Saturday, January 21, 2006

Pay peanuts, get monkey hosts

There's been a lot of coverage in UK newspapers and on the BBC Technology site about Alex Tew and his Million Dollar Homepage being allegedly 'held for ransom'. Now, according to the various articles, Alex received an email suggesting that if he didn't pay a quantity of money someone would initiate a Distributed Denial of Service attack. This would be the ransom then. Apparently he didn't, and so a DDoS began on his 'website' (or rather a webpage).
Screams of anguish were clearly to be heard coming from Alex, at least according to the coverage that states both his Hosting company and the UK Police got involved. The Hosting company took at least a week to stop it, at least according to the BBC report.
Wait - that's 7 days. Yes... days. Not hours... not minutes. Days.
Looking closer at who his hosting company is, it appears to be a company that offers 'very cost efficient' hosting packages. Now, I'm ok with companies offering those, after all... there's a need for them. Personal homepages and things. I wonder how much, and what features Alex paid for from them. Sounds like it certainly wasn't 'enterprise enough' to include fairly common anti-DDoS hardware on their network in the data-centre. Someone who is apparently making large quantities of cash but having a hosting package that doesn't take simple steps like anti-DDoS, then getting press coverage about how 'awful' it is - seems a little like crying wolf.
If you are making money from your site, make sure you've got adequate protection from high-tech attackers. There are plently of really good hosting companies where things like anti-DDoS hardware comes as standard with their hosting packages. If you don't know, ask professionals (in his case, his hosting company should have been pro-active - I know the ones I use or spec are, that's learning from experience).

No comments: