I'd been thinking about it for quite a while — I'm not even sure what first prompted it.
The trigger that made me decide to switch was the following conversation with technical support (TS).
Me: 17.8. 10:20
Good morning, > could you update the list of fingerprints for your servers in the FAQ?
I checked the one for [server] and it doesn't match (SHA1).
TS: 17.8. 10:44
Good morning,
We have removed the information entirely, so it won't confuse you anymore.
Me: 17.8. 10:52
And how am I supposed, in your opinion, to verify that the server I'm connecting to is actually the right one?
TS: 17.8. 10:53
Good morning,
if you enter the server address correctly for your FTP connection, that is the right server. At this point I was already convinced that I would be changing hosting provider. I just didn't yet know where I'd move.
Me: 17.8. 11:11
I hope you're not being serious.
If you are, I'll refer you to Wikipedia and the article on Man-in-the-middle attacks.
TS: 17.8. 11:24
Good morning,
I believe that if you verify that the given hostname resolves to the correct IP — which you can easily check with a query to any "trustworthy" DNS server (e.g. from an external source), the risk of a MITM attack is more or less hypothetical, and if you consider your ISP trustworthy (if not, the question is why you use their services), then verifying in this way + using a secure connection to the server is more than sufficient given the nature of the services provided.
It is worth noting that (as with virtually any other web hosting provider) we do not provide services requiring any special security — given the continuous changes to infrastructure, migration to a new server structure, etc., it would be wholly disproportionately complicated to maintain fingerprints for all certificates of all services, especially given that you appear to be the only person who actually checks this — the discrepancy you flagged (thank you for doing so) had been there for at least several years.
I would venture to note that the use of a secure connection to FTP is so rare (practically below the threshold of statistical significance, utterly negligible) that maintaining, monitoring, etc. of this kind of traffic makes little sense — most users simply use regular FTP and don't assume that their website would be of interest to anyone for MITM-type attacks.
We endeavour to offer our customers the broadest possible range of services and to continuously expand them, however, if we were to go into details that have no justification given the nature of the services provided, we would reach a point where some services would not be worth offering at all. Thank you for your understanding.
I didn't understand that at all — and so at 11:45 the order with Active24 was completed. Five minutes later I had transferred the domain to their management. In the meantime I was uploading data to the server and waiting for the DNS changes to propagate…
TS: 17.8. 12:06
Good morning,
the following values currently apply to the server:
By around 15:00 my website, email, and this blog were all working again.
P.S. What did I gain? HTTPS for everything, DNSSEC, SSHFP, and a whole lot of other things I consider standard.
