I can assure you that the opposite is true. Tumblr deleted half their content. MySpace lost all their content. GeoCities lost everything. Facebook "accidentally" lost Zuckerberg's old posts and with all the money and software "engineers" in the world can't recover them. Startups and corporations that had the kind of money and technical expertise you could only dream of can't keep data forever. Don't get carried away and make promises there is no way you can keep.
EDIT: I see you've redefined forever in the fine print:
> 1MB is not a big company. This is a project funded, developed, and maintained by an individual. By subscribing to Pro you are helping keep this project online for years to come.
> (1) Forever or for the life of the project. 1MB isn't going anywhere, but we also can't predict the future. No refunds!
Small nitpick, but Yahoo deleted everything. Let's not forget how poorly run Yahoo is.
[0] For example,archive storage at OVH runs at 0.0026$ per GB, so having a backup of 4 million 1mb sites would cost 1.04$/month for three copies of data.
Edit: it looks like these carcas pits are all calling themselves graves now ;-)
Edit; we also made custom scanners for porn and phishing; especially phishing, at that time had a simply pattern; the phishing page(s) would have keywords in them and would not be linked anywhere on the domain while not being the index.html. That allowed us to move almost all of them automatically.
Like, it's OK that you didn't, but maybe you should check that your entire public API (all microservices, UI, etc) will really be secure.
You will probably struggle to get a secure interface while user content is served from the same domain as your UI.
I think the interaction in this forum thread says a lot about my focus on security. An issue was reported and I jumped on it immediately. I’m not going to sit here and claim to be perfect, but I am going to tell you that I work really hard to make sure I do stuff right and fix my mistakes ASAP. I have had white hat hackers review my API by the way and have patched reported security vulnerabilities.
See github.com vs github.io[1], amazon.com vs. elasticbeanstalk.com, azure.com vs azurewebsites.net, etc... Every major company I know of that hosts arbitrary user content dedicates a TLD to it that's not shared by the management APIs.
[1] https://github.blog/2013-04-05-new-github-pages-domain-githu...
Really? In my experience not many people care about logout CSRF, it's the lowest of low risk vulns that infosec consultants write in a report when they don't have any real vulnerabilities. I'm not sure its presence really says much about the site overall.
Effort is much better spent elsewhere - strict Content-Security-Policy, for example. Or, if there are 'real' CSRF vulns that actually do damage