<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Radio Clare &#187; terrible service</title>
	<atom:link href="http://radioclare.com/tag/terrible-service/feed/" rel="self" type="application/rss+xml" />
	<link>http://radioclare.com</link>
	<description>Stories &#38; Musings From A Duck Enthusiast Whose Life Is Stranger Than Fiction</description>
	<lastBuildDate>Sat, 06 Aug 2011 21:55:53 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>We&#8217;re Back~!</title>
		<link>http://radioclare.com/2008/03/were-back/</link>
		<comments>http://radioclare.com/2008/03/were-back/#comments</comments>
		<pubDate>Fri, 14 Mar 2008 01:21:14 +0000</pubDate>
		<dc:creator>Babel</dc:creator>
				<category><![CDATA[Random rambling]]></category>
		<category><![CDATA[3iX]]></category>
		<category><![CDATA[complaints]]></category>
		<category><![CDATA[terrible service]]></category>

		<guid isPermaLink="false">http://radioclare.com/2008/03/14/were-back/</guid>
		<description><![CDATA[It&#8217;s not a nice feeling to know that someone has access to your server. Unfortunately this is something with which Clare and I have been contending for the last few weeks. If something is too good to be true &#8230; it probably is. It&#8217;s not merely that I created this site for Clare; I had [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s not a nice feeling to know that someone has access to your server.  Unfortunately this is something with which Clare and I have been contending for the last few weeks.</p>
<blockquote><p>If something is too good to be true &#8230; it probably is.</p></blockquote>
<p><span id="more-107"></span><br />
It&#8217;s not merely that I created this site for Clare; I had to find somewhere for it to live too.</p>
<p>Not being particularly well versed in hosting I had recourse to my friend, your friend, all of our friends:</p>
<p style="text-align: center"><img src="http://j9marshall.files.wordpress.com/2007/12/google_logo_halloween_d-mip.jpg" alt="Google logo" /></p>
<p>Before too long I&#8217;d stumbled across a company called 3iX.  I couldn&#8217;t resist it; how could anyone?  It offered us 20GB of storage, unlimited bandwidth, and the ability to host three sites there for the piddling sum of £1.77 per month.  &#8220;Where&#8217;s the catch?&#8221;</p>
<p>We found out in early February that Clare&#8217;s work PC had contracted a virus from my site.  Well colour me shocked!  A Google search of the virus name showed that several other sites had caught the same bug &#8230; and all were hosted on 3iX.</p>
<p>I got in touch with their live support to discuss the issue.  Rather than do anything about it, the jabroni on the end refused to help unless I had a ticket &#8230; not that the hard-of-thinking klutz would tell me what that meant or whence I might obtain one.</p>
<p>I eventually found out what to do and submitted the complaint.  Later that day I received the following message from them:</p>
<blockquote><p>Hello,</p>
<p>We have removed unwanted code from your index pages and now your site is working fine. Please check it and confirm.</p>
<p>Please feel free to contact us back in case of any other information.</p>
<p>Regards,</p>
<p>Simon<br />
Host-Care Support Team.</p></blockquote>
<p>That was jolly nice of them, especially their kind offer of inviting me to contact them.  Not being terribly impressed that my supposedly secure account had had malicious code inserted I took them up on that offer.  In particular, I asked them what they might do to ensure that this didn&#8217;t happen again.</p>
<p>I received an answer the next day.  Apparently the secret to not having my account hacked by someone who breaks into <em>their</em> main server and thus gains access to sites hosted on it is to &#8230; change my password.  Change <em>my</em> password.  The sender of the e-mail was nice enough to paste a patronising mail about how to choose a strong password.  Heaven forfend my brain be so shrivelled that I not know that <strong>opensesame</strong> is not as good as <strong>xp0Fr~~hT¬¦</strong>.</p>
<p>The brain train left the station without that particular employee, I fear.</p>
<p>Not long after my AVG pops up whilst I&#8217;m looking at Clare&#8217;s site.</p>
<p align="center"><img src="http://radioclare.com/wp-content/uploads/2008/03/threatdetected.jpg" alt="Threat Detected!" /></p>
<p>In spite of the fact that I had changed the password, Clare&#8217;s site had now been infected.</p>
