The ongoing story of a Dreamhost account compromise
old.nabble.com
old.nabble.com
The lowest tier server at Linode is $19/month (see http://vb.ly/linode) and will easily host plenty of virtual host based sites - although you could also check SliceHost or RackSpace Cloud Servers, etc.
Learning to run a simple server is really rewarding and you get to own root and run the box the way you want to.
Full disclosure: the link above has my referral code in it - it doesn't effect the cost of Linode's plans to you but if you do sign up you'll cover my hosting for a month. I hope people are ok with that.
Secondly, Dreamhost does provide VPSes with root access as well as web hosting and domain reg.
Thirdly, VPS isn't always the right solution. You have to account for time and willingness to do the sysadmin work -- instead of spending the effort on, say, programming or marketting.
Not everybody wants to spend several extra hours up front setting up and securing a server for a simple website or webapp.
And then patching it regularly and worrying about all sorts of things that may not be related to your goal in the slightest.
With most (read:good) VPS offerings the support guys won't have access to your VPS password (root, etc) and so from that perspective this would be safer and more secure for the OP. Shared hosting, by it's nature, holds a much higher chance of the hosting company holding your password in the clear/decryptable state.
My apologies if I wasn't clear in my original reply.
Dreamhost is fine for what it offers. People hopefully don't think they can really run something big and serious on $9/mo, but it's a good easy out for people who just want some web space.
Sure, I totally understand that this is over-kill if you are just running a personal blog - but then that's what wordpress.com etc are for. I'm working on the assumption that most people here on HN are either running a startup, a public facing project or building their personal brand -- all of which IMHO warrant setting things up properly.
There's of course, the added reward of having learned and accomplished something new.
Anyone who is the slightest bit technical would gain a lot from managing a VPS for their site. Even if you just want to host a bunch of wordpress blogs, or even static files.
Things like Exim and Postfix are non-trivial to setup correctly and very easy to screw up the configs, at least in my experience; though most of the time that I've tried to configure them I was trying to get them to do non-standard things (like redirect all outgoing emails to non-whitelisted -- through a pattern/regex -- email addresses to a specific mailbox).
That, to me, is not a good indication of a savvy & competent company.
Edit: I haven't used them for hosting.
He explained that there are customers who want passwords e-mailed to them, presumably even if you explain that it is not secure: http://news.ycombinator.com/item?id=1148848
And he mentioned that Dreamhost offers the (non-default) option of not storing the password text: http://news.ycombinator.com/item?id=1148732
I don't agree with their decision though, since most major websites will not email you back your password, by default. If facebook can get away with it, I'm sure dreamhost can too.
But unless there's something I'm missing, I suspect I'm just preaching to the choir right now ;)
- They've forgotten the password, but it's still in the keychain (or equivalent) for their mail or FTP client, which will all stop working when they reset the password.
- The password is shared with other employees, and it might be difficult to notify them all of the new password.
(2) Why not just ask the other employees for the old password?
(2) I wish I knew. Not really our place to ask, though.
The Apache Software Foundation has had some issues in the past with guys trying to hijack apcahe.org -- same thing, password resets on our registors site, etc, but luckly we noticed within a minute, and were able to talk to a human being on the phone quickly.
But I still really really want multifactor authentication for registers :|
Try dynadot.com.
They offer SMS for auth, and they're also the registrar for wikileaks.org, which takes a lot of guts, IMHO. :)
They keep expenses low with no telephone support. So you're SOL when bad stuff happens.
I've had a couple of these throughout the years (with hosts that will remain nameless). The nice thing was the control panel was separate from the support site. (Extra login info to remember but comes in handy when the server hosting your cpanel via a vm is compromised.).
Maybe I missed something in that thread, but IIRC the original poster said that his Dreamhost account was only for domain registration. How does that translate into 'discount hosting?' Back when domain registration cost $75/year from Network Solutions, they were still known for horrible customer service, IIRC. Paying more money for something doesn't necessarily mean you get better service.
I have a couple of private servers on DH which entitles me to free "live chat" with support.
This story makes me wonder if I should open up another account, and put one of my private servers on it, so if something happens to one account, I use the other one to make contact with support.
Don't put up home in the ghetto.
Where did he state that he feels there is a 'high chance?' If I encrypt my hard drive, does that mean I feel there is a 'high chance' of law enforcement coming after me and that I must be doing something 'bad?'
> The fact he is running sites that want to be anonymized
WHOIS records are only 'supposed' to be used to contact the site admin, etc. That said, when my WHOIS records were public I used to get a ton of junk snail mail. Especially from other domain registrars or 'protection services' wanting me to jump on board with them. The fact that he doesn't want his phone number and address connected to a domain doesn't mean that he wants the domain 'anonymized.' He just doesn't want someone to be able to Google his name and get a phone number and address.
> Don't put up home in the ghetto.
So the fact that a person wants a site to be 'anonymous' means that it's by definition a sleazy site? What about a forum for abused women? Should the site admin be forced to be contacted/harassed by possessive (and potentially violent) men that are trying to find where their girlfriend/wife that ran away is?
He didn't but the fact cryptnoob felt the need to mention it suggests he/she is concerned about. I myself don't go around registering multiple accounts "in case something happens" to one of the accounts. Do you?
>"WHOIS records are only 'supposed' to be used to contact the site admin, etc"
Dude, cry me a river. I own a shit ton of domains and so I get that spam all the time. The spirit of the rules around public record of WHOIS data (for com/net/org at least) is that someone can be contacted for technical and administrative reasons about the domain. It's a reasonable rule and so if people fundamentally disagree with it perhaps they should lobby ICANN/etc.
From my own experience running a web hosting business in the past that most people who anonymize their WHOIS details are doing so for suspicious reasons.
> "So the fact that a person wants a site to be 'anonymous' means that it's by definition a sleazy site?"
No, and my apologies for not being clearer on that - perhaps the word "ghetto" wasn't what I meant. What I meant was shared hosting is like being in the ghetto - you are at the mercy of your neighbors on the same server. An account on the same box sharing warez forums is going to affect YOUR site's performance.
> "Should the site admin be forced to be contacted/harassed by possessive (and potentially violent) men that are trying to find where their girlfriend/wife that ran away is?"
As someone whose domestic partner is a leading voice in women's rights online, who receives regular abuse and has had numerous death threats, I can assure you I am very familiar with this subject.
There is a difference between anonymous (read:un-contactable) whois vs using a business address or mailbox where you can receive communication but is not your private residence, etc.
I own a shit ton of domains
Well, you're the expert. Who am I to argue with anybody who owns a "shit ton" of domains? As someone whose domestic partner ...has had numerous
death threats
OK, on this, I'd say you're a liar. Anybody actually in that situation, I guarantee, would understand perfectly why anonymity on the net is often considered important to people. You are either a complete dolt, or a liar (or both, I suppose)I enjoy the convenience DH offers me in keeping my name out of Google. My reasons have nothing to do with whether or not my sites are sleezy. They're not. Privacy for myself and my family is not something I should need to justify to some random git (look it up) on HN.
While I agree that there's a higher chance of it being a made-up story just to try and win an 'internet argument,' than of dotBen actually happening to have a domestic partner in such a situation; there's still a possibility that dotBen and his/her domestic partner are people that are into ultra-openness (i.e. change doesn't happen unless you take risks). Don't be so quick to discount that possibility. Though I agree that rabidly trying to enforce your 'ultra openness' on other people is an aggressive stance to take, and a bit out of nature on HN.
> There is a difference between anonymous (read:un-contactable) whois vs using a business address or mailbox where you can receive communication but is not your private residence, etc.
Either you don't fully understand what 'private' WHOIS records are or you're purposely ignoring that information. When a WHOIS is 'private' a person is not 'un-contactable.' The service that makes your WHOIS record 'private' acts as a proxy, forwarding messages on to you while allowing you to remain 'anonymous' if you choose not to reply to the messages. Having public WHOIS information isn't just about having your contact information out in public, it's also about having your name attached to the site. If someone is upset with the content of the site and wants to find your home address, putting a PO Box or a business address as your WHOIS address isn't going to stop them if your real name is attached to the record. With a proxy service, you allow others to contact you while preventing personal information from leaking out unless you choose to respond to the person. It's not like public WHOIS information forces a site admin to respond to issues you have when you contact them.
> From my own experience running a web hosting business in the past that most people who anonymize their WHOIS details are doing so for suspicious reasons.
Suspicious how though? This is turning into a "if you haven't done anything wrong, then you've got nothing to hide" argument.
> I myself don't go around registering multiple accounts "in case something happens" to one of the accounts. Do you?
Did you say the same thing when people got paranoid about Google shutting down entire Google accounts over an issue with one of their products? (i.e. Google thinks that someone's AdSense account is gaming the system so some automated process closes the entire account and now the person no longer has Gmail access, nor Google Analytics access, etc) I remember multiple people talking about keeping each service on a separate account just in case one of them got shut down. That way they wouldn't lose 'everything' for the duration of the time that they were trying to get support from Google (if they ever got support from Google).
Why is this issue with Dreamhost that much different? If someone hijacks your account, and you need your account to contact Dreamhost to tell them that your account was hijacked, it presents a sort of Catch-22, no? Why is a person therefore to be looked at with suspicion for wanting to prevent such a problem?
In any case, why is it that someone must be a devious 'evil-doer' rather than just holding paranoid delusions? Wouldn't it be more likely that the person is just ultra paranoid than someone that was 'up to no good?'