Why I could never use Media Temple
Saturday, May 29th, 2010I have been impressed with the customer service at Media Temple. And their web servers seem powerful enough to handle all the needs of my clients. But all the same, for my own sites, I will continue to use dedicated servers from Hostway and RackSpace. And that is because of the email like the one I post here. Media Temple found a security flaw in their set up and is forcing everyone to change the passwords on all of the software they have on their site. I now have a client whose site is down with an ugly error message, because the PHP code running the site can no longer reach the database. So I’m taking time to fix my clients site, but this is all at a time when I’d rather be doing other things. I do understand the argument that Media Temple’s set up is probably more secure than anything I can achieve on my own, but I’d like to take that risk, just so I have control over when I devote time to security matters such as changing passwords. Having these things forced on me by some other company is not a viable option for me, especially not over the long term.
Dear Site Owner,
This notification is meant to inform you that we will be initiating an automated database user password change on (gs) Grid-Service Cluster.06 on 05/26/10.
Due to recent developments regarding System Incident #1167, we have determined that this action is a required safety precaution.
We expect that it will take several days for our system to complete password changes for the entire cluster. If you have received this email, then your (gs) Grid-Service is part of the selected service group.
IMPORTANT NOTE:
You still have time to manually update your database user passwords if you act quickly. You may manually update your passwords right up until our system reaches your particular service in our queue. If you do so, your service will become exempt from the automated change.
We encourage all (gs) Grid-Service customers to choose this manual update route. Once you change your passwords, make sure to update any database configuration files on your service that make use of those passwords. Please see the following article for more details:
http://kb.mediatemple.net/questions/1807
For customers who do not manually update their passwords, please continue reading:
Once the automated password change has been completed for your service, our internal system will automatically open a new Support Request for you within the (mt) AccountCenter and you will be notified of that via email as well.
In addition to the automated password changes, our custom scripts will also update the database configuration files for the following applications to include the newly-assigned passwords:
CakePHP
Django
Drupal
Expression Engine
Gallery
Indexhibit
Joomla
Magento
Mint
Miva
MODx CMS
Moodle
Movable Type
osCommerce
phpBB3
PixelPost
PrestaShop
Ruby on Rails
Simple Machines Forum
SlideShowPro
Symphony
vBulletin
WordPress
ZenCart
QUESTIONS?
We have prepared an in-depth KnowledgeBase article to address any additional questions that you may have regarding this process and the possible impact to your sites/hosting services:
http://kb.mediatemple.net/questions/1807/
We understand that changing database user passwords is not a preferred solution, but we have exhausted all other routes. We have also put much effort into finding ways to minimize customer impact throughout this process.
If you have any further questions, please feel free to contact us at any time, and we thank you for your patience and understanding regarding this matter.
Regards,
(mt) Media Temple, Inc
Hosting Operations