Chart of YC companies' hosting decisions, 2010 edition
jpf.github.com
jpf.github.com
Guide:
<dns provider> <uptime %> <downtime> <outages> <avg speed>
October:
Godaddy DNS 100.00% 0h 00m 00s 0 68 ms
Dynect SMB 100.00% 0h 00m 00s 0 31 ms
DNSMadeEasy 100.00% 0h 00m 00s 0 39 ms
November:
Godaddy DNS 100.00% 0h 00m 00s 0 67 ms
Dynect SMB 100.00% 0h 00m 00s 0 26 ms
DNSMadeEasy 99.98% 0h 10m 00s 1 43 ms
December:
Godaddy DNS 99.99% 0h 05m 00s 1 58 ms
Dynect SMB 100.00% 0h 00m 00s 0 28 ms
DNSMadeEasy 99.00% 7h 25m 00s 22 40 ms
So basically Godaddy DNS is reliable but slow, DNSMadeEasy is relatively fast but had some uptime troubles in December, and Dynect (Dyn Inc) is fast + super reliable.As for pricing:
- Godaddy DNS is free (I think?)
- DNSMadeEasy runs about $2-5/month (max of 10 million queries/month)
- Dynect SMB runs between $30-95/month depending on what you need (max of 1.8 million queries/month)
If your serious about availability, this is the place to start.
Although we currently use DNSMadeEasy, and due to the uptime issues we might be looking to switch at which point I'll cast a broader net. Of course if you have a pingdom account, setting up these DNS checks is quite easy. They have a special monitoring type just for DNS.
Showing one name server is good, but it is not judging a providers "downtime". Would be much more useful if you tested all name servers. If several were down at once then yes... there is a good chance that you could loose a query.
Thanks for the efforts though.
I'm not sure what the cause of it was though.
Maybe for YC 2011 we could have a start up compete with GoDaddy. If some one started a trustworthy domain register targeted at start ups I could see it doing well.
This report actually checked an average of all name servers on Pingdom for a month. The full posting said:
I have been really down on Dynect because of their sales approach and their in-the-face cocky attitude. My very few interactions with them have been to immediately put down companies and competitors with complete BS statements.
But I have seen many people say how great the performance is. So did a pingdom test for all of their servers (used Twitter) and I did a test for all of my name servers on DNS Made Easy.
These are averages for "ALL" name servers.
DNS Made Easy: Avg. Response Time 34 ms Slowest avg. response time 58 ms Fastest avg. response time 23 ms
Dynect: Avg. Response Time 37 ms Slowest avg. response time 59 ms Fastest avg. response time 27 ms
Now Pingdom only does US and Europe testing... nothing in Asia where is looks like Dynect is stronger. But their network is no where as strong as they say it is. I have done as many trace routes as possible and I can never get a query answered in their singapore or australia locations.
So really... I do not get it.... Where is Dynect faster? Now I know this is only for the past month.... but really.... I think DNS Made Easy runs a hell of a network and they are a fraction of the Dynect guys (whom I have negative feelings about anyway).
Looking at tools like www.dnscomparison.com it looks like DNSMadeEasy is fastest some weeks, Dynect is fast other weeks, UltraDNS is faster some other weeks. Of course I'm not sure how "honest" this is as well.
But create a pingdom account... do some tests... be interested in seeing other results.
So far I say that DNSMadeEasy is as fast or faster then the ones that are many times more expensive.
Comments, ideas, bugs and patches welcome. The program I used to generate the report is hosted on GitHub here: https://github.com/jpf/domain-profiler/
This is mostly thanks to the suggestion from HN user jedsmith. I've updated my script to incorporate what should be a more accurate way of determining the name of an organization that owns a particular IP address.
I'd guess that the reason people aren't using AppEngine is more that it's strategically a pretty bad idea. You can't move off it, and its constraints have a major effect on how you design and architect your application. When you're still figuring out what your product is, using a platform that requires you to design your data storage to fit the queries you are going to run isn't necessarily that smart.
Wattvision is hosted on App Engine.
You can't point an A record at App Engine.
For Web Hosts it comes (roughly) to:
o Amazon EC2
o Rackspace Cloud
o Self Hosted (Surprisingly large number)
o Slicehost
o Hurricane Electric (which is likely self hosted? EDIT (per jedsmith) Linode?)
Two things I found very, very surprising. #1 - Small use of Linode
#2 - How much Rackspace is used more than Slicehost.
Anybody care to comment on why SoftLayer is so predominant?My guesses are: (a) they provide dedicated servers that are comparable to Rackspace but at a lower cost (but with a support trade-off), (b) they also offer cloud computing and storage instances that are decent (in my experience).
We we have worked with many providers, including all of those listed.
We continue to recommend Softlayer for leased dedicated hardware needs because of the features they provide, and the solid network infrastructure (although they do have hiccups on occasion).
Softlayer has a great support team, fast server deployment (1-2 hours) and full management capabilities - power strip reboot, IPMI KVM, OS reloads, etc..
Regards
The SimpleCDN issue involved three parties: SimpleCDN, 100TB (aka UK2), and SoftLayer. We've only heard from SimpleCDN and they threatened to sue the other two, so the silence is not surprising. In any case, my opinion of SoftLayer didn't change as a result.
I do admire your courage.
Regards
Both the SimpleCDN and FileVo shutdowns do look bad. But I'm not relying on courage, I'm relying on experience. Over four years I personally have had hundreds of phone, email, and forum interactions with SoftLayer at every level from their CEO to first level support. And countless DMCA requests. If I believed based on those experiences I was at risk hosting my company and my livelihood there, you better believe I would beat a path to the door.
So if you want to run on bare metal, but you don't want to rack servers yourself, they're a compelling option.
(I'm jamie@bu.mp, and as you can see from the spreadsheet, we use softlayer)
It's depressing how little GoDaddy has innovated and how dominant it still is.
I did note a small reduction in the percentage of YC domains registered with GoDaddy, but nothing significant. :/
I'll gladly pay plenty more only to avoid being exposed to the ridiculous mess that GoDaddy calls a web interface.
Godaddy has done the most/best marketing, that's all.
I am always interested to know what pitfalls other smart people have run into.
The small instances are very cheap, and we've been automating everything with chef, so it's east for us to gradually scale up by adding large instances to our cluster instead of small ones.
This means we've been able to build a scalable and secure infrastructure, that didn't cost us much more than a hundred bucks a month during development.
Our testing ended up leading us back to Linode, since with a simple support ticket you can up your private interface to the full 100mbps. So our "combo" ended up being Linode + Amazon S3 (since for many of our items the reduced redundancy storage is sufficient, and is half the price of could files).
It's sure fun though setting up your own small "cloud" system ;)
1. I'm a control freak and a privacy freak. I don't trust any third party with my email. I want to know how things work under the hood. And if I want to make a change, I don't want to have to depend on any third party to do it.
2. It's not hard to do. apt-get install postfix and dovecot, invest a couple of hours munging config files, and you're done.
3. Much easier to transition your data if you do get "enterprisey." All your data is on your server, so you can just tar it up and ship it anywhere.
4. You can configure the server so that insecure connections are not possible, making it that much less likely that someone will leak a password accidentally.
5. Stealth. It's much less likely that someone will try to break into my server than into Google's servers.
2. It's not hard to do. apt-get install postfix and dovecot, invest a couple of hours munging config files, and you're done
Bullshit. There's troubleshooting when things go wrong, patching, maintenance, etc.edit: don't forget adding additional storage, managing spam and malware filtering, user admin, backups, and other tasks.
5. Stealth. It's much less likely that someone will try to break into my server than into Google's servers.
You wish. Your single server is much easier to target and break into than Google's.(conspiracy theory: Google gives the public one text box on a webpage to search the Internet. Do you think they don't have a text box on an internal webpage to search all of Gmail? Do you think facebook doesn't have one internal webpage capable of searching all private communications? Facebook used to advertise "spy on your friends!" as an employment perk.)
That kind of thing would leak out sooner or later.
It might not be as easy as a textbox to search all of Gmail but your gmail data store appears to be wide open to a fairly large number of google employees.
and who can subpoena your private communications.
Hate to break it to you, but that same subpoena can just as easily allow your house, office, or datacenter to be raided. Your data is just as susceptible to lawful intercept at Google as it is your private premises.Furthermore, you can fight a subpoena. Do you trust Google to fight a subpoena on your behalf? How would they even know whether or not they should; how would they be able to tell if the subpoena is reasonable or not?
Not sure what you mean by additional storage? Local corporate e-mail might take up ~10GB per person after a few years? Most of my servers have 1+ TB of local storage + SAN. Takes a lot of e-mail to fill that up.
Spam and malware filtering are both pretty easy. yum/apt-get install clam and/or spamassissin/razor/pyzor/whatever. If you're running your own server(s) anyhow then backups, user admin, etc... are a sunk cost you've already spent.
