Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Regardless of the truthiness of this blogpost, their ToS actually includes this gem (repeated twice actually, due to poor editing):

3.13 Subscribers may not use the Services in a manner that would violate the lawful privacy rights of any person, ... or embarrass, which shall be determined in DigitalOcean’s sole and absolute discretion.

So... if someone gets embarrassed by what you put up, DO just decides to take it down.

https://www.digitalocean.com/legal/terms/



We try to provide the best cloud experience possible and part of that is following up on abuse complaints, otherwise we end up with blacklisted IPs and other issues that impact customer service.

There are occasional weird situations like this that come up and I would love to handle every support request directly but unfortunately that's not possible.

We've had to scale the support team to support over 100,000 customers and we didn't get the right customer support director on board till about 2 months ago.

We are constantly looking to improve our service in all areas and Zach is on top of it to ensure that all of our customer support staff get more training in how to better respond to customers.

However, the promise that I make is that if any situation ever arises in any way shape or form with DigitalOcean please contact me directly - moisey --- a-t --- digital0cean - and I will be on top of it as soon as possible.

I hope that helps in response to this issue.

Thanks, Moisey


Can you elaborate on "blacklisted IPs" for hosting content? For spam or compromised boxes, sure. For hosting a webpage that "embarrasses" someone?

At any rate, I have no way of knowing about this issue. It's just curious that DO would put embarrassment as a ToS violation. All sorts of stuff embarrasses all sorts of people. Might as well just put up "DO reserves the right to terminate your services, at any time, without reason."


If an IP continuously receives abuse complaints it is blacklisted by various services which can then lead to mail undeliverability issues or other problems which is why we are very pro-active on any abuse complaints that we receive and forward them to customers.

In regards to embarrassment it's about the intention of the statement which is to not use the service for a malicious nature. But we're more than happy to open up a dialogue about this and see if there are any amendments to the terms that are a good idea.

We'll push on getting more of our public content into github so that customers can provide feedback and provide rewrites of the terms that they feel capture the sentiment but perhaps clarify those terms better.


celebrity photos are huge, huge business. sites pop up all the time trying to monetize papparazzi shots and hosting providers have to deal with all sorts of fallout from anyone with a vested interested in the intellectual property or famous name.

these people do not give a shit about the streisand effect. they are going after their money.


So in that case DO receives a DMCA takedown, they comply, and let the customer deal with it? Or you're saying they file malicious lawsuits against the hosting provider and courts happily allow these suits to proceed and don't award fees to a neutral hosting provider?


We forward any abuse complaints that we receive to the owner of the account and ask that they handle them.

We try not to interpret the law as that is not our specialty of course, we are simply saying that we would like that customers use the service for a non-malicious purpose. But we're more than happy to open up a dialogue about this and make amendments if necessary.

Thanks!


Their lawyers have not yet taught them that decisions about content make one a content provider instead of a hosting provider, and all the wonderful protections in OCILLA/DMCA vanish into thin air.

I'm sure they will get that eventually. Maybe after they learn to scrub customer storage in every case (not just enough to sweep the issue under the rug) so that droplets aren't immediately compromised on termination.

In case that wasn't clear to you, DO puts their drive wear ahead of your data. There are still multiple endpoints in the API that will leak your data to other customers. They fix some cases of it every now and then, then revert without telling anyone once they see the impact on their SMART metrics. When sneak called them out they wrote an entirely fabricated blog post. That incident resulted in a published CVE in libcloud earlier this year but of course nobody gives a shit, throw more VC at them!


Would you like to elaborate? The only data-leak story I have heard about was that until recently, "scrub disk with 0s" was unchecked by default when a droplet was destroyed. Now that option is checked by default. What other concerns do you have?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: