they think about Linode in 2016.
I really think that if it was some other VPS, they could not have done much better. You remember the outages that Amazon had? It's just a matter of fact the way I see it, these attacks happen. We learn from it, resilience is built. Until a new type of attack takes place, and then the process repeats. I understand that uptime can't be 100% all the time -- the 1 or 2 days it was down in 2015 was an inconvenience, but not totally unacceptable. I also understand that if you're against very determined attackers, it's pretty tough. How will any of the other VPSs fare when the attacker happens to have an 0day or something?
By the way, I noticed a few years ago that bitcoin-related startups were likely to use Linode. That makes linode a huuuuuuge target. I really don't think that if it was some other VPS in the crosshairs, these determined attackers could have been stopped 3 or 4 years ago with the ferocity and resourcefulness they seemed to be equipped with.
You know what makes it even tougher? Using COLDFUSION in 2016.
We've been happy Linode customers for a while now, and definitely prefer Linode to where we were before (Rackspace, via the Slicehost acquisition). I'm not opposed to moving to something like DigitalOcean or other but right now I'm seeing any compelling reason to make a move.
Would it be that much harder to say "Don't use Linode, they have a bad history security-wise and just got hacked again"?
Then there's the whole lying to cover up hacks, not investigating clear compromises when reported by customers and generally just avoiding any kind of negative press at all costs.
Hell, I know some in 2016 that are plain text offenders still.
You get what you pay for, and unless you pay about double what Linode charges...you don't get much in the way of added security or protection.
I do know who you are and I do have respect for your contributions, but my friend, it's seems like you're flaunting a sense of superiority when you issue a drive-by decree. It's only made worse when you choose to take the time you could have spent helping the readers whose opinions you're hoping to sway, and piss it away with grammar/spelling corrections and sarcasm. We routinely call out people in other public forums who give blatant non-answers, don't we?
I thought your comment was helpful. Until you decided that only those who would take it on faith or on fallible googling would be worthy of your help.
I'm not sure if tptacek implied the claim requires substantiation, but IMO naming and shaming is just the ethical thing to do when someone is covering up hacks.
FWIW, I am aware of the past issues Linode has had, and hope they do get their act together.
But in all seriousness, I don't know a single provider that sells cheap VPSs [e.g. At Linode's price point] and actually has something resembling security.
>Yes, but not if you found out such from confidential information you agreed to keep confidential.
Debatable.
Its roughly the same as DO, etc. Yes, its more expensive than buying a dedicated server.
I define anything cheaper than AWS/Google Cloud/Azure/etc. as "cheap". I am assuming you are using a reasonable level of bandwidth [e.g. 100GB+] when making such statements.
Really the only places you can find even cheaper VMs is sites like lowendtalk.com and you really don't want to go that cheap if you can avoid it.
> Debatable
Let me put it this way, "contractually obligated to".
Anyway, if anyone is going to make a blanket statement like "Don't use X", there's no harm in providing at least a high level explanation of why you're saying that. One shouldn't assume other people keep up with the exact same news that they do.
I do agree that some level of explanation would definitely be useful, but this comes up so often that I really don't find it surprising that people are too lazy to explain such statements.
There are times I am comfortable broadcasting clear, direct advice that might hurt some entity's feelings.
There aren't many times when I am comfortable doing both at the same time.
> Linode has had enough security issues that I wouldn't trust them with my servers.
All told, it took a few minutes one evening.
Please don't say AWS, I have no interest in learning that overcomplicated mess.
I'm using it right now, works great
Was working fine for few years before this happened.
Every company around that price point has these problems [and if they don't, they are either burning VC money or lying].