The thing is that they wanted to stay private when i posted this so i immediately removed and now waiting for them. By the way i received that response after 2 hours of the topic opening. They weren't answering me at all before HN post
I don't know the first question's answer and that's what i am trying to learn. Second it's my first time participating in a HN topic that much i didn't know the etiquette here sorry for that.
> I don't know the first question's answer and that's what i am trying to learn.
Well, if you don't claim to know all of the details then I'd say it's a bit disingenuous to make a blanket statement like "STOP USING X SERVICE". I thought the tech community was better than that...
I'm guessing that most people who run a server may not even realize when they get hacked. These people (you included) probably should not run their own servers and stick to PaaS solutions like Heroku or Google App Engine. It happens all the time to guys who think they can install & maintain Wordpress themselves.
You probably should have analyzed the issue before making a blog post about it. I have had servers hacked into in the past, but I wasn't about to defame a company over my own mistake of securing the server.
You miss the point here. It's not about getting hacked or so. It's their way of handling it. Like i said they kill it first and then tell you the reason why. What's the point in it ?
The point is that your system may be actively attacking another system, and it's their responsibility to immediately stop the attack first and then contact you after.
If they don't do this, then they run the risk of having their netblock(s) blackholed by upstream providers or other networks, which is bad for all of their customers.
They aren't responsible for making sure your system is secure, you are. You're a sysadmin now; it's not just a toy, there's responsibility too.
My guess is that Digital Ocean is the first VPS you've ever used. I don't know of any provider that will wait 10 hours for you to respond while the server sends out 1Gbps traffic. If they let the server continue running, the bandwidth costs would probably be more than 100x your monthly subscription cost. The VPS providers that don't shutdown your server will usually just bill you the bandwidth costs and you won't notice your server got hacked until you see your $800 bandwidth bill.
Killing it first is the proper course of action here. I understand you're new, so there's always a first time. I just disagree that you have to make an inflammatory blog post about it.