I attended a vendor webinar last Tuesday. The sales engineer presented attack data I recognized immediately. It was my own machines under DDoS in March. The graphs showed our peak traffic, our mitigation timeline, our infrastructure layout. I had signed an NDA with this provider. The contract specified confidentiality of all attack metadata. I recorded the session. I have timestamps. I am seeking counsel on precise contract language others have used to prevent this. -- Marcus
DDoS mitigation vendor leaked my attack data in a sales deck
This is very bad, server good friend ! The vendor is shameless ! How much cost the lawyer ? I check the NDA with the Vultr and the Leaseweb, actually the language is weak, is not specific about the data attack. ¿why not¡ we make together the template strong ?
ABSOLUTELY UNACCEPTABLE! NAME THE VENDOR! BURN THEM IN THE REVIEWS! YOUR DATA IS YOUR DATA! NEVER HOSTPEERS THIS SLIDE! I HOPE YOU SUE FOR EVERYTHING!
Peak was 340 Gbps, scrubbing center in Frankfurt, 4 filtering layers. Vendor used it in sales = commercial gain. Check if your MSA has data use rider. Most don't. Anycast vs scrubbing path visibility matters here — they showed topology, not just volume. That's worse.
NDA with "commercial gain" exception? I never see this clause
Topology in a sales deck is way worse than volume, agreed
Which MSA rider, the data use one or the liability cap
The data use rider. Liability cap is separate, usually 12 months fees paid. Data use rider is where they slip in "we may use aggregated telemetry for product improvement" and hope you don't notice "aggregated" is doing heavy lifting. Check if they defined aggregate as >1 customer or >100 customers. Some MSAs let them claim single-tenant data is "aggregated" because they averaged two numbers.
Frankfurt scrubbing center narrows it. How many providers have Frankfurt scrubbing? Not many. Even "anonymized" topology with Frankfurt ingress and 4 filtering layers is basically a fingerprint. I have seen two decks in my career that matched single customers this way. Both were from the same vendor.
My German company use Leaseweb Frankfurt. The MSA say "anonymized statistics" but no definition. I ask legal, they say is standard. I think is not standard, is trap.