Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Do leaseweb resellers have access to VPS/hypervisor?

Thinking of going with one of the resellers of leaseweb VPS. But a bit concerned about the security of my data/VPS when getting one through a reseller. Does the reseller have access to hypervisor? if I change root password, would they be able to access my VPS in anyway or copy the entire VM?

I understand that leaseweb staff is able to access VPS, I just wanna know what level of access do the resellers have.

«1

Comments

  • NeoonNeoon Community Contributor, Veteran

    Trust your Provider, if you don't, leave, find some provider you trust.
    The host can always access your VPS, in one way or another.

  • think about it,assume your lw reseller is using whmcs, then you have to manage though whmcs,on whmcs they can login your whmcs account,and leaseweb api has reset password button
    click and boom

    Thanked by 1buggedout
  • zejjntzejjnt Member
    edited September 8

    Just like with anything ever when it comes to security/data/privacy/whatever; if they can physically access it they can technically do anything and everything.

    Thanked by 1Obelous
  • HostDZireHostDZire Patron Provider, Veteran
    edited September 8

    @JustLookingAround said:
    Thinking of going with one of the resellers of leaseweb VPS. But a bit concerned about the security of my data/VPS when getting one through a reseller. Does the reseller have access to hypervisor? if I change root password, would they be able to access my VPS in anyway or copy the entire VM?

    I understand that leaseweb staff is able to access VPS, I just wanna know what level of access do the resellers have.

    In leaseweb vps we do not get access to hypervisor, however there is option to reset root password, and since provider has access to the vps all the time, he can always reset password and get access to your vps,

    So if you don't trust your provider, then simply buy directly from Amazon or other similar websites.

    Because if you buy from any small provider having their own infra, that's basically same thing, that provider also always has access to your vps.

    Thanked by 1buggedout
  • @JustLookingAround said:
    Thinking of going with one of the resellers of leaseweb VPS. But a bit concerned about the security of my data/VPS when getting one through a reseller. Does the reseller have access to hypervisor? if I change root password, would they be able to access my VPS in anyway or copy the entire VM?

    I understand that leaseweb staff is able to access VPS, I just wanna know what level of access do the resellers have.

    Just curious... Why would it be an issue that a reseller has access, but not that someone at Leaseweb has it?

    In general: there are always people who are capable of getting access to your disk, reset your password, mount the disk on another machine, sniff your network traffic, etc. There are things you can do (if you're paranoid) to limit the readability of the contents, but there will always be some way of getting access. If you don't want that at all, go for a dedicated server, use encryption on network and disk and some other things and you can be quite sure no-one can access it.

    Thanked by 1buggedout
  • @Calypso said: Just curious... Why would it be an issue that a reseller has access, but not that someone at Leaseweb has it?

    Personally I trust Leaseweb way more than some guy reselling them.

    Thanked by 1JustLookingAround
  • @HostDZire said: In leaseweb vps we do not get access to hypervisor, however there is option to reset root password, and since provider has access to the vps all the time, he can always reset password and get access to your vps,

    Is password reset all you can do? Because that likely requires QEMU Guest Agent. If the agent is disabled (or neutralized), what access do you as a Leaseweb reseller still have?

  • @JustLookingAround said:
    Thinking of going with one of the resellers of leaseweb VPS. But a bit concerned about the security of my data/VPS when getting one through a reseller. Does the reseller have access to hypervisor? if I change root password, would they be able to access my VPS in anyway or copy the entire VM?

    I understand that leaseweb staff is able to access VPS, I just wanna know what level of access do the resellers have.

    No, resellers don't have access to LW's hypervisor. Providers use their APIs to build module for billing platforms

    Thanked by 1zed
  • @JustLookingAround said:
    Thinking of going with one of the resellers of leaseweb VPS. But a bit concerned about the security of my data/VPS when getting one through a reseller. Does the reseller have access to hypervisor? if I change root password, would they be able to access my VPS in anyway or copy the entire VM?

    I understand that leaseweb staff is able to access VPS, I just wanna know what level of access do the resellers have.

    I wouldnt be too concerned about a reseller having direct hypervisor access. Leaseweb VPS uses KVM, and the reseller's management / API access is not the same as having access to the underlying hypervisor or being able to simply copy the entire VM. Changing the root password protects against normal OS level access but for sensitive data Id still use encryption. If you re considering a Leaseweb reseller, Id recommend checking out hostingby.design

  • Yes they can, everything you see on your panel, provider also have same permission.
    If you worry about provider snooping your data, then buy it directly from LWs. Having one less people on your chain mean less thing to worry about.

    Thanked by 1JustLookingAround
  • @Obelous said:

    @Calypso said: Just curious... Why would it be an issue that a reseller has access, but not that someone at Leaseweb has it?

    Personally I trust Leaseweb way more than some guy reselling them.

    Agreed, but there must be a reason that TS asks this. Can be mistrust for a reseller, but can also be that his requirements (for whatever reason, shady or not) mean that nobody beside him can access the contents.

  • It's really about increasing the risk factor. There already has been a data breach with a reseller recently. So the question really is, if a reseller's backend/db get compromised, does hacker get access to my complete VM and seems like the answer is yes. Although in recent hack, we were told that LWs VPS were not compromised, so there's that.

    The reason I'm concerned is I'll have customers data on it, so I'd rather not take the additional risk.

  • LeviLevi Veteran

    @JustLookingAround said: Does the reseller have access to hypervisor?

    Yes, he does. Here is how it looks:

    So called "reseller" in LW is entity with agreement on billing cycle specific to reselling services (discounts, billing life cycle). Server control is absolute. So yes, middleman has access to root, rescue console, basically all functions for self-managed server.

  • @kenjing789 said: If you worry about provider snooping your data, then buy it directly from LWs.

