6 ms·
I'm thinking Rackspace might well have been in the right on this one. If the customer was in fact phishing, Rackspace was well within their rights to shut down
by matrix 16y ago
I'm thinking Rackspace might well have been in the right on this one. If the customer was in fact phishing, Rackspace was well within their rights to shut down the account. It's really up to the application creator to prevent that abuse.
That said, it's good to have a reminder of the risks of outsourcing your hosting. I still think the tradeoff is worth it for experimental products where you don't want to invest too much upfront.
- nl 16y agoI agree. Hosting providers usually reserve the right to shutdown your server if it has been hacked, and phishing is often more directly harmful to people.
- watchandwait 16y agoAgree. This wasn't a simple DMCA issue-- phishing is an active, criminal activity. Even one hour notice is generous.
- A1kmm 16y agoTaking the contents of the article on faith, I think the point was that their customers were abusing the startup's service for phishing. This would be analogous to, for example, AWS taking reddit offline because a user posted a phising link. Nearly every web business which lets people put information on the web that others can see will face abuse issues at some point or the other - and cutting off a business and its legitimate customers because of one client misusing the service does not inspire confidence.
- royuen 16y agoThe problem here is Rackspace as a infrastructure provider judging on behalf of service provider. They give no explanation of the complaint details or why it is justified. Many comments here take the phishing as "a fact", their terms might grant them the power to shut any server down but this is a threat I think every startup should learn if they use Rackspace Cloud or consider to. And we learnt that. 24 hrs is not just for respond to remove the content, it is also for the server providers to verify the complaint and react responsibly.
- rickmak 16y agoEveryone hate spam. I don't object Rackspace to shut down an account that is obviously phishing/spam, but not take down as soon as they think there is an abuse. Grace period must be given, so the the site holder can respond. I don't think it is possible for few-man startup can responds in 1 hours for 24x7. I would choose to use an alternative hosting that give a longer gracing period.
- NyxWulf 16y agoThe reality is that each minute the phishing site remains up, another account may get its information stolen. Imagine if you are the person that had your bank account information stolen and drained during the "grace period" for the company to respond to the takedown notice. This is the kind of thing where a customer who gets their information stolen while Rackspace is waiting for the grace period to expire might have a legal cause of action against Rackspace. Ultimately, I think Rackspace did exactly the right thing here. If you are operating a service that would potentially allow fishing, then you are bearing the risk of policing your users. Asking Rackspace and affected users to give you a grace period is asking them to bear the risk instead. I 100% agree with the decision to immediately shut the site down.
- royuen 16y agoDo you think that it is reasonable if someone creates a phishing website on heroku, and all servers on heroku got shut down by amazon in an hour?
- lsc 16y agoIf heroku got enough complaints (relative to it's size) they would get shut down or asked to leave. Now, heroku has a lot more than two servers, so it's going to take more than one or two complaints to take them out, and they are probably going to get more than an hour of notice, but if you provide a hosting service, you need to make sure that your users and customers are not using your service to host phishing sites.
- nl 16y ago
- neeleshs 16y agoMay be technology can help a bit here? I think the issue in this case was more about the granularity of "takedown". If there was some kind of an API contract between the infrastructure provider and the application service provider - an API that lets you shutdown a single subdomain, an email service and so on, the situation would be more tolerable.
- goosmurf 16y agoOr even something simpler - call the account holder's phone and play a simple recorded message that says "hey, its Rackspace, we need you to deal with an urgent issue, please check your email ASAP". Cheap for Rackspace, gives the customer fair warning, and if there's no response within some reasonable time frame then shutdown the machines in question.
- bconway 16y agoWhat if I'm on a two-hour flight, though? A one-hour response time is ridiculous.
- goosmurf 16y agoWell I didn't agree or disagree with one hour, I said "some reasonable time frame" explicitly because the expected response time needs to consider what the real risks are.
- xiongchiamiov 16y agoWhat if I'm asleep in bed?
- paolomaffei 16y agoThey were in their right. And I'm in the right of choosing a provider that won't disrupt my business. I'm not talking about bulletproof hosting but 1 hour notice before takedown? Can't upvote this story enough.