If you're running your own servers anyhow, it's really not a big deal. I have a normal GMail account and a enterprise google apps account and both of them have pretty frequent IMAP outages (usually just for 5-15 minutes, nothing serious) whereas my mail servers haven't been down in years (minus planned server migrations). Also, if something does break, I like being able to go in and fix it, without waiting for other people.
In over 10 years of hosting my own email I've never had a problem that needed troubleshooting after getting the initial installation sorted out. And patching on Debian is trivial.
> Your single server is much easier to target and break into than Google's.
"Stealth" does not mean "harder to break into", it means "less likely to attract the attention of someone with the means and motivation to break in." Google may be harder to break into, but it's a much bigger target.
My house is easier to break into than, say, Bagram air force base. That doesn't mean that I'm safer in Bagram.
Patching is never trivial. The process itself may be trivial, but you have to actually do it. That latter part requires ongoing attention, which makes it non-trivial.
less likely to attract the attention of someone with the means and motivation to break in
That depends. Most attackers go for low hanging fruit. And the fruit hardly hangs low at google with their dedicated security team.
The most juicy targets are actually those little homebrew servers that someone once setup and then mostly forgot about. The spammers can often use these servers for months before anyone (usually the ISP, not the owner) takes notice.
If your server is listening on Port 25 then it's not stealth. It's very likely being scanned while I write this comment - perhaps to see if it's an exim vulnerable to the recent remote-shell exploit (http://www.debian.org/security/2010/dsa-2131).
So, to wrap this up. I also run mailservers for various companies. I also run debian. I even also run dovecot and postfix. But I'm doing this for a living, am subscribed to the relevant security mailing lists, harden the hosts before deploying them, and I monitor them.
If you don't have a dedicated or hired admin to do all that then hosted e-mail usually has the better value proposition.
It's more likely that someone will break into your server than Google's, isn't it?
A thing I learnt while running my own server was that all you needed to be a victim of automated attacks was to have an IP address.
True, it is probably easier for someone to break into my Linode than a Google server. However I think it's probably even easier for someone to break into my Google account. The surface area of a Google account is huge nowadays..
Email should be considered public. Unless you're using encryption it's sent in plaintext and could easily be stored on any server it goes through. While it may be harder for the gov to get access to it a clever hacker or employee can still get it.
> 5. Stealth. It's much less likely that someone will try to break into my server than into Google's servers.
Security by obscurity is not security at all.
i do complex server-side filtering with procmail to keep my inbox clean (so all of my devices polling my mailbox will only alert me when something important comes through), automatically archive all email in an "allmail" backup folder, and do things like rewrite e-mail headers for certain conditions.
Should I keep them separate?
What many people here are looking for is a snapshot of the choices a group of smart people have made : Going to rackspace.com is a whole different choice than heading over to slicehost.com.
Edit: Changed. However, the number of companies with A records in netblocks that are owned by "Slicehost" is pretty small. Perhaps Rackspace has been working on changing the names on the Slicehost netblocks?
That's embed.ly - they're at Slicehost, but you still have them at Rackspace even after this change. Your script might be confused because the /24 is a reassigned child of Rackspace's /16.
I've parsed WHOIS in the past and the corner cases make a very solid argument for just doing it by hand. IP ownership issues, which you've already seen with Linode, make it almost exclusively a wet code problem.
There's a few nagging questions with the list from a casual skim, too, one of them being octopart.com - 64.71.142.178 is part of a reassigned /28 out of a Hurricane /18, which means Octopart likely hosts themselves. I have doubts you get a /28 from Hurricane with their shared hosting, but their sales page does list a static address (singular). Shrug.
At the surface, it would seem that Linode offers more bang for your buck (almost twice as much) and outdoes Slice in the performance benchmarks.
Thoughts?
Linode also has StackScripts, which are pre-configured user-contributed setups for your VPS, so setting up a LAMP server is really easy.
We do it for security and privacy reasons. It matters less now, but for getting early carrier deals it was key, and now those agreements still bind us.
I use Amazon EC2 personally and would love to use it for more at Loopt, but can't.
Where's reddit? ;)
FWIW:
Web Host: EC2 (Amazon)
Email Host: Self hosted
DNS Host: Akamai
Registrar: Corporation Service Company
SSL Issuer: None
Certificate Type: None
Yes, it's a "List of active Y Combinator startups that haven't exited yet."
https://github.com/jpf/domain-profiler/blob/master/ycombinat...
Edit: Fixed.
it's also interesting that so many are using the hurricane electric host...never even heard of them before
I'm fairly sure Linode's West coast datacenter is in a Hurricane Electric facility so imagine those are simply Linode customers.