I replied to the ticket saying, "How am I DDoSing someone when the bandwidth/packet-rate graphs you host show I am not?" to which they acknowledged it was a false report, unrestricted my node and closed the ticket. Not a big deal but still odd that they did not first check their own bandwidth graphs. That to me appeared to be a front-line customer support training issue.
I should add that the player was really upset that their exploit code could not crash my server. It happened a couple times so I found the packet that took it down and used a simple iptables string filter to drop it. That is when they went with the false reporting tactic.
In my case, Linode opened an “AUP violation” ticket with a copy of the report, the steps they required to close the ticket (essentially: fix it and explain corrective measures), and a time when they would disable the server otherwise (which was something like 24 hours). It sounds like itch.io decided to ignore the AUP violation ticket and their server was disabled after 24 hours, just like the ticket said it would. (Waiting on a support ticket instead of calling also seems like a weird bad choice when your whole site is offline.)
I guess, having some first-hand experience with Linode’s malware handling process, that itch.io were at fault here, but I guess there may be more to the story they haven’t shared or weren’t clear on.
[0] Actually twice; some internet vigilante hooked up a virus scanner to a web crawler and was sending false positive reports directly to the abuse address for the netblock. After the second one I kindly suggested Linode stop accepting these reports, and never heard anything again.
Did you see the part where they removed the content within 24 hours?
I’m not sure what the point is of interrogating me here; I am just a third party who went through the same thing and thought additional detail about the process would be appreciated. I didn’t have any service interruption, but I followed Linode’s instructions, and this leads me to conclude that the OP probably did not.
At least if you own the hardware, you won't lose your data (except in extreme cases where the government takes it, but if this is the case you're screwed and data / service loss is the least of your worries).
Compared to?
Backups are something you should have regardless, an account with other providers and means to spin up some nodes is just basic common sense.
Vote with your wallet, let the execs know and never come back, it's honestly that simple.
Always better to have an escape hatch and corresponding protocols in place.
Nothing to do with the medium, just when you have 100-1000s of systems which are backed up, some of these systems 10+ years old, testing the backups is simply not done in reality.
A good thing is all these viral security requirements slithering through the software supply chain (and backup is a part of security because ransomware) will force anyone who sells SaaS to consider it after the startup stages when they sell to enterprises.
For colocation you probably won't loose the data but the company you chose can still disconnect you. And it's not uncommon in certain countries that police will take the whole rack belonging to different customers when they do police raids against pirating, mainly because they're incompetent but also trying to find other violators.