Hacker News new | ask | show | jobs
by darklajid 3810 days ago
Ignoring the childish domain name, hopefully the discussion won't go down that route again - that guy seems quite sincere and explains the situation quite well.

My take away: Don't (blindly) trust Germany, and certainly don't use Hetzner. If he's correct ("Hetzner didn't provide a copy of the confiscation order to me or my lawyer") I'm glad to be the first in this community that runs around, arms flailing, shouting "Hetzner is bad, Hetzner is the devil".

4 comments

About 10 years ago I've been running a popular German blog with a lively comments/discussion area. It didn't take long till the police showed up and took the server hard drives.

To my misfortune the procurator in charge didn't know much about how blogs worked so not only did the police confiscate the server drives but also my private computer.

Turns out someone liked Hitler too much and some other user notified the police.

Since then I haven't hosted anything in Germany. It's just too much trouble because German law regarding insults/forbidden symbols/hate speech is very strict. Policing user comments on a popular site would be a full time job.

Yeah, Hetzner also has this strange habit of spitting out SQL errors when you put apostrophes into forms on their website.

I'd avoid them.

At least a few years ago, shared hosting with Hetzner used to be a complete security mess. By default, every user could access many other users' www directories via SFTP, including loads of PHP config files with MySQL access data inside. No SFTP jails in place, no automated process to prevent 775 (or 777!) permissions. (Yes, you could delete other users' whole www directories.) Real names of all users on the same server world-readable in /etc/passwd. Didn't exactly increase my trust in their products.
As someone who just applied for (and failed to get) a job at a DB company:

Not sanitizing your inputs is unacceptable, even for a newbie. These guys must be really stupid.

They are to big to fail at this point. And based on their price the servers are amazing. (If you dont care about a perfect uptime.)
Is there a place where info like this is tracked? For performance/features you can find some level of information in various forums, but trying to find stories like this is probably difficult.
Hetzner actually has the reputation that they take things down that they think are critical and that they happily coorperate with each official request.

It seems this things are not known outside of the german internet tho. Its a nice hoster, and cheap, but they dont care to fuck around for a few dollars and rather delete/close/remove.