The Jukebox Podcast from WP Tavern recently hosted David Snead to discuss improving security and cooperation across the hosting industry. David has worked in hosting since 1999, beginning as legal counsel for an early shared hosting company, helping to found the i2Coalition, serving in-house at cPanel and WebPros, and now leading the Secure Hosting Alliance.
What the project is trying to solve
David explains two key goals: raise ethics and professionalism across hosting, and rebuild the camaraderie and practical cooperation that waned as the industry consolidated. The Secure Hosting Alliance and the Internet Infrastructure Forum (IIF) aim to make it easier for registrars, registries, DNS providers, hosting and cloud companies to share actionable abuse information quickly, so the ecosystem can detect and stop threats faster than attackers adapt.
How the IIF works (prototype stage)
The IIF is a voluntary cross-industry effort facilitated by the Internet & Jurisdiction Foundation. The current work is a prototype to determine what information should be shared and how it should be routed. Participating parties submit specific, non-proprietary details about an abuse incident—timestamps, domain names, IP addresses—into a central secretariat. That secretariat enriches the data and sends it to the appropriate provider to take action. The initial test focus is on fake shops and credential-harvesting campaigns, a practical example where coordinated response matters.
Why this matters to hosts of all sizes
Large hosts often have teams and resources to absorb abuse volume. Smaller providers, however, can be overwhelmed by a single large problem. Sharing detailed, actionable intelligence saves hours of investigation for small teams and reduces costs tied to bandwidth, payment processing disputes, and customer support. David argues the business case—reduced operating cost and risk—is often a stronger motivator than moral appeals when recruiting participants.
Privacy, legal and trust considerations
A central concern is what data can be shared legally across jurisdictions. The working group is mapping legal issues: information being exchanged is intentionally limited to non-confidential and non-proprietary fields (e.g., domain/IP/timestamps) and formatted using established abuse-reporting formats such as X-ARF. Nonetheless, legal differences across regions (EU, US, Brazil, India, etc.) must be navigated carefully before broad rollout.
Scope and limits: intelligence, not fixes
The IIF’s role is to coordinate and deliver intelligence, not to develop technical fixes. The secretariat acts as a conduit: flagging problems and pointing the right operators to the information they need to remediate issues themselves. This keeps the effort focused and leverages each provider’s existing operational capabilities.
How organizations will interact with the system
The prototype envisages simple, machine-readable exchanges—files or APIs that participants can pull. The aim is a 24/7 accessible feed that operators can ingest into their own systems to detect and respond to abuse quickly. The project is in a test phase to validate the architecture and workflow before scaling up.
Credentials and trust signals
Separately, the Secure Hosting Alliance maintains a Trust Seal program for hosts that meet customer-friendly practices (for example, presenting contracts to customers before signup). While the IIF focuses on real-time abuse sharing, the Trust Seal offers a way for hosts to signal vetted practices to agencies and customers.
Who should join and how membership works
The initiative is platform-agnostic—WordPress hosts are a natural audience because of the community’s size, but Drupal sites, custom platforms, and any infrastructure provider can participate. The Secure Hosting Alliance is a working group of the i2Coalition: membership is handled through i2Coalition enrollment, with membership dues scaled by self-reported revenue. The culture of the group relies on rough consensus; despite commercial competition, hosting operators historically collaborate well on shared infrastructure issues.
Progress and participation
The Secure Hosting Alliance is relatively new but growing: from a few charter members to multiple hosting and security vendor members, and nearly 20 Trust Seal certified hosts so far. Major companies and smaller operators both participate, including well-known registrars and hosts, while smaller providers benefit from actionable intelligence they can adapt to their bespoke systems.
If you’re interested
David invites hosts, registrars, DNS providers, agencies and developers to join the conversation. More information is available at hostingsecurity.net. You can contact him directly at [email protected]. The project’s next steps involve expanding participation in the prototype, refining legal and operational workflows, and rolling out more automated exchange mechanisms so the whole ecosystem can respond faster and more effectively to abuse.