Stop using Digital Ocean Now For the greater good
serdardogruyol.com
serdardogruyol.com
If the customer would authorize this disclosure then we can discuss it publicly.
Otherwise, as much as it pains us to get negative feedback, whether or not it is deserved, it is beyond our control as the privacy of our customers is the most important issue at stake in a public discussion.
As we (Blekko) get better at identifying and shutting down click fraud and other schemes to defraud advertisers a lot them end up being traced back to hosts in inexpensive hosting services. That is but one of many ways of having a machine on the Internet that generates cash for you. We ended up basically shutting out a couple of class Bs from an hosting service in the Ukraine for that reason, people can write us and get white-listed but in over 27,000 IP's not a single one was a legitimate user. Way too many people coming up with schemes to get some "free" extra cash.
I've been nothing but impressed with DO, right now there seems to be a misunderstanding and OP is not providing full details nor is he allowing DO to discuss what happened.
If he truly cared about others not using DO he'd allow it to be discussed, but it does seem like OP is hiding some fact...
So now I'm left with great service and product vs 1 guy who seems like he did something shady and got caught. Maybe it was an accident and maybe there is a way forward, but only if he brings to light the details of his actions.
Edit: Plus now you delete your post where you hint at your DDoS (by mistake or not) does not add up to your favor: http://i.imgur.com/1pxIxiN.png
One user sent me a bill for $10,000 after I cut 'em off for running a spam cannon, for lost business. I mean, I'd say 90% chance that they were just incompetent sysadmins trying to run wordpress and they got compromised, but ground truth was that they were sending out rather a lot of spam.
I sent a few notices before and after shutting them down, but their mail was hosted on the down VPS, so they never got it. Man, they were angry.
Dealing with stuff like this is the hardest part, I think, of running a low-cost (and thus low support expectation) VPS service. (one of the advantages, I think, of a high-touch service is that if you are paying me to manage your VPS, well, if it gets compromised, well, first it's my job to see to it that it doesn't get compromised, but if it does, it becomes my job to clean up the mess, bring up a new host, restore from pre-compromise backups, etc... - you get to be the hero rather than the bad guy.)
Key here, I think, is setting expectations; setting expectations is harder than you think, though. I've got a bunch of random copy on my front page... which is probably the wrong way to do it. But the customer needs to know ahead of time what is going to happen if they start spewing spam or participating in a DoS... and the customer needs to understand that they are going to get shut down even if it was an accident.
This problem is made oh so much worse by this massive influx of developers without sysadmin skills who should properly be on a more managed (or PAAS) solution who are moving to VPSs because they are so cheap.
Isn't this why most competent hosts request/require a secondary contact e-mail, not hosted by them?
Enforcing that requirement would be... non-trivial, though. I mean, I could look at the MX records for the domain in question, but those quite often don't point at the final delivery servers.
Still, I should at least make that a rule, even if I don't enforce it.
edit: Also note, even when you contact folks successfully, sometimes they refuse to deal with it, as, well, properly dealing with a compromise involves formatting and re-installing, then restoring from a backup taken before the thing was compromised. Most people at this level are unwilling to go through the effort, meaning that they will remain compromised for as long as you leave them on your system.
Often I'll setup a new domain for them, with the old domain read-only, so they can pick through the data. More than half the time, within 24 hours, they are compromised again.
Is that because they don't upgrade their software in response to being compromised?
Recovering from a competent compromise is... more complex than that. You pretty much have gotta read all the code you move from the old (compromised) system to the new system. As part of that, you want to minimize the code you move from the compromised to the new system; so you should re-install as much as you can from scratch, then move over your custom stuff, one file at a time, after reading it carefully.
If you have a good pre-compromise backup, and you have some idea of where the hole was and that hole was in one of the packages/support libraries, and that hole has been patched, then you can restore and upgrade.
As I'm running a no-support service, I'm not digging in deeply enough to tell you exactly what happened, but I believe that in most cases, users are just copying over their documentroot wholesale, and at best upgrading over the top of the (possibly compromised) copy, which quite often won't help you.
If they don't have a know-good local copy of the code to upgrade the stock components of and redeploy on a fresh VM that just sounds like asking for trouble.
What do you do with such customers? If you "fire" the repeat offenders would you say it's been worth the forum backlash from them (which this story seems like an attempt at so far)?
I also strongly select for customers who have some sysadmin experience (e.g. I turned someone away this morning who wanted a VPS but didn't want to authenticate with an OpenSSH public key) which helps a lot (but also vastly decreases my customer base.)
