Centralized DNS for Faster, Safer and Easier Hosting

Looking back 2 years ago at our promise to unleash a series of service enhancements after switching fully to Site Tools, we keep delivering! After launching the Ultrafast PHP, new MySQL setup on shared and cloud, SG Optimizer new features, and more, we have also reworked our DNS service to make it faster, safer, more flexible and easy to use than ever. Take a read at what we have done and how that affects your websites hosted on our platform. 

What’s under the hood of our new DNS service 

Let us first make a quick reminder – the DNS (domain name system) is what makes it possible for a domain name to open a specific website. This system indicates on which of all the servers in the whole internet your website is hosted. Usually, a specific set of 2 nameservers and 2 IPs correspond to each server and they should be added in your domain’s management panel for the system to work. Each server also has a DNS service installed on it that processes the DNS queries and shows the proper website when a visitor types your domain in the browser. 

With our new centralized DNS setup we no longer need DNS service installed on each of our production servers that host your website. We are able to move all our DNS services to a completely separate cluster of multiple servers. This cluster is dedicated for DNS service only and is geographically dispersed around the globe thanks to the super cool Anycast network routing technology. Centralized DNS also allows us to have just one pair of nameservers and IPs for all the servers that SiteGround manages, and these are:

  • ns1.siteground.net
  • ns2.siteground.net

What are the benefits of our new DNS service

Faster Domain Resolving, Faster Website Loading

When a visitor searches for your website’s domain, the first thing that the browser does is make a DNS lookup to see on which IP the domain resolves and connects to the server with that IP. With the previous DNS setup lookup requests coming from a different continent from your server’s were handled a bit slower due to the physical distance between the visitor and the server resolving your domain. Now, with the centralized DNS which works on five different geographical locations and multiple instances, the resolving is handled by the closest node saving networking delays and improving your website loading speed.

Enhanced Redundancy 

As the new DNS setup relies on multiple geographically dispersed machines, it is extremely resilient. For example if one of the DNS servers goes down, the DNS requests would be handled by the second closest point, which is up and running. This setup also guards against DDoS attacks, as if there is a high amount of malicious traffic, it will be distributed among multiple DNS machines and it becomes much more difficult for such an attack to succeed. On top of that the DNS service is super scalable, and new machines can be added easily whenever there is a need for more resources.

If you are using your domain simultaneously for your hosting at SiteGround and other services too (for example your MX records are pointed to Gmail), having the DNS service hosted on a different location from your website has one more advantage. In case your hosting server goes down, your DNS will still work and your outside services will still resolve without being affected. 

Seamless Migrations Between Servers 

It’s part of our job to move data around – whether we transfer your account from an old hardware to a newer one, from cPanel server setup to machines with Site Tools setup, or from an old data center to Google Cloud infrastructure, migrations are something that happen and will continue to happen. Every time we migrate servers, one of the biggest challenges is handling the DNS zones. The new server comes with new nameservers and once websites get transferred, the domains have to be pointed to use the new nameservers. We have been updating them automatically for all domains managed via our control panels, but external domains needed manual change by webmasters. In both cases, there would be DNS propagation with potential downtime impact. With the new Centralized DNS it will be much easier to migrate and perform server upgrades in the future. In most of the cases such migrations would not involve any kind of DNS settings change thus preventing any issues caused by propagation. 

More Convenience & Ease of Use for you

With the decentralized DNS, people managing multiple sites on different servers have to keep track of different sets of nameservers, which may be inconvenient. The new centralized DNS simplifies multiple web site management processes for our clients, as all domains of all sites hosted on our platform, regardless of their hosting account or server can now use the same pair of nameservers.

When will the new DNS service become available?

All new websites created on our platform are already using the new DNS service. For older websites, we are now starting a gradual switch to the new centralized DNS. We will be updating nameservers for all domains registered with us automatically. For external domains used with our system, we will be informing our clients by email, confirming when it will be safe to update their DNS settings to the new ones. The old DNS system will continue to be supported for several more months, till the migration to the new one is fully completed. 

[subscribe_cta]

A Critical WooCommerce Vulnerability Promptly Addressed

Last week, the Woo team announced a critical vulnerability in the most popular eCommerce plugin for WordPress – WooCommerce. As described in their post, security updates were pushed to all Woo branches for users who have not disabled such updates. This was done in a very fast and efficient way. Furthermore, the Woo team has been extremely cooperative with providing all the needed information that allowed us to proactively add security rules to our WAF (Web Application Firewall) for an additional layer of protection. Read below to learn more about all actions taken and their results.

Branched updates pushed by Woo

Due to the severity of the vulnerabilities discovered, the WooCommerce team has worked more than 36 hours around the clock to patch every major release branch. This means that you don’t have to switch from WooCommerce 4 to 5 to protect yourself. Those updates were pushed and if not explicitly disabled, most probably your Woo has been already patched. However, we strongly recommend that you check this! All WooCommerce versions prior to the latest patch are vulnerable. You can check your version and compare it to the WooCommerce Releases (https://developer.woocommerce.com/releases/) page. For example, if you have WooCommerce 5.5.1 you should simply update to 5.5.2. That will fix the security problem without breaking any functionality.

Proactive WAF protection set by SiteGround

In regards to security, we’ve always believed that being proactive is the best approach. This particular vulnerability was no exception. As soon as we were informed about it by the Woo team, we acted immediately and added a new security rule to our Web Application Firewall (WAF) – an elaborate system for exploit prevention, running on all of our servers. You can think of the firewall as a set of rules that address exploit attempts. We are constantly on the watch out for information about common security issues and we are quick to act by adding security rules so that our system can block attempts to exploit such issues. WAF will not patch a security hole of a particular website, which can be only done through updating with the security release, but prevents attackers from using it to gain unauthorised access to your site.

You may wonder why you need a WAF rule when the Woo team is fast to release a new security version. We do it to ensure that clients have more time to react, during which their sites are safe from the exploit. While the majority of the WooCommerce users are automatically updated by Woo, some sites are not updated for various reasons – auto-updated failed, disabled, or postponed too far in the future. Some webmasters prefer to manage the updates themselves, mainly as they want to be sure that the update does not mess with any of their website functionality. After all, we are usually talking about online stores, relying on many additional plugins for shipping, payments, tracking, taxation, and many more. For these people, the WAF rules provide time to make sure all their critical functionality will work with the new Woo version.

As a whole, the handling of this Woo vulnerability shows how the combined efforts of responsible plugin developers and your hosting company pay off – even in emergency situations your clients are safe and business continues as usual!

[subscribe_cta]

One Multisite SFTP to Rule Them All

SFTP

This summer has been especially hot at SiteGround because new features come up one after the other. The latest addition to our platform is the option for Multisite SFTP access with a single SSH key. From now on, people that manage multiple sites on our platform will no longer have to use a separate SSH key for each of their sites in order to be able to securely upload files over SFTP. The Multisite SFTP Access can be used for all the sites you own or are added as a collaborator in a single Client Profile. 

Multisite SFTP Access is super convenient

This feature is especially handy for people that manage a lot of websites on our platform. If you are one of them, with our new feature you will no longer lose time creating a separate SSH key for each of your websites you wish to access over SFTP. Moreover,  you will no longer need to remember different usernames and hostnames for each site. From now on you may authenticate for an SFTP connection to each of your websites through one and the same central hostname and username. Our system will then grant you SFTP access to all the sites that have been added to your multisite SSH key. 

Multisite SFTP access is highly secure

The Multisite SFTP access is definitely making it more convenient to manage multiple websites. But rest assured this convenience does not come at the expense of security. As with our single site SFTP option, you get an encrypted file transfer between your local computer and the remote server hosting your site. We also use the much more secure authentication method of SSH keys instead of simple passwords. Keys have a number of undeniable security benefits – they are much longer and more complex, making it impossible to be brute-forced. In addition to that, the key itself is not transmitted during the authentication process. On the other hand passwords, even ones generated from tools, are prone to brute force attacks and they often rely on the same master password stored on a computer that could be potentially infected. And if you want to add a layer of security yourself, you have the option to easily restrict the multisite SFTP access of your SSH key to a specific IP.

Multisite SFTP access is easy to set up and manage

To use our new Multisite SFTP access you just need to create a master SSH key through your Client Area. At the time of the initial key setup you may choose which of your current sites to be accessible through it. Once you activate the key, each new site you create or you are made a collaborator to, will be automatically added to the key. You can edit the list of sites accessible through the key at any time through your Client Area. To learn more check out our detailed Multisite SFTP access tutorial.

NOTE: An obvious prerequisite for using our new service is to have more than one website managed through your client profile. If you have just one website, you still can access it through SFTP, of course, but you need to use its unique SSH key, generated through its Site Tools.

[subscribe_cta]

Enhanced Protection Against WordPress Vulnerabilities with SiteGround Security Plugin Preinstalled

We have recently launched our own WordPress security plugin — SiteGround Security (now named Security Optimizer), which aims to protect WordPress users against the most common vulnerabilities plaguing the sites. It is available for anyone to download and use for free, regardless which hosting platform they use. To make sure that our WordPress sites are well protected on application level, however, we have started preinstalling SiteGround Security on all new installations on our platform with some of the features enabled by default. 

Default SiteGround Security Settings Against Common WordPress Vulnerabilities 

Having your site set up with security in mind from the start can easily protect you against some of the most popular vulnerabilities out there. To help you achieve that goal, when we preinstall the SiteGround Security plugin we enable the following settings:

WordPress Version is Hidden by default

Hackers often crawl websites scooping information about software versions used. That way, when they get to discover a vulnerability in any of those versions, they are able to reach to and quickly hack many sites in bulk using that information. For WordPress application this data is openly available in 2 places – in an HTML tag and in the readme.html file. 

By default, our plugin removes the HTML tag with the WordPress version and we strongly recommend that you also remove the readme.html file via the option in the SiteGround Security plugin.

Advanced XSS Vulnerability Protection enabled

The cross-site script vulnerability, known as XSS, allows different apps and plugins to access information in your WordPress that they shouldn’t. Such attacks are often used to gather sensitive user data for example. By default, the SiteGround Security plugin enables protection against XSS by adding headers instructing browsers not to accept JS or other code injections.

Disabled XML-RPC protocol to prevent many vulnerabilities and attacks

The XML-RPC is an old protocol used by WordPress to talk to other systems. It is getting less and less used since the appearance of the REST API. However, it is available in the application and many are using it for exploiting vulnerabilities, starting DDOS attacks and other troubles. That is why our SiteGround Security plugin disables this open access line to your WordPress application by default.

NOTE:

Jetpack plugin and mobile apps are valid users of the XML-RPC protocol. If you download Jetpack at some point, we will automatically enable the protocol back. You can also enable it yourself through the plugin interface.

Option to Disable RSS and ATOM Feeds 

Similar to XML-RPC, feeds are rarely used nowadays, but they are often used by attackers and bad bots to scrape your site content. So the SiteGround Security plugin allows you to disable them easily. Unless you really need them, we recommend using this option and disable them as soon as possible.

Lock and Protect System Folders by default

Usually, when an exploit happens, attackers try inserting and executing PHP files in public folders to add backdoors and further compromise your account. By design, those publicly accessible WordPress folders are used for uploading media content (images for example). Via the SiteGround Security plugin, we do not forbid the upload of files, but we stop PHP files and malicious scripts from being executed and causing problems for your sites.  This feature protects those system folders and prevents potentially malicious scripts from being executed from them.  

Disabled “Admin” Username 

The default username and one most widely used on all applications by their owners is “Admin.” Hackers know that and when they wish to bruteforce a login form, they will definitely try it. That is why we disable this username by default. 

Disabled Themes & Plugins Editor

Editing code through the plugins and themes editor poses direct security risks both from potential elevation of privileges attacks and errors made by a regular site administrator. If you want to edit your files, it is strongly recommended that you use the File Manager tool in Site Tools, or your preferred editor through FTP or SSH (ideally on a staging copy of your site). To help you avoid bad practices and attacks, we disable the themes & plugins editor by default.

There are a few settings, which you can control from the SiteGround Security plugin, which we have not enabled by default because they need your permission or they pose a risk on the way you use your app. Yet, we wish to encourage you to enable them consciously as they are quite powerful protection tools as well.

Two-Factor Authentication is a MUST

You already know that 2FA protects your login from brute force attacks and hijacking of login credentials. You can read more on the topic here and you can enable it easily using the SiteGround Security plugin.

Limit Login Attempts 

When someone tries to log in several times with wrong credentials, they are most likely trying to guess your logins. That is why it is strongly recommended to block such attempts after the first few – 3 or 5. You can set that in the SiteGround Security plugin interface and after that many times of wrong logins, the user gets blocked for 1hour the first time, then 24hours on the second trial, and finally for 7 days on their third trial. Again, since if you don’t know about this functionality, you may lock yourself out of the WordPress admin area, we are not enabling it by default for you, but you can do it easily in a click!

More Tools Against WordPress Vulnerabilities Coming Up

We’re continuing the development of the plugin and will add a lot of new functionality soon. Monitor the change log for new features added with the upcoming updates. There isn’t a strict roadmap that we can share at this point but some of the features coming next are custom login URLs, Strict Transport Security headers and X Frame options that will prevent page hijacking. As usual, we want to bring what’s usually difficult to implement technologies to everyone and with an interface easily accessible without having to spend hours researching the exact syntax of the necessary headers or other code.

[subscribe_cta]

Data Safety and Disaster Recovery Policies at SiteGround Hosting (that just got better!)

Disaster_Recovery_SiteGround

Data storage and safety are key components of our web hosting service. That is why we are extremely conscious of keeping your websites frequently backed up and safeguarding those copies in good status for a potential future usage. Having been in the business for 17 years, we have witnessed different incidents seriously affecting or threatening different hosting providers around the world. There have been hurricanes in close proximity to big data centers, power outages due to a state emergency, and quite recently, we all saw how a large data center in France was caught by fire and all data, including backups was lost.

