Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

As part of the registration process with hetzner.de, you have to send them scans of personal documents (such as passport, drivers license or similar).

I asked them just now if these systems were compromised and they promptly replied:

"The system that stores scans of ids, credit cards and so on was not compromised. In addition to that, we delete that information after 21 days."



"you have to send them scans of personal documents (such as passport, drivers license or similar)."

What? Seriously?

"In addition to that, we delete that information after 21 days."

Hmm, do they delete the info that ends up on backup copies? How do you know they even actually delete it in 21 days? It's not like there is a third party even auditing which you can rely on. (Not that I'd ever do that for something like this anyway, I would just find another provider.)


Yes seriously, here is what they asked me on first order with them:

"Since you're a new customer with Hetzner, we ask you for a scan of your passport or ID card (authenticity check). It's only necessary for your first order with us.

Please send the scan by fax or as an email attachment."

When they say they delete it after 21 days, as they did in the mail I've just received, I trust them. I find their communication on this matter, as well as previous matters, open and serious.


not true for all customers - I needed to send them nothing of the kind (in the US)


This was dedicated servers (root servers they call them) - and I'm from Europe.


they haven't been doing this forever, so if you've been a customer for a while, you might not have been asked.

they also don't ask business customers (might not be true for all countries) if they supply certain details about their business.


Hey - I didn't have to provide anything but a CC number and I'm based in Europe. We don't have a huge account, how many boxes did you order?


I did need to send them scans of ID documents and I am in the US.


If they're proper backups then they're offline and you don't have to worry about them getting hacked.


They might be stolen.


Okay, but stealing a backup gets you 21 days of those documents, the same amount you can get from the live system. There is no need to worry about backups in particular.


Correct me if I'm wrong, but if you had a backup from 15 days ago, wouldn't that backup contain documents 21 days prior to it? So in effect: up to 36


The backup will have documents from 36 days ago through 15 days ago: 21 days.

If you're worried about someone stealing your entire backup system then you have bigger issues.


Is this outside of Germany? I rent two servers and I never sent any ID.

This shit is annoying. I think it have been only 6-8 months since the managed server part of Hetzner (KonsoleH) got hacked. Now the VPS/root server part (Robot) got hacked. I understand that both incidents are completely different and it seems that they might've learned a thing or two from the KonsoleH-hack, but still. My address data and my bank data are very likely to be compromised.

But then, changing the hoster doesn't make any sense. My data is somewhere out there, can't get any worse I guess.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: