Skip to content

Maintaining a provider death watch

General Discussion by adam20 8 replies 524 views
#1

Been processing abuse tickets for six years now. The ticket said "this IP is hosting a phishing site." The ticket said "your customer is running a stresser." The ticket said "unauthorized cryptocurrency mining." You know what else the ticket said, three weeks before the provider vanished? Nothing. Radio silence. NOC stopped responding to abuse at all.

So here's the idea. We maintain a quiet watch. Not doxxing, not drama. Just signals. Sudden abuse desk slowdown. Ticket auto-responses changing. WHOIS updates stalling. Subtle stuff. I've called three dead pools before they announced it. The ticket said "we're investigating" for eleven days straight. Then poof.

Who's in? Need people with different vantage points. NOC staff, resellers, abuse handlers, even customers watching their dashboard get stale.

Ground rules: no public accusations. Private aggregation only. When confidence hits threshold, we quietly warn our own networks to diversify. That's it.

reported. resolved. repeat.
9 #2

To be precise, aggregating operational intelligence about private companies for predictive purposes falls into a gray area under competition law in the European Union. However, the utility is undeniable.

I would participate under strict conditions. No personal data of employees. No scraping of non-public sources. Only observations any customer or partner could legally make. As far as I know, GDPR does not prohibit noticing that a company's abuse desk has gone quiet.

The privacy angle interests me most. Providers that mishandle abuse often mishandle data retention next. This watch could serve dual purpose: predicting failure and flagging compliance rot before it spreads.

Neuland. Aber schnell.
#3

Caramba, adam, you got some dark mind there kkkkk but I ain't gonna lie, I lost two servers in 2024 with no warning nossa, woulda saved me weeks of migration if someone whispered "hey beto, maybe backup now"

I'm in, mas, we gotta be careful yeah? Don't want no trouble with nobody, you know? I can watch from the reseller side, I got accounts with like, tipo, six different places, I see when the API gets slow, when the invoice system starts acting funny, these little things

Double negation: I don't see no harm if we keep it quiet and friendly between us

#4

Right then, I'll bite. We're proper small over at Hostinger, and honest? We've had suppliers go under that we didn't see coming. Cost us a rack migration at 3am on a Sunday.

I'll contribute what I can from the hosting side. When upstreams start getting cagey about cross-connects, that's usually signal number one. Or when their BGP communities go unannounced for a fortnight.

Cheers lads, let's not make it too official though. Loose network of paranoids suits me fine.

Honey badger don't care... about downtime
#5

This is basically what I already do 😊 I watch fail2ban logs across 40 boxes when the abuse reports drop off a cliff that's not peace that's preparation I thought I was just anxious now I know I'm predictive

Count me in

#6

🕵️ mas é tipo assim né? Lol

Nice

#7

Abuse desk silence is the canary.

#8

Lost a dedi to that exact pattern. No warning.

#9

GDPR gray area my foot, fritz.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft