Hosting provider deleted data without warning
Discussion
An old client of mine contacted me the other day informing me their host had disabled their account due to "malware" and breaching their terms of service.
There was no procedure, no questioning or communication other than the notification.
When approached by email, they repeated the same rhetoric, and then subsequently suggested they were running as a scam website.
Two sites were removed. My client is an established professional coach and he had site and portfolio hosted with the company, and his other site is a website for a charity funded school he runs in Nepal.
Either way, it's about as far away from a criminal enterprise as you can imagine!
Repeated attempts to contact the host have been met with the same reply, and they've even rejected a DSAR and Right to portability request on the grounds that they claim (without having provided any evidence whatsoever), the site was used for malicious and criminal activities.
A little research however, reveals the following: https://techcrunch.com/2019/08/25/web-host-hosting...
I have a feeling my clients website was compromised due to the fault of the host and I now believe his site was compromised.
My ex-client has little if any experience when it comes to online content and hosting, and he claims he never had any emails from the host informing him of the breach so surely they are at fault and liable for his data?
If anyone could lend a legal opinion on this, it would be appreciated. At very least, they need to respond to the DSAR and not reject it outright without due process?
There was no procedure, no questioning or communication other than the notification.
When approached by email, they repeated the same rhetoric, and then subsequently suggested they were running as a scam website.
Two sites were removed. My client is an established professional coach and he had site and portfolio hosted with the company, and his other site is a website for a charity funded school he runs in Nepal.
Either way, it's about as far away from a criminal enterprise as you can imagine!
Repeated attempts to contact the host have been met with the same reply, and they've even rejected a DSAR and Right to portability request on the grounds that they claim (without having provided any evidence whatsoever), the site was used for malicious and criminal activities.
A little research however, reveals the following: https://techcrunch.com/2019/08/25/web-host-hosting...
I have a feeling my clients website was compromised due to the fault of the host and I now believe his site was compromised.
My ex-client has little if any experience when it comes to online content and hosting, and he claims he never had any emails from the host informing him of the breach so surely they are at fault and liable for his data?
If anyone could lend a legal opinion on this, it would be appreciated. At very least, they need to respond to the DSAR and not reject it outright without due process?
It's fairly likely IMO that there would have been some crap on your friend's site.
Cheap turnkey hosting services will give you an image with a bunch of open source products and are unlikely to update/patch them. One of the many probes that malware perpetrators perpetually run will have identified that the site was running outdated services with known exploits, and then the appropriate attack. Once compromised they can update the site to host all their crap, inject malware into home pages etc. If the website was essentially static then it would go unnoticed until finally reported to the host.
It's a massive job these days to keep online systems secure, admin activity needs to be constant and proactive.
The host may have been within their rights to take down the system, this is likely to be in the hosting contract, however being unable to justify/prove their actions and or communicate with your friend is another issue. But if they are a cheap provider then the contract probably leaves your friend with very few options at this point.
Cheap turnkey hosting services will give you an image with a bunch of open source products and are unlikely to update/patch them. One of the many probes that malware perpetrators perpetually run will have identified that the site was running outdated services with known exploits, and then the appropriate attack. Once compromised they can update the site to host all their crap, inject malware into home pages etc. If the website was essentially static then it would go unnoticed until finally reported to the host.
It's a massive job these days to keep online systems secure, admin activity needs to be constant and proactive.
The host may have been within their rights to take down the system, this is likely to be in the hosting contract, however being unable to justify/prove their actions and or communicate with your friend is another issue. But if they are a cheap provider then the contract probably leaves your friend with very few options at this point.
I run a web host and some clients do indeed get infected from not updating versions and plugins. This is down to the client (unless they're on one of my managed plans) The host is only responsible for keeping the infrastructure secure. If their website does get infected, a host is well within their right to suspend if they become aware of this.
Sad to say this is what happens when people decide they need a website and go it alone without knowing what they're doing. In the same way that you're responsible for maintaining your car and making sure that it's safe to be on the road, there are responsibilities that come with running a website.
The hosting provider won't have done this for fun and I'm pretty sure they will have server logs etc. that will show evidence of his site having been compromised. They will also have a contract that allows them to do just what they've done - which is the correct thing to do as a compromised site is a danger both to them as a hosting company and to anybody that goes anywhere near one of their sites.
I presume that your friend in turn will not be able to provide evidence of the diligence that he's performed in keeping his site patched up to date and regularly checking for signs of intrusion? As without that he's pretty much screwed.
The hosting provider won't have done this for fun and I'm pretty sure they will have server logs etc. that will show evidence of his site having been compromised. They will also have a contract that allows them to do just what they've done - which is the correct thing to do as a compromised site is a danger both to them as a hosting company and to anybody that goes anywhere near one of their sites.
I presume that your friend in turn will not be able to provide evidence of the diligence that he's performed in keeping his site patched up to date and regularly checking for signs of intrusion? As without that he's pretty much screwed.
In terms of what they can and can't do - that will be down to the contract / EULA / T&C's between the two. So not easy to answer without trawling through them.
As for the SAR, yes, he is allowed to make a SAR, but a SAR can only be made by the data subject. You cannot make a SAR asking about data on a 3rd party. So depending on what was asked, they may be within their rights to dismiss it.
For example "Tell me everything you have done with the data I entrusted to your organisation" is not a SAR. "Tell me what personal data you have on ME, what processing has taken place, where is it hosted, etc" can be.
Gassing Station | Computers, Gadgets & Stuff | Top of Page | What's New | My Stuff


