4 ms·
Re the hack. It was a while back, but was troubling. However, they're willing to sign HIPAA Business Associate Agreements, which for my company's purpose miti
by ryebit 10y ago
Re the hack. It was a while back, but was troubling. However, they're willing to sign HIPAA Business Associate Agreements, which for my company's purpose mitigates those concerns... they're willing to be on the hook for host & physical security.
Re the DDoS. As a mitigating factor, the DDoS was rather intense. It actually took their upstream provider offline. They supposedly have mitigated it with redundant connections and orders of magnitude more bandwidth at the two hardest-hit locations (Atlanta & Newark).
That said, time will tell. I love pretty much everything about their service (hardware, interface, bandwidth, cost), but I've got a business to run... if there's more extended downtime, I'm gonna have to move, though I won't like it.
Digital Ocean and Vultr were the two I was looking at, though don't really know much about the popular opinion of Vultr.
- lloyd-christmas 10y agoA hack is "troubling", and you deal in healthcare? I work in med-tech. If my hosting service was hacked and PHI potentially exposed, we'd have finished migrating away within a week. If your concern is only a business agreement to limit liability, do you mind sharing your product so I can never use it?
- ryanlol 10y agoIn Linodes case it's not about "a hack" it's about at least 4 hacks within the past 5 years. http://arstechnica.com/business/2012/03/bitcoins-worth-228000-stolen-from-customers-of-hacked-webhost/ http://arstechnica.com/business/2012/03/bitcoins-worth-22800... https://blog.linode.com/2013/04/16/security-incident-update/ https://blog.linode.com/2013/04/16/security-incident-update/ https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-team/ https://blog.linode.com/2014/01/19/an-old-system-and-a-swat-... https://blog.linode.com/2016/01/05/security-notification-and-linode-manager-password-reset/ https://blog.linode.com/2016/01/05/security-notification-and... I'm not even sure if they ever figured out the last one. So yeah, hopefully ryebit was just kidding.
- ryebit 10y agoLuckily, we don't deal with patient records or related PHI; which lowered concerns to the "BAA is sufficient" level. If I was running an EMR or such, I'd want the servers in a colo, with gated physical access, and contracts signed in blood of the each person's firstborn :)
- jest7325 10y agoI use Vultr and there are some DC that are more stable than other. Generally speaking it's worth what you pay for and I can't complaint.