That is why we never let our guard down, periodically evaluate the risk and add new policies to make our disaster recovery strategy better and better. For example, we recently introduced a new backup algorithm that keeps your accounts’ backups in а datacenter different from the one hosting the live account and in case of an accident we can power up your website quickly in a new facility. 

Now we want to give you an overview of how we keep your data safe and how we restore them when needed so that you rest assured we are proactively taking care of your websites and information.

How do we keep your data safe?

  • Google cloud infrastructure redundancy and omnipresence

Since we migrated our platform to Google Cloud’s infrastructure, we feel more confident in the redundancy of our service. Natively, Google Cloud maintains a highly redundant clouds of servers in different data centers worldwide and allows us to easily migrate data from one virtual machine to another, or one data center to another, regardless of the continent. That by default means that in case of an incident with your live server, it is quite likely that your files would be still on the cloud.

  • Daily backups

The Cloud-based infrastructure ensures a great ground level of data safety, but  is not a 100% guarantee that we will be able to restore your files when needed, which is why we have been creating free daily backups to all our accounts. Not only that, but we keep multiple backup copies of the accounts we host. That way even if our backup script fails for some reason one day, we will have previous copies to revert to and that significantly improves the chances for having a backup when you need one. To be specific, for StartUp, GrowBig and GoGeek plans we store 30 copies, while for cloud accounts we keep 7 copies.

  • Backup storage in a different geo location [NEW FEATURE]

To minimize the damages possible due to a server failure, we have always kept your backups separately from your account – on a different physical machine, but in the same data center. As of last month, however, we have introduced an awesome enhancement – we now keep your account’s backups in a different physical facility from the one hosting the live sites. 

We evaluated the risk factor of having not just a whole server down, but the whole datacenter and with the climate change which leads to an increasing number of natural disasters worldwide, as well as a recent incident when a fire hit a large data center in France and resulted in huge data losses, we see that probabilities are growing so we decided to take actions. Thanks to Google Cloud’s facilities, we are now doing the following:

Iowa, US servers are backed up on machines in Virginia, US

London, UK servers are backed up in Eemshaven, NL

Frankfurt, DE servers are backed up in Eemshaven, NL

Eemshaven, NL servers are backed up in Frankfurt, DE 

Sydney, AU servers are backed up in Singapore, SG

This service is not available only for accounts hosted in the Singapore data center.

  • On-demand backups

Since the highest likelihood of losing data and breaking a website is when users try to upload changes on their sites, we strongly recommend using the on-demand backup creation tool available in your Site Tools. Make a backup right before you deploy new code, plugin, theme or else on the site so you can revert in a click in case anything goes wrong. Try to make it a routine! You have the tools at your disposal, just go and hit that backup button before you deploy anything!

SiteGround_Site_Tools_Ondemand_Backups

How do we recover data in case of an incident?

In case of any incident, whether a self-incurred by the user website damage, or a more serious hardware failure, your account data can be easily restored from the available backups. Here’s how:

  • Restore tool for quick website issue resolution 

All our clients have a free restore tool in their Site Tools control panels, which gives you access to all available copies made by our daily backup script or manually by you from the backup creation tool. Just click and restore the copy that is either the most recent one, or seems to be unaffected by malware or human errors.

SiteGround_Site_Tools_Restore
  • Mass incident disaster recovery

So accidents happen, regardless how much you try to protect against them. In case of a massive server crash, or power outage for a long period of time, or a natural disaster, we as your host need to be able to step up and find a way to restore your data and minimize the downtime. That is why years ago we built our sophisticated backup system. The main advantage of this system is that it could migrate TB of data in just a few hours as it allows simultaneous restores from multiple backup instances to multiple production servers. 

What is more, we will be able to power up your website on a server that is in a different country or continent if that’s the fastest way to put it back online!

[subscribe_cta]

Security Optimizer (formerly SiteGround Security) – our new must-have WordPress plugin

The security of our clients’ websites has always been an extremely important part of our web hosting services. Some of the brightest technical minds in our team have been continuously dedicated to crafting unique security solutions and keep the safety level of our hosting infrastructure on an unmatched high level. We have been an industry pioneer in developing server level protections like account isolation, server health monitoring, anti-bot traffic prevention, etc. We also know that on top of the server level solutions, the security of each individual website should be strengthened on application level too. That is why we provide services like auto updates, backups and WAF protection to our clients. 

Today we are happy to introduce another tool that can greatly enhance any WordPress site security – our brand new plugin – Security Optimizer (formerly SiteGround Security). The Security Optimizer plugin is available for free download for anyone and it comes preinstalled with all new WordPress installations hosted at SiteGround and provides its users an easy way to protect a WordPress site from malicious attacks. It also includes valuable tools that can help a website owner react in case there is a suspicion that the site might have been compromised. Read below to learn how to make your site safer with our new plugin.

Protect your WordPress against common attacks

In the Site Security section of our plugin you will be able to easily switch on several rules that will harden your website security and prevent common malware, bruteforce and other security issues. Some of these rules, like hiding your WordPress version or deleting your default readme.txt, will make it harder for crawlers to detect you’re even using WordPress. Thus your website will not be easily identified as a possible attack victim when a vulnerability appears. Other rules in this section will add advanced XSS protection and protect your system folders from being injected with malicious files. 

Strengthen your login security 

In the Login Security section of our plugin you will be able to apply several methods that protect your login from unauthorised access. One of the most recommended methods to protect your login is the 2-factor authentication and with the Security Optimizer plugin, you can easily switch it on for your WordPress administrative area. Some simple, yet very effective protection measures like changing your login URL and not allowing “admin” to be used as a username can be also easily set here. You can also limit the number of login attempts from one and the same IP, which will block attackers trying to guess your password through brute force. And if you want to go even deeper in protecting your WordPress login, there are two more advanced options available. You can specify the IPs from which your login page can be accessed. The option should be used with caution if you use dynamic IP, so that you do not block yourself out.

Monitor your admin area activity log

One of the best plugin features is the detailed Activity log. It allows you to pinpoint things like bad IP addresses that try to access your website as well as registered users that are performing tasks they are not supposed to. For example, you can block with one click IPs that have numerous incorrect logins and at the same time find out which user has deleted that post you are missing. For the initial version, we keep the log 16 days back so it’s worth giving it a look every now and then especially if you have a busy site and number of users with the capabilities to edit content.

React if you suspect your site might have been compromised.

In the Post-hack section of the plugin you will find a set of actions that are useful, if you believe your site security has been compromised. Here you will be able to automatically log out all users and force them to change passwords. This way if any user was compromised, you may stop the malicious access through its account. You will also be able to reinstall all your current plugins. This will make sure you are using a clean copy of each plugin instead of a possible compromised one. Please bear in mind that although these post-hack actions are handy, they are not a substitute to a thorough site clean up that might need to be done by a WordPress security expert, if there are signs that your website might have been hacked.

How to get Security Optimizer?

Security Optimizer is available as any other free WordPress plugin. You can find it in the official WordPress plugin repository (https://wordpress.org/plugins/sg-security/) or install it directly through your WordPress admin area. If you host your next WordPress website at SiteGround, using the plugin comes right out-of-the-box, since all new WordPress installations now come with the plugin preinstalled with some of its features enabled by default.

This is the first plugin we are releasing whose full functionality can be used by anyone, even people that are not hosted by SiteGround. This said, we haven’t done excessive testing on every other company so issues caused by their particular setup may occur. If that’s the case, don’t hesitate to post a thread in the plugin forum in the WordPress repository, we will do our best to make sure it works great on all platforms.

[subscribe_cta]

Moving to PHP 7.4 and Discontinuing Some Old Versions

A large part of our service involves keeping server-side and client-side software up to date, secure and fast. One of the key elements of our server stack that requires expert maintenance is the PHP programming language, which is a prerequisite for the functioning of the majority of the websites. PHP is an extremely popular and well-supported language and, as any software, its development involves the continuous release of new versions. New versions introduce new features and important performance and security enhancements. As a managed hosting service provider we keep track of how each PHP version evolves, especially how fast it is adopted by the leading application developers, and we make proactive efforts to make sure our customers get all the benefits of the newer versions as soon as possible. Here is our latest PHP maintenance update.

PHP 8.4: Stay Updated! 🚀 Check out our latest blog post to explore the newest features and enhancements in PHP 8.4.

Moving to PHP 7.4 as the server default

As of June 2021, we will be switching the default version on our servers to PHP 7.4. This means that all new sites will be using 7.4, unless manually switched to a different one. PHP 7.4 has been around for more than 2 years now and has already become widely compatible with different CMS’s, themes and plugins, where PHP 7.3 (our current default) is already out of active support and will get out of security support too by the end of this year. Keeping your PHP version up to date has undeniable performance and security advantages and that is why we are now helping you switch to PHP 7.4.

All websites using our Managed PHP service will also be upgraded to 7.4 in the period June 10-21, 2021. PHP 7.3 will still be available on our servers and can be set up manually for any site by our clients from Site Tools > Dev > PHP Manager.