<p>I went into the files and deleted the malicious code and changed passwords <em>again</em>.  Two hours later the index files once more featured the bad code.</p>
<p>Pissed off, I responded to the person who sent me the mail about how I needed to change my password to prevent this from happening again.</p>
<blockquote><p>Thanks, but if I&#8217;d wanted a patronising note on how to choose a password, that&#8217;s what I&#8217;d have requested.</p>
<p>What I asked you was:</p>
<p>WHAT ACTIONS ARE YOU GOING TO TAKE TO ENSURE THAT THIS DOESN&#8217;T HAPPEN AGAIN? Don&#8217;t you dare attribute the blame to me for the fact that someone somewhere has got their hands on 3iX passwords. (Mine wasn&#8217;t the only site housed on 3iX that reported this on that day.)</p>
<p>If you are unable to answer the question yourself THEN DON&#8217;T FOB ME OFF WITH STUPID TALK ABOUT HOW TO CHOOSE A PASSWORD; put me in touch with someone who can answer my question instead.</p>
<p>My second question was to ask why I can&#8217;t have secure FTP. How do you, in 2008, justify the use of regular FTP?</p>
<p>Third point, and very important: My girlfriend&#8217;s site is on the same server, and now hers has become infected too. My site is also now infected with the same code again on the index.php file. This is true even though I changed the password.</p>
<p>Tell me how you propose to deal with this issue before I cease custom with you, get hosted elsewhere, and write a series of posts explaining to readers why I moved.</p>
<p>I expect relevant answers, so think before you respond. You are *this* close to losing a customer.</p></blockquote>
<p>I never got a response.</p>
<p>A few hours later the virus had returned.  I fired off another mail to 3iX:</p>
<blockquote><p>I&#8217;ve already discussed this with you once. The former ticket was PKF-173548.</p>
<p>My site has been hacked and a malicious line of code placed on the index page. No-one else knows my password. If you look at my previous ticket, you&#8217;ll see that I researched the name of the virus and found a help thread in the WordPress forums where people said it was a 3ix issue.</p>
<p>The code is back, even though I have changed the password. It seems that there must be something extra that rewrites the bad code after I delete it.</p>
<p>So: I want this problem fixed. I also want answers about how and why this is happening. I want to know why I cannot have secure ftp.</p>
<p>Fix this issue. After that, fix the same thing on my other site http://meddysong.com/ which is hosted on the same server.</p>
<p>I am very, very unhappy about this. The frontpage of your website reads &#8220;satisfaction guaranteed&#8221;. I am far from satisfied so far. I expect this issue resolved with an explanation about why my password (and others on 3ix) fell into the hands of these hackers.</p>
<p>I expect an answer to all of my questions. If you can&#8217;t provide one, put me in touch with someone who can.</p></blockquote>
<p>I actually received an answer to this one:</p>
<blockquote><p>Hello,</p>
<p>We have removed unwanted code from your index pages and now your site is working fine. Please check it and confirm.</p>
<p>Please feel free to contact us back in case of any other information.</p>
<p>Regards,</p>
<p>Simon<br />
Host-Care Support Team.</p></blockquote>
<p>Anything about that seem familiar?  Scroll above; it&#8217;s the exact same response that I received the first time.  That&#8217;s right; 3iX either</p>
<ol>
<li>sends you an incorrect response blaming you for their server getting hacked, since you&#8217;re obviously too stupid to think of a strong password, even this has no bearing on the fact that <em>they</em> were hacked, not <em>you</em></li>
<li>ignores you altogether</li>
<li>pastes a default response because they have so much disdain for their customers that they can&#8217;t be bothered to answer questions that are put to them.</li>
</ol>
<p>Not far off needing a megadosage of tablets to lower my blood pressure I replied:</p>
<blockquote><p>Did you even pay the slightest attention to what I wrote? I am quite capable of removing the unwanted code myself, thanks. I want to know why I can&#8217;t have secure ftp and to whom I can complain, seeing as it&#8217;s *your* fault not mine that my site was hacked.</p>
<p>I suppose that you&#8217;ll ignore this message too like you&#8217;ve done my previous ones, you fucking retards.</p></blockquote>