Worst case is when someone knowledgeable setup someone else on my service, then broke off contact; I'm now expected to step in and essentially be their sysadmin for $12/month. - That's the problem with unsophisticated users in a unsupported environment; they don't know enough to know if the problem is a hardware problem (which really is my responsibility) or a configuration on their own VPS.
but yeah, occasionally I get someone really, really angry. It's no fun.
My least favorite part of the job is firing customers who are the /target/ of DDoS attacks. I mean, if the attack is smaller than my pipe, I can tolerate it, but I've had customers hit with 10 gigabit+ attacks. Few providers can deal with that, so you are forced to get rid of the customer; It's really sad and messed up, because sometimes it's not even the customer's fault. Someone on the internet who controls a botnet doesn't like them. It's not fair that you finish the job, but there often isn't a whole lot of choice in the matter.
I have a whole lot less sympathy for people who allow their domains to be compromised and used in those attacks against other people.
"You might not get notified when shit hits the fan" seems like some natural enforcement :-P
Now, can a lawyer come in and discuss whether or not this can serve as authorization such that DO can't be sued?
My question is what do the apps do? That could easily be where the violation of the TOS is happening. Child porn? Fraud?
The lack of clarification is making the OP seem shady. Whats to hide?
While I can't say that they're TOS violation claim is bogus, I also can't say it's not bogus, because the author didn't publish (or, apparently, ask) for that information.
Great, you've got a large number of users, and you used Digital Ocean to host your backend. Why are they saying you're in violation of the TOS?
Ask the follow up, figure out why they're not pleased with you, and don't try to appeal to emotion when you have no substantiating information.
As a side note, I have no horse in this race. I don't use Digital Ocean, and I have no affiliation with them. I just don't see the author's claim as being 100% put together and honest.
What if a site was compromised? What if an employee typoed the IP of an abuser? What if, what if?
Their "fullstop" replies are not professional.
And if you did have some automated system and various criteria for detecting likely abuses, if someone got shut down under those terms, would you tell them exactly where the line was? Or would you keep your detection methods to yourself?
"Your site has been turned off due to hosting child porn, in contravention of local/international law XXXXXX, per complaint YYYYYY".
Then they can at least dialogue.
Worst case scenario: the VPS is shut off automatically, I get a semi-urgent notice, and I reply to the customer with further details as soon as possible. And they would get a message letting them as much.
http://i.imgur.com/1pxIxiN.png
Just because the blog post doesn't say why doesn't mean he doesn't know why. Only that he's selectively sharing the information.
I still think it's important to reiterate as much as possible why a service was shut off, both for a customer understanding viewpoint, AND from a "cover your ass" viewpoint.
It can't hurt to say "As stated in the past email, your server was shut off due to YYYYY", rather than just "Game over, man. Stop emailing us." equivalents.
If the author was breaking the AUP, I don't feel very sorry for him. If someone's doing something that legitimately violates acceptable use, they probably should be shut down without prior notification.
I realize you sound angry because you were asked to verify your account, but this reads vindictive and makes me think that the same behavior that caused their abuse department to flag your account is what's responsible for this attack blog post.
Unless you provide that information this post comes across as a rant.
> DigitalOcean reserves the right to modify the Terms of Service without notice.
Well... that more or less invalidates the sanctity of the terms.
> DigitalOcean also reserves the right to terminate a customers account if they are targeted by malicious activity from other parties.
What is the justification for that? Simply being the target of malicious activity means that your account can be terminated? It's not as though one is responsible for malicious activity directed against them.
> DIGITALOCEAN DISCLAIMS ALL WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, REGARDING THE SERVICES PROVIDED HEREUNDER, INCLUDING ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE ...
I see this a lot with software, but doesn't this mean that DigitalOcean has no actual obligation to provide the cloud or VPS services they advertise? I didn't see any such clause in the EC2 TOS, but I did not look very hard.
Is this the usual sort of agreement for such a service?
See section 10 of http://aws.amazon.com/agreement/
Frankly, none of those terms seems atypical. Amazon does have SLAs[1], but they do not apply if your account has been suspended. Reasons for suspension can include your use of the service adversely affecting any other AWS customer. They may also terminate you if providing services creates a substantial technical burden. Both of those can be triggered by you being "targeted by malicious activity from other other parties".
You'll find the plurality (if not majority) of ToS's out there include such a statement.
>What is the justification for that? Simply being the target of malicious activity means that your account can be terminated? It's not as though one is responsible for malicious activity directed against them.
They don't want to deal with the networking implications of a large scale DDoS. They're providing low priced VPS services, not high bandwidth, high load custom racks. Also, they "reserve the right" not the "always exercise the right". DO likely won't kick you for a small DoS/DDoS but sustained attacks take much more manpower to deal with than you're paying them for.
>I see this a lot with software, but doesn't this mean that DigitalOcean has no actual obligation to provide the cloud or VPS services they advertise?
No, it means you can't sue DO because your VPS went down and you lost 10K is sales because customers couldn't access your storefront. It's an indemnity clause.
>Is this the usual sort of agreement for such a service?
Yes, unless you're paying a good deal of money for something like a Colo with 1hour SLA or an AWS instance with a high SLA.
IANAL, but I don't think that warranty disclaimer is relevant here. I don't think it means much at all actually. As a business you can say you're not liable for anything bad that happens, but that doesn't necessarily make it true.
Most providers will shut you off if you're running a server that attracts a lot of DDOS attempts. Many providers explicitly disallow running irc servers up front to avoid this very scenario. If your site is constantly getting DDOSed for whatever reason that is going to have a big impact on the hoster's entire network and other servers they are hosting and while it may be through no fault of your own, almost all hosters are going to bounce you if it is a recurring problem.
Their response? They shut down the server because of "unusual traffic" coming from the server which wasn't even being used yet.. but there was "outbound traffic about 977.38 Mbps at its peak at around 2013-07-22 14:50:00UTC"
They need to fully verify accounts before letting anyone create a server. You shouldn't just take down a server out of nowhere, for several hours, after it's been running for weeks.
Does this not sound suspicious to you? Maybe the server was compromised. "Unused" servers usually don't generate 970 Mbps traffic randomly.
I had to go through their 'verification procedure,' as well. I thought it was odd but if it keeps prices low due to fraud, I really don't mind.
I said that IS the point.
> he should have included Digital Ocean's side
OP claims they didn't give any
I'm wondering now if dropbox reported them for abuse and DO suspects that the account was compromised and is being used maliciously...?
Edit: Looking at their backup script, I don't see any error condition or exception handling when the file upload is posted via the dropbox client.
It might be that dropbox triggered some kind of abuse/rate limiting with a message to that extent. Without catching that scenario, the cron job would simply keep running... could be a situation where the dropbox user didn't know they were being abusive, were reported by dropbox to DO for abuse, and here we are.
This is nitpicking but in the end, you (DO) have a smiling icon because you expect you support group smiles. If your support group is a machine, well then... use this one.
## ##
##############
#### ###### ####
######################
## ############## ##
## ## ## ##
#### ####What? Is this a common procedure now?
It's so weird to see things like 'Twitter account' and 'Facebook account' being 'assumed'.
They are just two private companies why should we (directly/indirectly) force everyone to have one?
Email I'm fine with, it's a open technology.
It's only a matter of time until we turn Twitter and Facebook into more open technologies like email. I sure hope to see that happen.
How many times do you contact support? For me to contact support, there has to be a problem with the actual service itself. That is, it's an obvious problem that is outside of my control. I have been running VM's with quite a few providers, certainly all the big names. I almost never have to contact support (I would have to think pretty hard about a time that I have done this.) These services are usually quite solid and if there is a problem, usually there is some sort of status which lets you know there is a problem so that you don't have to ask.
For me, having to contact support even once would be a big problem. Having to contact support often enough that I have noticed that support was once good but then turned bad would have been enough for me to have long since moved on.
Did you find out what the breach of terms of service they spoke about was? Unless I missed it the article...
1- Host/distribute copyrighted material
2- Run a torrent client and distribute copyrighted material
3- DOS attacks (especially when you can create several droplets for a limited period of time)
The hosting provider is like a bank, and has the right to ask you where you got that information from; and for what you are using it (though a bank doesn't ask you what you use your money for)
I think it's acceptable that the hosting provider ask for your activity and you provide a response for that (which you didn't).
Personally, I have had a great experience using digital ocean. Now I am terrified of moving forward with them if they proceed with this "shut down first, ask questions later" pattern.
There was also no mention in this article (except in one of the screenshots) about whatever -- "[a] UDP flood or so" "at the beginning of this month".
It would certainly suck to have your account locked out when you're serving production sites but it sounds like we haven't heard all of the story (we obviously haven't heard DO's, of course).
Also, are you sure it wasn't something else, not the dropbox db script which could have caused problems?
We really need to hear from DO to hear the other side of the story though.
I used the Live image of my droplet to mount the disk, copy the databases, and websites. Once I was satisfied I got everything I destroyed the droplet.
Before you destroy your droplet, request this!
[Lish]: (https://library.linode.com/using-lish-the-linode-shell)?
This honestly sounds like growing pains, now that we are "taking off" we need to make sure users arent abusing our service. Lets do a user verification process for certain instances that are flagged for whatever reason.
I have experienced similar verify account problems with Pay Pal/eBay. While its a burden on people who are doing legitimate business, if it keeps spammers/scammers off of a service then it is worth it.
Op seems very childish and not very forthcoming.