Discontinuing support for 7.2, 7.1, 7.0, 5.6 and lower at the end of the year

At the same time, the security support for all PHP versions below 7.3 has been officially over for quite some time, and given the exploits that leak out once in a while, we believe the risk of using them is growing higher. Additionally, the performance of websites using old PHP versions is considerably lower compared to sites using newer versions. That is why we are starting a process of discontinuation of PHP 7.2, 7.1, 7.0, 5.6 and lower on our servers. After June 21, 2021 we will be gradually updating the sites using old PHP versions to PHP 7.4. PHP versions below 7.3 will no longer be supported on our servers after December 31, 2021.

What to do if you are using an old PHP version?

This PHP update will affect many websites on our platform. That is why we have started communicating the update one month ago and we strongly encourage you to evaluate the impact of upgrading to 7.4 on your site as soon as possible by using this tool:

your-domain.com/.well-known/sg-php-try-v74

To see if a site will work properly after the upgrade, please type the above URL using your own site domain in the browser and browse through the site, its subdomains (if any) and its admin area. If anything does not look or behave as expected, we highly recommend that you further investigate your site compatibility with PHP 7.4 and fix any issues before the update. If you have broken plugins or a theme, consider updating or replacing them. If that’s too hard, or the problem is elsewhere, contact your developers for assistance.

Note: By opening your website through the link above you will browse it using PHP 7.4. This change affects ONLY your current browser session. All other visitors will continue to access your site with its current PHP version. To stop the compatibility check browsing mode in your own browser, please close the browser and access your site again via its standard URL.

Magento special case: Sites using Magento 2.3.6 or lower are not compatible with PHP 7.4 That is why, if you have such a website, we strongly recommend you update it to 2.3.7 as soon as possible, so that it is compatible with PHP 7.4 and ready for the PHP upgrade.

We are aware that sites currently using PHP version 7.2 or lower may need longer time to fix possible incompatibilities with PHP 7.4. That is why, the owners of such sites were provided with a link for possible opt-out in the email about the update, sent over the past few days. By opting out through this link, clients confirm that they do not want us to update their site PHP version for them, but are aware that this version will nonetheless stop functioning after December 31, 2021.

For clients using PHP 7.3, we strongly recommend that they do not postpone their PHP update, but in case this is really needed they may simply switch to manual PHP version management, until their site is ready for PHP 7.4.

Looking forward to seeing more secure and much faster sites after the update!

[subscribe_cta]

Geographically Distributed Backups for Enhanced Data Protection

distributed_backups_SiteGround

We are excited to announce that as of this month, we have deployed a system for geographically distributed backups, which minimizes the risk of data loss and аllows for fast data recovery even in case of a serious incident that may affect a whole data center. 

Backups are stored in a different physical data center from the one hosting the live account

As of this month, we started backing up accounts in a data center different from the one hosting the live account as follows: 

  • Iowa, US servers are backed up on machines in Virginia, US
  • Virginia, US servers are backed up on machines in Ohio, US
  • California, US servers are backed up on machines in Oregon, US
  • Texas, US servers are backed up on machines in Southern Carolina, US
  • London, UK servers are backed up in Eemshaven, NL
  • Frankfurt, DE servers are backed up in Eemshaven, NL
  • Madrid, ES servers are backed up in Eemshaven, NL
  • Eemshaven, NL servers are backed up in Frankfurt, DE 
  • Sydney, AU servers are backed up in Singapore, SG
  • Paris, FR servers are backed up in Madrid, ES

This service is not available for accounts hosted in Singapore for now. These accounts are backed up on different servers within the Singapore facility.

Enhanced data protection

Data storage and safety is a key component of our service and there are multiple risk factors and threats that we keep in mind when coming up with data security solutions. The most common ones are human errors, hardware failure, and hacks. For those occasions, we rely on our daily backups stored on different servers independently from the live account. But then, there are the less likely, yet more damaging risks such as fire, power outage, or a natural disaster that may shut down a whole data center facility. Hosting the backups in a different location means we improve the chances of saving your data and putting it back online even in case of such a serious incident.

Faster service restore

Now imagine your website goes offline due to a massive power outage and the ETA is unknown, which most often means hours of downtime. Or, a hurricane completely destroyed the facility and all servers are lost beyond recovery. That was a very real threat we experienced with Katrina hurricane back in 2005 and is a growing risk in some areas given the climate change and the growing number of natural disasters all over the world. Or, maybe a fire burns the datacenter and a lot, if not all, servers are hurt. That one happened quite recently to a third-party data center in France.

Thanks to our new system, we now have you covered since we have your data safely backed up not more than 24 hours ago in a different data center. In case of an incident, we would be able to put your website back online in the new location that is fully operational.

