Ask the forum, part 2 - What happens when someone shouts scam

An accusation is the beginning of the process, not the end of it.
Second of three posts on how a forum full of anonymous strangers works out who to trust. Part 1 covered the signals: the slang, the tags, the way a member's posting history gets read, and the slow public grind a provider goes through before anyone calls it safe. This part covers what happens when that goes wrong, somebody posts an accusation, and several thousand people have to decide what to believe.
A note on names: @handle is a real forum account, quoted from a public thread. Companies appear without the @. LES is LowEndSpirit, where this is posted; OGF is LowEndTalk, the other forum, and I say so when a quote comes from there.
In this part
1. How a scam alert actually spreads
2. The deadpool list as a trust ledger
3. Second-order trust, or who vouched for the voucher
4. There is no verified badge, and then in 2026 there nearly was
How a scam alert actually spreads
One angry customer posting "this provider is a scam" does almost nothing on its own. That is not cynicism about complainants, it is just what a decade of watching these threads teaches you. Some accusations are right, some are a misunderstanding about a billing cycle, and from the first post you frequently cannot tell which. So the community does not treat the accusation as the verdict. It treats it as the opening of a hearing, and three things decide the outcome: what is in the thread, whether anyone independently corroborates it, and, weighted far above the other two, how the provider answers.
Two real threads show the whole range.
In August 2024 a member called @xbugx posted about Dedi Rock. Their service had been cancelled on the 24th, days after being switched to a six-month billing period, with no refund. The post did not hedge: "I do NOT recommend Dedi Rock. They are an ultimate scam, and their support is beyond terrible."
Note what happened next, because it is not what an outsider expects. The forum went after the accuser first. @tetech asked, bluntly, "Where's the ticket screenshots? Given they replied next business day and you've had a meltdown, the issue must have been urgent." Then, more specifically: "Where is the screenshot from Ticket ID: #MRB-399189?" @bikegremlin asked the question that actually decided it: "When they switched you to the 6-month billing period and issued an invoice for it (on the 19th), did you pay that invoice before the 24th (when your service was cancelled)?"
Then Dedi Rock showed up:
"Hey, very sorry about this. There was definitely an error however nothing was done manually on this end. It appears it was automatic. We are getting to the bottom of it now to make it right (we have never seen this error before). If you should choose to continue with us I will compensate you a free month or two for the trouble, if not I will process the refund in full."
Dedi Rock, the provider, replying in the thread
Apology in the first four words. A specific mechanism. An admission of not knowing the cause yet. Two concrete remedies, one of which costs them the customer and the money. The thread title was then edited to "Dedi Rock payment processing hiccup - resolved," which is the forum's permanent public verdict on that accusation, sitting in the URL forever.
Now the other direction. In late January 2024 Limewave went dark, the whole operation, AS36369, gone. The operator, @Dvo, eventually posted at length over on OGF: the shutdown had not been planned before the end of Q4, the company was profitable but had missed targets, 62% of customers were paying late, nodes would come back through OVH for about three weeks so people could pull their data. On exit scams he wrote, "The problem with exit scams is that fortunately, they don't exist anymore." On chargebacks: "If people think paying $12/yr for a service, using the service for 6 months, then charging back the full $12 when they're only lawfully entitled to a $6 refund, I'm not going to sit there and fuck around with arguing with people."
It was thousands of words. The community's response to all of it fit in one line, from @MrFd:
@treesmokah put the reading plainly: "Funny, basically exit-scamming but saying he isn't and deflecting." Members went to their banks. @Blohsh, who had a year prepaid and around $250 in credit, was one of many.
Same forum, same mechanism, opposite outcomes, and the length of the response had nothing to do with it. Dedi Rock wrote four sentences and kept its reputation. Limewave wrote an essay and lost everything. What separates them is that one of them accepted the cost and the other explained why the cost was somebody else's fault, and that distinction is genuinely hard to fake under pressure in public, which is exactly why the community weights it so heavily.
There is a rule layer under all this now. Since June 2026, a negative review posted on LowEndSpirit without proof goes to the Rants section, which is de-indexed. The complaint still exists, members can still read it, and it stops appearing in Google against the provider's name. That is a sharper piece of design than it looks: it separates "I want to warn people" from "I want to permanently damage a company on the strength of my say-so," without requiring a moderator to decide who is telling the truth.
The deadpool list as a trust ledger

