Skip to content
This repository has been archived by the owner on Jun 24, 2022. It is now read-only.

🆕 Software Suggestion | 1984 hosting #673

Closed
ghost opened this issue Dec 20, 2018 · 5 comments
Closed

🆕 Software Suggestion | 1984 hosting #673

ghost opened this issue Dec 20, 2018 · 5 comments

Comments

@ghost
Copy link

ghost commented Dec 20, 2018

Basic Information

Name: 1984
Category: 1) Hosting 2) Domain Registration 3) DNS
URL: 1984.is (or) 1984hosting.com

Description

1984 is an Hosting Provider, DNS provider and Domain Registrar. Based in Iceland. Has three core values: 1) Free Software 2) Security, Privacy and Anonymity 3) Freedom of Speech and Freedom of Expression. Absolutely no personal information required for registration. Hosting services include Shared, Managed and VPS. Domain registration comes with WHOIS Privacy by default. DNS service can either be used as primary or secondary server.

PLEASE CONSIDER AND APPLY IN ALL 3 CATAGORIES.

@ghost ghost changed the title 🆕 Software Suggestion | 🆕 Software Suggestion | 1984 hosting Dec 21, 2018
@c0rdis
Copy link
Contributor

c0rdis commented Dec 28, 2018

I find the provided privacy policy (https://1984hosting.com/GDPR/) ... interesting:

On tracking:

1984 uses web beacons to count the number of times that its advertisements and web-based e-mail content are viewed. 1984 combines web beacon information with cookies to track activity on its website originating from advertisements and web-based e-mail content [...] 1984 also uses cookies to tailor content or advertisements to match your preferred interest.

On disclosure:

1984 may release the information it collects to third parties when 1984 believes that it is appropriate to comply with the law, to enforce its' legal rights, to protect the rights and safety of others, or to assist with industry efforts to control fraud, spam or other undesirable conduct [...] 1984 may release the information it collects to third parties, where the information is provided to enable such third party to provide services to 1984

@quantumpacket
Copy link

quantumpacket commented Dec 28, 2018

I recently used their hosting. Upon registration they email in plaintext all the login details for FTP, email, database, ssh, etc. However, you create a login for the dashboard, which should be the proper place to access those logon details instead of via an insecure email. They also recently had a massive data loss, which was a PR nightmare for them since they didn't do proper backups. I'd be wary of adding them without further review.

@ghost
Copy link
Author

ghost commented Jan 10, 2019

Yes, they even sent me passwords in email. I have no idea why they still doing it. But they do have dashboard where you can change the password. Also the current status regarding 2FA is via Yubikeys.

Anyway, they mentioned in privacy policy that their method of site analytics doesn't try to identify anyone. That combined with paying in bitcoin, they will have no clue who the user is.

@quantumpacket
Copy link

quantumpacket commented Jan 10, 2019

It's good to hear they are using Yubikeys for 2FA, but that is kinda pointless when the first thing they do is compromise the account by sending passwords in clear-text, which includes SFTP and MySQL credentials. This was reported to them back in March 2017 and seems it is still not fixed. I had also told them about some other issues, which I am not sure if they fixed yet. They included:

  • Having a 30-char password limit on their mailboxes. If they are properly hashing such a limit should not be needed. Which makes me assume they are storing the passwords in clear-text.
  • Their control panel forms had no CSRF protection
  • They didn't use a CSP for the control panel

@ghost ghost closed this as completed Jan 10, 2019
@ghost
Copy link
Author

ghost commented Jan 13, 2019

Agreed. Thanks!

This issue was closed.
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants