I asked them just now if these systems were compromised and they promptly replied:
"The system that stores scans of ids, credit cards and so on was not compromised. In addition to that, we delete that information after 21 days."
I asked them just now if these systems were compromised and they promptly replied:
"The system that stores scans of ids, credit cards and so on was not compromised. In addition to that, we delete that information after 21 days."
What? Seriously?
"In addition to that, we delete that information after 21 days."
Hmm, do they delete the info that ends up on backup copies? How do you know they even actually delete it in 21 days? It's not like there is a third party even auditing which you can rely on. (Not that I'd ever do that for something like this anyway, I would just find another provider.)
"Since you're a new customer with Hetzner, we ask you for a scan of your passport or ID card (authenticity check). It's only necessary for your first order with us.
Please send the scan by fax or as an email attachment."
When they say they delete it after 21 days, as they did in the mail I've just received, I trust them. I find their communication on this matter, as well as previous matters, open and serious.
they also don't ask business customers (might not be true for all countries) if they supply certain details about their business.
If you're worried about someone stealing your entire backup system then you have bigger issues.
This shit is annoying. I think it have been only 6-8 months since the managed server part of Hetzner (KonsoleH) got hacked. Now the VPS/root server part (Robot) got hacked. I understand that both incidents are completely different and it seems that they might've learned a thing or two from the KonsoleH-hack, but still. My address data and my bank data are very likely to be compromised.
But then, changing the hoster doesn't make any sense. My data is somewhere out there, can't get any worse I guess.