Nobody is assigned to maintain it. It updates itself every time somebody gets burned.
Institutions remember through records, audits and filings. This community remembers through one enormous thread. The "2015 Deadpool List" on LowEndTalk ran up more than 13,000 views and 265 replies, and it does the job a credit bureau does, by completely different means: it aggregates dispersed private experience into one checkable public record.
Read as a trust document rather than a history, what it answers is a question no single member could answer alone. Has this company already burned people, and how. Somebody evaluating an unfamiliar provider can search that thread and inherit a decade of collective memory they were not around for. BigVPS.io, Viral VPS, Haphost, BlueVM, GoodHosting, Heroicvps, onebesthost.com, all sitting there in public.
The record is more careful than a blacklist would be, which is what makes it usable. GreenValueHost was salvaged by XFuse/TacVPS and later absorbed by Hostress. NatVPS and 32mb.club went to MyServerPlanet. Reversehost's clients ended up at HostUS. Peak Servers was bought outright by ServerHub. Neximweb just discontinued its VPS plans and carried on doing something else. "Acquired" and "vanished with your data" are different outcomes, and the thread distinguishes them, because the people writing it were the people affected and they cared about the difference.
The single most damning entry in the whole ledger is not about a provider at all. In December 2019, twenty separately branded budget VPS companies, sharing page structure, copied marketing text and the same CAPTCHA implementation, sent an identical shutdown notice within hours of each other and went dark. Seventeen of the eighteen hosts advertised on the community's own deal-listing site in the preceding two months were among the twenty. The record kept by the community indicted the community's own promotional channel, in public, and stayed there.
What makes this ledger durable is that nobody maintains it. There is no custodian, no assigned role, no funding. It updates passively, every time somebody who just got burned writes down what happened, mostly so the next person does not have to find out the same way. That is a different model of institutional memory than any formal archive, and its running cost is zero.
Second-order trust, or who vouched for the voucher

Almost nobody verifies a provider directly. They trust somebody who did.
Here is the part that undercuts the tidy version of this story: most trust here is not first-hand at all. Very few members personally evaluate a provider. They trust somebody whose judgment has been reliable before, who trusted somebody else, and so on. That is second-order trust, and the system runs on it far more than on independent verification.
This is unavoidable and mostly fine. Nobody has time to research every provider mentioned here or read every complaint thread to the end. Second-order trust compresses years of distributed evaluation into "people whose judgment I have tested seem comfortable with this," which lets one person act on far more information than one person could ever hold.
The clearest artifact of it is this forum's own FAQ. A new member called @Joseph asked, in a thread, what LES was and where it came from. @bikegremlin, a member with no staff role at the time, wrote an 8-minute article answering it on his personal site. That article was then republished, with permission, as the forum's official FAQ. Nobody on the admin team wrote the document that explains this place to newcomers. A volunteer did, because somebody asked, and the community adopted it. The same logic put him in a moderator role in 2022, after @Mason and I stopped appointing people and asked the membership instead, in a public thread that attracted several joke bitcoin bribes alongside the real nominations.
The most expensive version of this I have watched involved no forum thread at all. When NexusBytes was dying, its owner @seriesn seriously ill and its infrastructure gradually running out of money, @jarland, who runs the competing email host MXRoute, quietly funded its continued operation for months so that a rival's customers had time to migrate their data out. He was under no obligation and got no forum tag for it. What he got was a reputation that now travels ahead of him, which is the whole currency this system runs on.
The failure mode is exactly what you would expect. Errors propagate rather than staying local. A member with ten years of good calls who vouches for the wrong provider does more damage than a stranger making the identical claim, precisely because the track record is what made the recommendation worth anything. There is no mechanism to catch that in advance. There is only the slow public correction from the last section, where somebody eventually posts a contradicting experience and the chain re-evaluates itself.
What keeps it from collapsing into an echo chamber is the number of chains running in parallel. A recommendation that traces back to several unconnected members with their own separate track records is worth substantially more than one that traces back, on inspection, to a single enthusiastic source. If you are reading this community from the outside, that is the most useful habit to steal: before weighing a recommendation, work out how many independent people it actually comes from.
There is no verified badge, and then in 2026 there nearly was

Nobody certifies your judgment here. The entry gate, though, just got a vote attached.
It would be tidier to end this with a description of the verifier role: some recognised status, earned through a defined process, marking certain members as authoritative. That would be false. There is no such title. Nothing on this forum certifies that a given member's judgment is sound, and no tag means "believe this person." OG marks tenure. Content Writer marks contribution. Hosting marks a commercial interest. None of them is an opinion about whether you are right.
That absence has a real advantage, and it is worth naming because it is the reason not to fix it. A formal verifier tier is a single point of capture. Whoever decides who gets verified decides whose word carries official weight, which rebuilds the exact centralised authority that this community was founded to get away from. Distributed credibility is slower and harder to explain, and it cannot be captured by controlling one role.
That is the principled version. Here is what actually happened in 2026.
In June, provider vetting became formal: a new provider now applies through the registered-providers page, and a public thread is opened so members can weigh in before the tag is granted, with automated voting behind it. Then, mid-year, the same treatment came for members. New registrations answer a question with a minimum answer length, in one shared new-members thread, and the community votes. At -7 they are auto-banned. At +7 they are promoted to standard member. Until promoted, they cannot see offers or domain sales and cannot start threads. Only members with at least 25 karma can vote, a threshold Anthony Smith (@AnthonySmith) said had been discussed at 100 and deliberately left low to see how it went.
The numbers he reported on 11 August were stark: new memberships down 66% over thirty days, new members posting in topics up 141%. Bots filtered, real people participating faster.
His own framing of the change was the interesting part:
"the previous system was 1 question and 1 person deciding, it's just more visible now."
Anthony Smith (@AnthonySmith), LES founder and admin, on the new member verification system
The argument that followed is the thing worth reading, because the community immediately found every failure mode a formal system introduces. @somik argued that anonymous downvoting has no accountability attached and discourages legitimate signups. @treesmokah, after a new member was downvoted for wanting hosting for something politically questionable, argued that community voting produces emotional judgment where neutral staff judgment used to sit, and compared it unfavourably to Reddit. @ahnlak countered that vague phrasing in a hosting request is itself a signal. @MichaelCee resolved it against the house rule: if you're racist, you're a dick. @Lee complained the new-member threads were cluttering the homepage. I proposed raising the promotion threshold to reduce how volatile the voting is.
Notice what got formalised and what did not. The community built a gate, with a number attached, for entry. It still has not built anything that certifies judgment, and nobody in that argument proposed one. You can now be voted into the room. Nothing votes on whether you are worth listening to once you are in it, and that distinction is the load-bearing one.
Part 3 is about where all of this breaks: the pile-ons, the unfair outcomes, and what actually transfers to a community that is not this one.
“Technology is best when it brings people together.” – Matt Mullenweg




Comments
4 minutes. I think the content partially rehash parts of previous blog.
I'd recommend cover the user-fault and host&user sharing fault.
As for the trust-graph, maybe add @jsg and @yoursunny?
They are related to each other. Instead of having everything in one series, it's broken up.
Of course some things will reference other blog posts and threads on the forum.
“Technology is best when it brings people together.” – Matt Mullenweg