<p>With that, I went off to their live support:</p>
<blockquote><p>Chat24x7: Welcome to 3iX live chat, my name is Susan, please hold for a moment, I am reviewing your question.</p>
<p>Chat24x7: may i know what is the issue ?</p>
<p>Tim Owen: Certainly.</p>
<p>Tim Owen: My sites (I have two on the same server)</p>
<p>Tim Owen: were hacked.</p>
<p>Tim Owen: It was the case that several 3ix passwords</p>
<p>Tim Owen: were obtained by a Serbian IP.</p>
<p>Tim Owen: The support people have removed the code</p>
<p>Tim Owen: but it keeps coming back, even though I&#8217;ve changed the password.</p>
<p>Tim Owen: So I am very, very angry.</p>
<p>Tim Owen: I want to know why I can&#8217;t have secure ftp</p>
<p>Tim Owen: and what you intend to do about this.</p>
<p>Tim Owen: Every time I&#8217;ve mentioned it to the support team</p>
<p>Tim Owen: they either ignore it</p>
<p>Tim Owen: of paste me a patronising mail</p>
<p>Tim Owen: about how to choose a good password,</p>
<p>Tim Owen: conveniently ignoring that it doesn&#8217;t matter how good the password is</p>
<p>Tim Owen: if some Serbian IP can actually see them.</p>
<p>Tim Owen: So, I want an apology, I want secure ftp</p>
<p>Tim Owen: and if I can&#8217;t have them, then I want a refund and to terminate my contract.</p></blockquote>
<p>What is the response to this, you ask.  Not what one would have expected:</p>
<blockquote><p>Chat24x7: Network speed and technology</p>
<p>Chat24x7: http://www.3ix.org/data_center.php</p></blockquote>
<p>Fortunately the respondent recovered:</p>
<blockquote><p>Chat24x7: What is your domain/site name?</p>
<p>Tim Owen: http://radioclare.com</p>
<p>Chat24x7: Please hold for a moment</p>
<p>Tim Owen: and http://meddysong.com</p>
<p>Chat24x7: we provide secure ftp only with expert and extreme hosting packages</p>
<p>Chat24x7: and you are hosted with Extra hosting package</p>
<p>Tim Owen: oh &#8230; so you want more money to give me a service where I&#8217;m protected from hackers?</p>
<p>Tim Owen: You know how it says &#8220;satisfaction guaranteed&#8221; on your front page?</p>
<p>Tim Owen: That&#8217;s not exactly accurate.</p>
<p>Tim Owen: I&#8217;d suggest putting &#8220;if you take us up on our cheaper packages, we&#8217;ll allow your password to fall into the hands of hackers, and we won&#8217;t apologise or offer you standard protection like secure ftp&#8221;. That would be far more accurate.</p>
<p>Tim Owen: So, seeing as I can&#8217;t get an apology or protection, how about you give me a refund</p>
<p>Tim Owen: so that I can go to a service that actually cares about the security of their customers?</p>
<p>Chat24x7: To cancel your account please send an email to billing@3ix.org with the subject &#8216;MONEY BACK GUARANTEE &#8211; domain.com&#8217; (specify your site name), use your registered email address to send the request and advise your cpanel username and password as verification. The cancellation and refund will be made within 48 hours.</p>
<p>Tim Owen: And that will be authorised?</p>
<p>Tim Owen: It&#8217;s just that your support people have done a wonderful job of avoiding issues like this, so I&#8217;m understandably dubious.<br />
Chat24x7: if it is under 30 days money back guarantee than it will be authorised</p>
<p>Tim Owen: It&#8217;s not under 30 days</p>
<p>Tim Owen: Sorry, I don&#8217;t get hacked to order</p>
<p>Tim Owen: Maybe you&#8217;d be nice enough to let hackers see people&#8217;s passwords within the 30 days next time then.</p>
<p>Chat24x7: then you cannot get a refund</p>
<p>Tim Owen: Right</p>
<p>Tim Owen: So, about this &#8220;satisfaction guaranteed&#8221; thing: Can we at least both agree that that is a lie?</p>
<p>Chat24x7: if you want we can reset your account</p>
<p>Chat24x7: you can upload your data and change the password</p>
<p>Tim Owen: But what good is that if my account can be hacked?!</p>
<p>Chat24x7: <strong>if you keep changing your password frequently then this can be avoided</strong></p>
<p>Tim Owen: You&#8217;re completely skirting around the issue! If things were secure</p>
<p>Tim Owen: I wouldn&#8217;t have to change my password at all!</p>
<p>Tim Owen: You people are ridiculous at putting the blame for your security lapses on to the shoulders of your customers.</p>
<p>Tim Owen: It&#8217;s nothing to do with me</p>
<p>Tim Owen: that some Serbian IP could see 3ix passwords!</p>
