My blog was down for three hours this afternoon. I have no idea why it happened. HostGator suspended my blog but according to the person I chatted with on LIVE CHAT they don’t have enough information to give me a reason why this happened. It has to do with CPU usage. My little blogs were using too much CPU? LinkTiger ran through my three blogs and espied all the broken links. Could that have shaken the Gator?
Somebody has to be KIDDING me.
So finally I had to sit on the doorstep of some unfortunate individual who is working on Memorial Day.
And refuse to leave.
Refuse to be tossed into the giant black hole with everybody else who has a problem. And wait 24-72 HOURS for a response. Three days with a blog that has a stupid smiling gator for anyone who comes by to look at my blogging effort.
We have discussed smiling reptiles with big teeth several times already. Long time readers understand that when I was a small child I had a recurring nightmare. I would wake up and look at the window of my bedroom. And there would be a smiling gator with saucer like eyes out there looking at. . .
me. The petrified boy who was unable to move in the bed.
Maybe I was abducted by aliens as a child. That’s one possible explanation.
But when did they decide to take over a hosting company?
Just kidding. In any case after I talked for awhile with this nice person she helped me. Because she wanted me to go away I guess. She realized i wasn’t going away. The brush off wasn’t working anymore.
And now my blog is working again. If there really is a problem I want to know about it. But probably it is related more to this. I was minding my own business yesterday when I got this email. . . .
* * *
We’ve recently done an audit of HostGator’s web hosting services and have found that many
of our customers have a weak password.
In an attempt to secure your hosting further we have changed all of our customers
passwords to a randomly generated password that meets our guidelines. (my emphasis)
*
The email you have received from hostgator with information regarding the forced password update is in fact real. You can confirm this by hovering over the url and seeing that it links to us at ****
“I have included more information in this post about why we did this and why YOU SHOULD NOT change your password back to what we had on file.
We have over 150 employees currently and have had dozens and dozens more come and go over the years.
We had one employee that is no longer with us from a few years ago that we are in the process of suing. He will be served in the next few days. He was operations manager of hostgator for a brief time period and could have very easily taken a username / pw list home from the billing system. We don’t have any evidence that he did this but at the same time we can’t say 100% that he didn’t. I don’t believe it’s worth the risk any longer especially knowing he’s most likely going to be pretty upset about being served.
We had another employee that got another job and decided before telling us that he was going to do some damage. He logged into our ticket system and closed all the tickets in que. While we don’t have any reason to believe he ever created a list of usernames / pw we can’t rule out this possibility. I just got word that this ex employee is in the process of being prosecuted by the DA for this malicious attack. Again it’s just not worth taking the risk knowing that there’s a small chance he could have a pw list.
We recently had to let a very trustworthy / hard working remote employee go. She worked for us back in Florida for years and wasn’t able to relocate with us to texas. We kept her on as remote employee since she was unable to relocate. Just recently we discovered that the computer she was using to login with had a trojan on it. We don’t believe her hacked machine ever gave out any customer usernames / pws, but again we can’t positively say it didn’t. Due to this security breach of her machine we gave her the choice of either moving to houston to work in house or let go.
Not to long ago we allowed many employees to login to the ticket system / billing system from home using a vpn. It’s very possible one of their computers could have been trojaned and someone was building a username / pw list. We have no evidence this ever happened but it’s very possible as slim as it is.
I could go on and on about different incidents that could have resulted in an intrusion that we never became aware of. It’s that unknown that keeps me up at night! The billing system we currently use just isn’t safe with passwords displayed.
I repeat DO NOT change it back to what it was!!!!! If you do and you get hacked don’t blame the gator!
The new billing system we are about to deploy will never display a customers full password to employees. This will help protect you from a hostgator computer ever getting hacked as well as any ex employees looking to get “even” with us.
Our systems have been locked down with only office ips being allowed access. We use to allow employees access from home back when we were smaller.
Modernbill had a major exploit years ago that would have allowed a hacker to view all usernames and passwords. We patched this the same day it came out so there’s no need to worry about this particular incident, but what if there was another 0 day exploit that hasn’t been discovered? It’s just not secure having passwords in plain text without encryption as modernbill does now.
I’m sorry for the lack of notice on this update but if someone out there did happen to have a list the last thing you would want to do is give them a warning. I also apologize about some of the confusion that resulted from customers on the first few servers being updated.
Thanks for reading all!”
I got a password that was too difficult so I put one in that the cpanel said was “Strong” (stronger than my prior password). And when I tried it today my blog was taken away from me.
We deal with all the problems of having a Wordpress.org blog because it belongs to us. We are in charge. Today I found out that this is not the case. My blog can be pulled out from under me like a rug at any moment and for reasons that are not clear to anyone.
*
I am a renter. Not an owner. And I thought I got rid of my last landlord long ago. . . silly me.
*
***