[HN Gopher] ButterCMS unreported downtime and security concerns
       ___________________________________________________________________
        
       ButterCMS unreported downtime and security concerns
        
       Author : unknownhad
       Score  : 18 points
       Date   : 2024-09-23 10:05 UTC (2 days ago)
        
 (HTM) web link (cside.dev)
 (TXT) w3m dump (cside.dev)
        
       | swijck wrote:
       | Surely a company that in their own docs suggests using
       | "dangerouslySetInnerHTML" knows how important it is to be
       | transparent about their downtime? This is shocking, thanks for
       | sharing!
        
         | unknownhad wrote:
         | There are several red flags in this situation:
         | 
         | 1) ButterCMS should have informed their customers/users about
         | what they missed. 2) The way the issue was introduced could
         | have led to a significant supply chain vulnerability. 3) I
         | haven't found any analysis or communication from ButterCMS
         | addressing the issue with their customers. 4) There's still no
         | downtime indicator on their website.
        
       | burningChrome wrote:
       | I remember passing on them and thinking they were way to spendy
       | at $100/month for a blog/CMS hosting when you can self host or
       | use a service like Netlify for a fraction of the cost.
       | 
       | Reading this article and then the company not even mentioning it
       | on their site or on any of their social channels is suspicious
       | and just confirms I dodged a bullet.
        
         | fuzzy_biscuit wrote:
         | 100%. The post cap for that price level is unreasonable, and I
         | don't understand what kind of basic CMS service warrants that
         | pricing.
        
       | Reubend wrote:
       | Thanks for sharing this. Unreported downtime is a nasty, nasty
       | look for any service provider. Unfortunately even large providers
       | are often guilty of it given that SLAs can be expensive when
       | they're violated.
        
       | mgkimsal wrote:
       | Unrelated point of contrast:
       | 
       | I got an email a couple weeks ago from a vendor I'm using telling
       | me about 2 hours of downtime I didn't even know about. They
       | certainly could have only written to customers known to have been
       | affected, and maybe just posted on a blog, but I got an email
       | telling me things were down (I didn't even notice) and what was
       | being done to reduce/avoid that.
       | 
       | They will likely grow to a point where they stop being that
       | transparent, but until then... I appreciate the honesty and
       | transparency.
        
       ___________________________________________________________________
       (page generated 2024-09-25 23:01 UTC)