<p>Tim Owen: The responsibility for security lies at YOUR feet in this case, not mine.</p></blockquote>
<p>I pause for five quiet minutes.</p>
<blockquote><p>Tim Owen: So &#8230; You&#8217;ve gone quite</p>
<p>Tim Owen: What do I get? Refund or secure ftp?</p>
<p>Tim Owen: I&#8217;ve ruled out the potential of an apology; you staff seem particularly averse to acknowledging that it&#8217;s not my fault that you provide an unsecure service</p>
<p>Tim Owen: and will only give me something that can&#8217;t be hacked if I pay you some more money.</p>
<p>Tim Owen: I&#8217;m unsure whether one would label that &#8216;ransom&#8217; or &#8216;blackmail&#8217;, but it&#8217;s not a good thing, that&#8217;s for sure.</p>
<p>Chat24x7: wait am enabling ssh for secure ftp connection</p>
<p>Chat24x7: you can now ssh with hostname as your domain name , port 3131 and cpanel username and password</p>
<p>Tim Owen: Thank you.</p>
<p>Chat24x7: Is there anything else I can help you with?</p>
<p>Tim Owen: No, everything is fine.</p>
<p>Tim Owen: Thanks you, you&#8217;ve been much more help than the people</p>
<p>Tim Owen: at the support group.</p></blockquote>
<p>Unfortunately Secure FTP didn&#8217;t help, since the hackers had left in a backdoor or script to replicate the malicious code in the event that I deleted it.</p>
<p>In the meantime they mustn&#8217;t have appreciated my earlier line of &#8220;I suppose that you&#8217;ll ignore this message too like you&#8217;ve done my previous ones, you fucking retards&#8221;, since they sent me the following e-mail: (Right-click &gt; View Image to see full-scale image.)</p>
<p><img src="http://radioclare.com/wp-content/uploads/2008/03/idiot.gif" alt="We’re looking into it" /></p>
<p>And not a few minutes later I receive their answer:</p>
<p><img src="http://radioclare.com/wp-content/uploads/2008/03/idiots.gif" alt="We’ve removed the unwanted code …" /></p>
<p>Yes &#8230; the same generic answer as every other fucking time!</p>
<p>That was it.  I set about finding another host.  In my rush I transferred the domain radioclare.com to other nameservers without first downloading the content that was on 3iX.  Because of this, I couldn&#8217;t log back in to their hosting area.  Feel my pain as I endured a conversation with 3iX&#8217;s support over 30 miserable minutes that brought a new low to the definition &#8216;customer disservice&#8217;:</p>
<blockquote><p>Live-Chat: Welcome to 3iX live chat, my name is Mike, please hold for a moment, I am reviewing your question.</p>
<p>Live-Chat: Before the DNS has propagated you can view your site using http://serverip/~username and for cPanel you can use http://serverIP:2082</p>
<p>Tim Owen: It&#8217;s not allowing me to log in.</p>
<p>Tim Owen: My name and password were stored automatically as a cookie, so I know it&#8217;s not a mistake with the typing.</p>
<p>Tim Owen: So &#8230; any chance of an a response here? I need access to my hosting area. i awesome that the DNS hasn&#8217;t propogated so quickly. And if it has, could I not have direct access to my hosting area?</p>
<p>Tim Owen: *i assume</p>
<p>Tim Owen: hello?</p>
<p>Tim Owen: any chance of some acknowledgment?</p>
<p>Tim Owen: OK, you&#8217;re not paying any attentiont</p>
<p>Tim Owen: i&#8217;ll get the site redirected to 3iX again and</p>
<p>Tim Owen: retrieve the database that I need.</p>
<p>Tim Owen: Thanks for being so kind as to ignore me for the last 20 minutes &#8230;</p>
<p>Tim Owen: This is the point where you could offer me the nameservers that I&#8217;ll need to redirect to &#8230;</p>
<p>Tim Owen: Jesus. Is there *any* chance of acknowledgment at all?</p>
<p>Tim Owen: Look! Just tell me what your nameservers are, so that I can get redirected back to this site.</p>
<p>Tim Owen: Hold the front page: &#8220;3iX in awful service shock!&#8221;</p>
<p>Tim Owen: Right, I&#8217;m out of here.</p>
<p>Tim Owen: Thanks for nothing. Fingers crossed you&#8217;ll get fired</p></blockquote>
<p>And that was that.  Stick a fork in them, 3iX are done.</p>
<p>Clare and I are now hosted on <a href="http://asmallorange.com/services/hosting/">A Small Orange</a>.  So far everything is perfect.</p>
<p>If you&#8217;ve made it this far, congratulations.  Your reward is a free piece of advice: <strong>Don&#8217;t Use 3iX: They&#8217;re Fucking Shit</strong>.</p>
]]></content:encoded>
			<wfw:commentRss>http://radioclare.com/2008/03/were-back/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

