Managed hosting is a requirement for the masses, and comparing a managed hosting service with a self-service VPS is a bit disingenuous IMO. Managed may seem more pricey, but that's only unless you don't value your own time as an administrator, or if your time isn't valuable (you're not good at it lol).
FWIW I use Namecheap / Linode myself, and will probably never go back to shared hosting. But the flip side of that coin is you do need to manage it, regardless of the website you are hosting.
Or you can opt out of this mess and run a simple server. Not as root.
The update & maintenance treadmill can be slowed down to nearly a halt if you're ok using simple software that doesn't have a billion features and just as many bugs. Which, I suppose, someone running a static site would be quite willing to do.
Little old grandma just loves ssh'ing into her pet server every day to read her system logs.
http://yaffa-cdn.s3.amazonaws.com/adnews/live/images/yafNews...
It's not a strawman at all. I am speaking from real experience, except for the part where my grandmother could tell you the difference between SSH and SSL.
And I don't think GoDaddy or other managed hosting providers are doing a better job than this.
Also FYI static websites have a much smaller surface of attack when compared to forever-vulnerable shit like WordPress.
Godaddy is not doing much more than auto-updating packages with security fixes. This is easily handled with most Linux VPSs (often automatically, in the case of DigitalOcean). I am pretty sure the Amazon Linux AMIs do this too on AWS EC2. And most other distros can turn this on once with one command.
I don't think GoDaddy is going much deeper than this, so security is a moot comparison between the two. In fact most sites are hacked at the application level anyway, not the system level. So the real security hole is not something on Linux, but the actual wordpress site thats installed within it. Food for thought: 83% of hacked websites in 2017 were Wordpress sites. Source: https://sucuri.net/reports/2017-hacked-website-report
^ I know this statement appears absurd to you, so I'm wondering why you're posting as if it's true?
Also, another time I was having problems with their stupid 2FA app (back when they ran their own app and it broke constantly), and their solution was to just disable the 2FA for my account. They said I can set it up again whenever I want to. So then I told the woman, that if someone wanted to hack into my account, they could just open a livechat and get my 2FA disabled and then log in, why should I even bother having 2FA at all if you're just going to disable it.
To be fair, they finally moved to a more traditional 2FA now, where you can use any 2FA app instead of their proprietary namecheap app. So they might not do this anymore. I think they were disabling 2FA back when they used their own app for it, because it was super buggy and people (like myself) would get locked out of our accounts for no reason other than their app was buggy.
Their UI hasn't always been the latest & greatest (but even here they came a long way in the past 2 years). their knowledgeable (and helpful) customer support really makes up for it.
I don't know the internals of the company but would assume that the people running it are still the same team who founded it and they really know networking & DNS inside-out. Refreshing in a time where financial and marketer types have taken over a lot of the decision making in tech or where you're in a customer support loop for ages and everything is handled by a bot.
I still have a few domains with them it I’ve been using namesilo lately after hearing about them here and no complaints. Well the only complaint I have of them is they don’t have the range of TLD’s as namecheap does (but it’s only a handful of TLDs such as .es)
But you know what? I'm okay with that. I honestly can't think of a scenario where I'd want to use any other nameservers.
What about the scenerio where you are thrown off of cloudflare service? A CDN is more inclined to ban sites to limit their own risks from litigious IP owners, etc, irregardless of who would win an actual court case.
That could be an argument not to use their DNS service and their CDN service.
It shouldn't be an issue for the DNS service by itself.
But... I haven't been a fan of them lately.
I've got a password manager and 2FA on all my accounts, and I went to sign in. I kept getting an incorrect password response. Reset, tried again. Just kept getting the same error. Freaked me out as I couldn't sign in.
Fast forward, came to find out because I was on my company VPN they were blocking me. Rather than just show a message, "We don't accept users on a VPN..." they let me think my password was wrong and go through the panic of not being able to sign in. And, even thought they thought I was some sort of spammer / hacker for using a VPN, they were more than happy to discuss my sign in details over live chat.
I sort of get "security" here, but they shouldn't be heavy handed with just saying who can and can't sign in, and if you are going to block me, tell me why -- at least send an email letting me know what's up if you don't want to display a browser message. 2FA was enabled, at that point... just leave it up to the user where they want to sign in from, don't put in secret rules around who can and can't sign in.
Anyway, I moved everyone over to Amazon Route 53 and haven't had any more issues.
Run a website of any importance and you will quickly be shocked at the amount of malicious traffic that keep coming from Tor/DigitalOcean/VPN/openproxy and a few other sources.
And they blocked me.
They didn't tell me why, I figured it out on my own inadvertently.
I wasn't on a junky free VPN, I was on a corporate VPN service.
And I was blocked, worse I was given false information about my password being incorrect... and worse still, given that they assumed someone was trying to enter a fake password, they never emailed me to let me know -- I had to contact them.
Plenty of legit reasons for someone to use a VPN. I'm relatively certain nobody from the telco in Australia who set up the VPN had been trying to hack Namecheap, looks more just like someone found a way to classify that IP as a VPN and blocked it.
And look, to put the nail in the coffin, they were more that willing to tell me the email address to check for the reset password via live chat.
Anyway I tend to be the guy harping about security, but when they start banning VPNs just for being a VPN I don't think that's secure, I think it's obnoxious. We should encourage people to use VPNs, not make it annoying for them.
Proper procedure would be to let the bad guy try, block the IP (or better yet, browser finger print), let them know why they were blocked (in case they aren't a bad guy), and (if the owner didn't have 2FA) send the owner an email saying someone was trying to get access but wasn't successful.
For users with 2FA, all you'd ever really have to do is send an email to the owner, and / or access distribution list, letting them know when a certain user signed in. I wish more people offered this service, getting access notifications when any admin signed in would be key for helping me figure out what task broke something if I have to go fix it.
But then comes namecheap. They are literally the only service on the internet where I will get locked out with 2FA. It will keep claiming it is the wrong password, when I know its not. I don't ever have a problem with any other online service, but the 2FA on namecheap is a constant problem. I have been locked out on Namecheap for no reason now 5+ times that I have now just turned it off.
Now that I read your comment, I wonder if I have the same problem. I am sometimes logged in via VPN and I wonder now if that is why it was rejecting me. Its frustrating because i know the password is correct and the app is set up correctly, but it will keep claiming I have the wrong password. Like i said, I now just have it turned off, because I am terrified of losing access to my domains. But I am also terrified of not having 2FA protecting my domains. So its made me consider transferring elsewhere.
I also considered just using Amazon. Most of my domains are already using Route53 as a premium DNS instead of relying on Namecheap as a DNS anyway. So I am considering just having them be the registrar too.
I am purposefully staying away from AWS. They are super popular right now and developer friendly, but I know how their business operates and that popularity will subside in a few years. I predict many of their users will feel betrayed at some point in the future after enough people have moved to their DNS.