> That literally annoyed me so much even on something like hetzner.
In one word: fraud. I've worked at a company similar to Hetzner, and the "add a credit card first" is the single most effective way to weed out 99% of abusers. People that will each up swaths of compute and mine crypto, ruining the service for everyone. Or hosting CSAM material. Or participating in botnets. Or sending spam. All those makes both the company AND the clients suffer.
You still get the occasional Pakistani bank that allows the emission of unlimited credit cards for fraudsters or the stolen cards (stripe goes a long way for this), but it simply makes the business bearable.
So yeah, we were not thrilled to enforce CC for signup. Believe it or not, even marketing or sales hated it, because it introduces friction in the signup tunnel.
As to re: logged in to open tickets, it is a necessity to avoid customer getting their account stolen. As a customer you receive fake "change your password now!" emails, as a company you receive fake "i've lost my password!" emails. That's the sad way the world is right now. Account theft for hosting providers is a real thing, because the stakes can be very very high.