Thus the distributed backups not only save your data but allow us to restore service in the new DC much faster than any optimistic ETA would forecast for restoring in the original DC.

The distributed backup strategy has been something we have considered for a long time. However, it became practically possible once we started to use the Google Cloud infrastructure. The use of one and the same provider for all our geographical locations, with a super fast interrelatedness between its different data centers and a wide network of facilities around the world, allowed us to distribute data across regions, countries, and continents in a way that was not possible before.

We have to recognize the fact that before switching to Google Cloud infrastructure that strategy for distributed backups was not possible in such a sophisticated way. Google Cloud has given us easy access to all their worldwide facilities, including networking capacity and that generated various new possibilities to distribute data across regions, countries, and continents.

Same level of data privacy

Our Privacy Policy and DPA continue to apply in light of our new geographically distributed backups. Our clients’ data will be protected in the same way as before, as promised, and under our DPA.

While we are hopeful that no natural forces will affect any data centers, our team prefers to be prepared for the worst and provide our clients with reassurance for their websites.

[subscribe_cta]

Green Web Hosting And SiteGround’s Commitment To Sustainability

Data centers play a big role in the Internet industry: they store, process and deliver all the websites’ information on their non-stop running servers. They are usually part of massive facilities which need a controlled and artificially-cooled environment to run properly. That requires a huge amount of energy, indeed, according to recent studies, global data centers are estimated to consume 1% of global electricity use, issuing high quantities of CO2.

As an international hosting provider that manages more than 2 Million domains and 5PB of data, we are fully aware of this impact on the environment and it is in our hands to actively mitigate it by committing to provide green web hosting services as much as possible. From designing our hosting operations and services with the highest efficiency in mind, to implementing several policies that support an environmentally-friendly mindset, we take it seriously because we truly care.

Since today is Earth Day and we want to celebrate that day with joy and gratitude, it seemed relevant to give you some background on what it means to be a green web hosting provider, what to keep in mind when choosing one, and what actions SiteGround is taking towards sustainability.

What is green web hosting and how hosting providers can mitigate their environmental impact?

Green web hosting means that the hosting provider is committed to contribute towards the health of the environment and proactively takes eco-friendly actions that involve either carbon offsetting or renewable energy usage in order to reduce or mitigate the environmental impact of their servers’ energy consumption.

There are two main actions a hosting provider can take on the way to offering green hosting service:

  1. Use renewable energy to power up their data centers and facilities. This means that the electricity they use comes from natural resources that are replenished naturally, such as sunlight, wind, rain, tides and geothermal heat.
  2. Buy carbon credits. With this option, the company can buy a permit to emit one ton of carbon dioxide per credit or its equivalent of any other greenhouse gas with the aim to offset their carbon footprint.

As the internet industry evolves, so does the amount of energy and resources needed to process all the operations that the content storage and traffic implies. Choosing a hosting provider which is actively running actions towards better efficiency of their data centers and fostering initiatives to reduce their business environmental footprint is becoming ever so important, as it all makes a great impact on climate change, in addition to having several advantages for you. Three of the main ones are:

  • Carbon footprint reduction of your e-business and online operations, since green hosting providers usually opt for renewable energy usage or buy carbon credits.
  • Better efficiency of your website, as their efforts towards sustainability may include the adoption of latest technologies and resources optimization. 
  • Easiness to be part of the green change, as at the very moment you host your website with a hosting committed to the environment, you are already making a difference compared to others in regards to climate change.

Actions SiteGround is taking as a green web hosting provider:

Reducing our carbon footprint by partnering with commited providers

Since we are not a data center provider, and are not operating our own data center facilities, we need to rely on the green policies of our main data center partners. That’s why, a key motivating factor for our decision to move our infrastructure to Google Cloud Platform was their commitment to sustainability. Google’s data centers match 100% of the energy consumed by their global operations with renewable energy and maintain a commitment to carbon neutrality. Choosing such a leader in energy efficiency as our infrastructure partner is something that we are very proud of.

Optimizing resources by providing customers with top-notch technologies for better efficiency of your website applications

Efficiency is another key factor of green web hosting. Simply put, every website operation is managed and executed by its hosting server processor, and requires CPU, RAM, and storage resources. The heavier your website is, the longer its server processor and resources are in use, the more electricity it consumes. 

At SiteGround, we are constantly optimizing our server software to get the most out of our technology and reduce the resource usage of our clients’ websites. As a result, the better optimized our servers are, the less resources and less energy your website will use for the same volume of tasks, making our operations and clients’ websites “greener” thanks to our software performance. For example, our Ultrafast PHP can speed up website performance up to 30%, making it consume proportionally less energy. Our latest RAM optimization of our cloud MySQL setup on our servers additionally increases client websites’ resource usage efficiency. 

We also constantly look for ways to optimize our internal operations for maximum efficiency – for example, performing regular backups at certain hours when the overall server resources usage is relatively low, to avoid putting extra load on the server processors, thus balancing energy consumption. Overall, our policy to always strive to make the latest website technologies available for our clients to use not only helps you reach top website performance, but promotes energy efficiency, as well.

Reducing the environmental impact of our workplace

In early 2019 we finished the building project of the new SiteGround Headquarters building. One of our main goals was for it to be built entirely in accordance with the Leadership in Energy and Environmental Design (LEED) requirements. LEED is the most widely used green building certification in the world, globally recognized as a symbol of sustainability achievement.

SiteGround Headquarters Building is built entirely in accordance with the LEED requirements.

Encouraging a more conscious lifestyle among our team members

In addition to our efforts on a business and company level to become a green web hosting provider, we constantly try to maximize our impact by encouraging every single employee of SiteGround to lead a more conscious lifestyle. We are running several internal initiatives to help us do that:

  • Company E-cars, e-bikes and free e-charging stations at the disposal of our employees during work hours or for running small errands. Following this benefit, we saw more colleagues opting for electric cars in their own households and others seriously considering it!;
Company E-cars are at the disposal of our employees during work hours.
  • No plastic water bottles, containers, or water coolers in the office: we installed water filter dispensers across all our offices to replace plastic use due to daily water consumption;
  • Using custom green-friendly tissue for our company gifts: For all SiteGround-branded gifts and packages that we send to employees and partners, we use a custom-design eco-packaging by Noissue’s Eco-Packaging Alliance. For every order made they plant a new tree, contributing to global reforestation and carbon neutrality;
  • Our last (for now) team building event in 2019 was dedicated entirely to the Zero-waste idea, which was reflected not only in all team workshops and activities, but across the whole event organisation, banning single-use plastics, separating and recycling all our waste from the event, etc.

Having in mind all of the above, we are fully aware that sustainability is a process – it starts with an intention and only goes on and improves with time. We will continue looking into adding even more meaningful actions to continue delivering green web hosting features. But the future depends on all of us. We all need to realize that our personal choices have public consequences, and be more conscious about what we can do in order to sustain our business or way of life, but in a way that is also considerate for the environment.

In addition to us sharing our efforts towards sustainability, we’d love to hear from you! Share in the comments below what you are individually doing to achieve a greener way of living, working, and doing business. It is always comforting to know every single step that is done at every level, as when put all together, they will sum up to turn into a big leap towards mitigating environmental issues.

[subscribe_cta]

Optimizing the RAM Utilization by the MySQL on the Cloud

Over the last 6 months, it has been all about speed at SiteGround. We have boosted the performance of the websites hosted with SiteGround up to 5 times by launching the new Ultrafast PHP and MySQL setups and enabling the dynamic cache (full page caching) for all sites. As a next major step in this process, we have turned our attention to our cloud servers and are glad to announce that we rolled out a new dynamic RAM-allocation algorithm that further improves the resource utilization of the MySQL and makes the database-intensive websites hosted on our higher cloud plans run faster. 

What is the problem with MySQL?

MySQL could be a real troublemaker. When left untamed, it devours resources and keeps asking for more. If it doesn’t get what it wants, it starts slowing processes one after the other and turns into a bottleneck for database-driven apps like WordPress. So the MySQL settings are the key to resolving many of the site slow issues reported, but many webmasters have difficulties tracing the origins of the slow performance. It is not just a question of adding more RAM. This RAM should be smartly utilized in a way that allows MySQL to run as fast as possible, but still to be restrained from eating up all the available resources.  

We have been helping clients with evaluating what is an optimal allocation of RAM to the MySQL given the specific services running on the website and the available specs and manually resolving those case by case, but, now we have come up with a way to automate that and diminish the amount of work and expertise required by our clients in the process.

What have we done?

We have implemented a dynamic configuration that depends on the amount of memory your Cloud account has. This means that MySQL settings will be adjusted depending on the available resources. We will not only start new Cloud instances with predefined configurations, but in case of an Automatic Scale event (or upgrade), the server config will adjust itself for optimal resource utilization without manual intervention.  That means that database queries will be processed faster and the I/O usage will be lower. Last, but not least, the additional RAM you add will now be utilized more efficiently, and even fast-growing sites will have to add less of it less often and thus save on their hosting expenses.  

Who Gets It?

The new system is already deployed on all Cloud servers! You don’t need to enable it or otherwise configure it. Just watch out for performance improvements and do let us know your feedback. The more database-intensive your site is (such are, for example, membership sites, online stores, forums, etc.), the bigger the improvement from the change will be!

[subscribe_cta]