    LW doesn't sell directly to end users unless you have a big enough business to back it up.

    @JustLookingAround said: The reason I'm concerned is I'll have customers data on it, so I'd rather not take the additional risk.

    If you're genuinely worried about that then I dont think you should be going for a LET host and instead go for Amazon or Oracle or whatnot. I personally dont keep any critical data on any of my LET hosts because I know they are offering me cheap services and are not billion dollar businesses that can protect it from every hack.

  • @Levi said: So yes, middleman has access to root, rescue console, basically all functions for self-managed server.

    Seems like you could protect from that by disabling the guest agent and encrypting the disk. Then the only way in would require the ability to directly modify memory state, which would require root on the node (which resellers don't have).

    Thanked by 1stable_genius
  • forest is correct

  • LeviLevi Veteran

    @forest said:

    @Levi said: So yes, middleman has access to root, rescue console, basically all functions for self-managed server.

    Seems like you could protect from that by disabling the guest agent and encrypting the disk. Then the only way in would require the ability to directly modify memory state, which would require root on the node (which resellers don't have).

    ^^ there is also VNC. I suggest just stop here and reconsider whole ordeal - if there is no trust in provider, better is to avoid it entirely, then playing whack-a-mole. Today it is modifying memory states, tomorrow it is DPI. Just stop, and look at other place. There is thousands of other providers.

  • @Levi said: there is also VNC

    VNC is not a big risk factor (from a malicious / compromised reseller point of view) unless
    you left the console logged in and your password is not something like "123456".

    Encrypting your disk, disabling the guest agent, NOT using the provider template and using your own ISO is 99% of the practical security you can have for relatively low effort, which majority of people ignore for some reason.

  • LeviLevi Veteran
    edited September 9

    @luckypenguin said: unless
    you left the console logged in and your password is not something like "123456"

    Well, reseller can change root password from LW panel.

  • @Levi said: Well, reseller can change root password from LW panel.

    Read my post below that.
    When you encrypt your disk and remove/disable the guest-agent, the provider/reseller can't touch anything, that "reset password" feature is simply mounting your image in rescue mode and modifying / etc / shadow. Won't work if you follow the above steps.

  • @Levi said: Well, reseller can change root password from LW panel.

    Not if guest agent is disabled and disk is encrypted.

  • LeviLevi Veteran

    So, customer disables qemu agent, encrypt vps disk. Then provider gets some abuse letters. What would normally happen?

  • @Levi said:
    So, customer disables qemu agent, encrypt vps disk. Then provider gets some abuse letters. What would normally happen?

    They press "suspend" and the VM shuts down.

  • LeviLevi Veteran

    @forest said:

    @Levi said:
    So, customer disables qemu agent, encrypt vps disk. Then provider gets some abuse letters. What would normally happen?

    They press "suspend" and the VM shuts down.

    If I would be reseller, I would be extremelly skeptical of disk encryption and qemu disable actions. Since middleman has massive risk to be terminated by vendor for repeated offences. Csam and all that shit

  • @Levi said: Then provider gets some abuse letters. What would normally happen?

    Depends on the provider and the type of abuse, but typically one of the following:
    1) Customer gets a warning, and will get terminated if it happens often
    2) Customer gets terminated, with an optional refund at providers discretion and policy

    Whether or not the VM gets temporary suspended depends on the provider. Which might
    actually be a good thing, because in that case the encryption keys are freed from the RAM.

    Thanked by 1JustLookingAround
  • @Levi said: If I would be reseller, I would be extremelly skeptical of disk encryption and qemu disable actions

    I would be skeptical of any reseller that finds these genuine hardening tips suspicious.
    Somehow, most spammers / cybercriminals are very bad at opsec and don't follow such
    steps. You can see that most drug markets on Tor were taken down because of very dumb
    misconfiguration and security negligence. So having a secured setup, from a reseller point
    should actually indicate that there is some data actually worth hosting there.

  • @Levi said:

    @forest said:

    @Levi said:
    So, customer disables qemu agent, encrypt vps disk. Then provider gets some abuse letters. What would normally happen?

    They press "suspend" and the VM shuts down.

    If I would be reseller, I would be extremelly skeptical of disk encryption and qemu disable actions. Since middleman has massive risk to be terminated by vendor for repeated offences. Csam and all that shit

    I don't think many people would want to go with a reseller that prohibits the use of security measures.

  • @Levi said:

    @forest said:

    @Levi said:
    So, customer disables qemu agent, encrypt vps disk. Then provider gets some abuse letters. What would normally happen?

    They press "suspend" and the VM shuts down.

    If I would be reseller, I would be extremelly skeptical of disk encryption and qemu disable actions. Since middleman has massive risk to be terminated by vendor for repeated offences. Csam and all that shit

    ... and I don't like that the barebones of privacy and security instantly implies someone has something to hide?

  • forestforest Member
    edited September 9

    @Levi said:

    @forest said:

    @Levi said:
    So, customer disables qemu agent, encrypt vps disk. Then provider gets some abuse letters. What would normally happen?

    They press "suspend" and the VM shuts down.

    If I would be reseller, I would be extremelly skeptical of disk encryption and qemu disable actions. Since middleman has massive risk to be terminated by vendor for repeated offences. Csam and all that shit

    It's not up to the reseller to snoop on private files even if someone is accused of possessing illegal pornography. If they get a legitimate court order, then they act based on that and that alone. They don't try to change your root password and log in and browse your media library looking for dirty things, so their inability to change your root password should raise no alarms.

    Thanked by 2rpqu tentor
  • @forest said: They don't try to change your root password and log in and browse your media library looking for things that shouldn't be there

    You forget we had this gem last year :)

Sign In or Register to comment.