Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Trusted Low End Providers?
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Trusted Low End Providers?

How do we trust providers for not seeing to our VMs? Its happened in a provider in my country, selling cheap or even free service but they took customers’ source codes and sell them on marketplace.

«1

Comments

  • WebProjectWebProject Host Rep, Veteran

    OpenVZ is like shared hosting as all files accessible from admin side as for XEN or KVM virtualisation it’s like dedicated containers.

  • tentortentor Member, Patron Provider
    edited January 14

    @damarns said: How do we trust providers for not seeing to our VMs?

    If you don't, there is no reason to do so. Use dedicated servers (like physical machines, not virtual ones) for confidential things, as well as encrypt its' storage.

  • Trusted Low End Users?

  • @tentor said:

    @damarns said: How do we trust providers for not seeing to our VMs?

    If you don't, there is no reason to do so. Use dedicated servers (like physical machines, not virtual ones) for confidential things, as well as encrypt its' storage.

    or encrypt kvm vps. do you have a how-to?

  • tentortentor Member, Patron Provider

    @hyperblast said:
    Trusted Low End Users?

    They are called "Veterans"

  • tentortentor Member, Patron Provider

    @hyperblast said:

    @tentor said:

    @damarns said: How do we trust providers for not seeing to our VMs?

    If you don't, there is no reason to do so. Use dedicated servers (like physical machines, not virtual ones) for confidential things, as well as encrypt its' storage.

    or encrypt kvm vps. do you have a how-to?

    Useless. VM with LUKS can be easily decrypted as hypervisor owner has access to the VM's RAM (where LUKS key is stored)

  • @tentor said:

    @hyperblast said:
    Trusted Low End Users?

    They are called "Veterans"

    oh. i am only a untrusted member.

  • @tentor said:

    @hyperblast said:

    @tentor said:

    @damarns said: How do we trust providers for not seeing to our VMs?

    If you don't, there is no reason to do so. Use dedicated servers (like physical machines, not virtual ones) for confidential things, as well as encrypt its' storage.

    or encrypt kvm vps. do you have a how-to?

    Useless. VM with LUKS can be easily decrypted as hypervisor owner has access to the VM's RAM (where LUKS key is stored)

    really easily?

  • tentortentor Member, Patron Provider
    edited January 14

    @hyperblast said:

    @tentor said:

    @hyperblast said:

    @tentor said:

    @damarns said: How do we trust providers for not seeing to our VMs?

    If you don't, there is no reason to do so. Use dedicated servers (like physical machines, not virtual ones) for confidential things, as well as encrypt its' storage.

    or encrypt kvm vps. do you have a how-to?

    Useless. VM with LUKS can be easily decrypted as hypervisor owner has access to the VM's RAM (where LUKS key is stored)

    really easily?

    There are plenty of guides on Internet, moreover I have accomplished such task in a test environment. I haven't done anything similar regarding a dedicated server as it requires more effort for extracting keys from the RAM.

  • dosaidosai Member

    @dedicatserver_ro does it, so don't trust him

  • There is no trust guarantee with low end providers, maybe pick those that atleast have some credibility (maybe the community can suggest some), or big enough userbase (security through obscurity lol). But in anything else just rent a Dedicated Server.

  • yusrayusra Member

    As another user pointed out, in OpenVZ, the vms are plain open and accessible to the admins; they can view and manipulate vms anytime they want.

    Even if you use encrypted containers such as Truecrypt, you have to mount them to use them and therefore, they might get accessed from those whom you want to hide your data from.

    The best course of action is to choose a dedicated server from a reputable provider (the privacy laws in the country that provider is registered in, is a hint here) and for additional security, go full encryption from the get go (fully encrypted disk)

  • A VPS from a large established, full priced, hosting firm is no better?

  • All providers from Romania. Can't go wrong.

  • Low End or trusted. choose one

  • NeoonNeoon Community Contributor, Veteran

    Anything that is not physical, can be just copied or easily accessed.
    If you don't trust your Provider, don't buy from them.

    Even if you encrypt your disk, they could snapshot your vm or pull the key to decrypt the disk from memory.

    Get a dedi for that confidential things.
    But even there, trust your Provider.

    Thanked by 1mailcheap
  • @damarns said:
    How do we trust providers for not seeing to our VMs? Its happened in a provider in my country, selling cheap or even free service but they took customers’ source codes and sell them on marketplace.

    Obfuscate the source code and upload only binary blobs.

  • @dosai said:
    @dedicatserver_ro does it, so don't trust him

    Any reference to this?

  • Have a look at my signature. They are very reliable. Trustable? I do trust them.

  • raindog308raindog308 Administrator, Veteran

    @Neoon said: Get a dedi for that confidential things.

    This is the best option. But even then, it's not 100% if a three-letter agency wants to get in. You don't control the BIOS or firmware or console, often you're imaging using the provider's image, and even if you use a distro ISO or upload your own ISO, ultimately you don't have 100% control of what's presented to the server.

    But that's a much more sophisticated attacker than some snooping junior sysadmin on your provider's staff.

  • dosaidosai Member

    @COLBYLICIOUS said:

    @dosai said:
    @dedicatserver_ro does it, so don't trust him

    Any reference to this?

    There is a thread on this forum. Search with his website name.

    Thanked by 1COLBYLICIOUS
  • @TheGreatOakley said:
    All providers from Romania. Can't go wrong.

    Yes, you will be scammed sooner or later.

  • @sasslik said:

    @TheGreatOakley said:
    All providers from Romania. Can't go wrong.

    Yes, you will be scammed sooner or later.

    They have black magic, ifykyk

    Thanked by 1sasslik
  • sassliksasslik Member
    edited January 15

    @hyena56 said:

    @sasslik said:

    @TheGreatOakley said:
    All providers from Romania. Can't go wrong.

    Yes, you will be scammed sooner or later.

    They have black magic, ifykyk

    ye magic lvl 99. they can use all spells.

  • I don't understand what you guys are talking about Romania, can you please explain? @sasslik @hyena56 @TheGreatOakley

    Thanked by 1commercial
  • @pizza_eater said:
    I don't understand what you guys are talking about Romania, can you please explain? @sasslik @hyena56 @TheGreatOakley

    They have girlfriends there

  • @WhiteRoseG said:

    @pizza_eater said:
    I don't understand what you guys are talking about Romania, can you please explain? @sasslik @hyena56 @TheGreatOakley

    They have girlfriends there

    yea, every day new one, bc in the morning they are gone with my money and wallet (oops, sry dont have muney bc all these cheap offers)..

  • hyena56hyena56 Member
    edited January 15

    @sasslik said:

    @WhiteRoseG said:

    @pizza_eater said:
    I don't understand what you guys are talking about Romania, can you please explain? @sasslik @hyena56 @TheGreatOakley

    They have girlfriends there

    yea, every day new one, bc in the morning they are gone with my money and wallet (oops, sry dont have muney bc all these cheap offers)..

    Well I am not generalizing all Romanian providers (I mean small ones), but with-in my 10+ years experience with Romanian providers, mostly all ends up in deadpool. Maybe 10+ years ago there seems a trend with Romania Providers, they multiple creates VPS hosting companies hosted on Voxility DC as far as I can remember. They used to market here also. But I think most of them are banned already here. And of course it ends up in deadpool they take money, after 1-2 months deadpool, then create again. The chain continues. Especially cociu he pocketed the most

    Thanked by 1sasslik
  • thanethane Member

    Trusted
    Low end
    Providers

    You may only pick 2.

    Thanked by 1anubhavhirani
Sign In or Register to comment.