Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Hetzner reuses disks to reduce cost. So a "new" server might come with old disks with shorter life-spans. Thats all okay, especially as they are not a 'premium' host. As long as you are aware of this, they are a good host. As others said, you can ask for new disks at a price.

Also be aware that their abuse department shoots first and asks later. I know of servers that were off the grid for multiple days without access because of abuse on a friday - everyone relevant went on weekend.

They _are_ cheap and that comes with a few trade-offs. Doesn't make the product bad, necessarily. If you are cash-strapped and need raw power, buy without hesitation.



When they get an abuse mail for your server, all they do is forward it to you. You then have 24 hours to fill out a form detailing what you did to stop whatever caused the abuse message.

If you ignore the 24 hour limit, it will just escalate the case to a support person, who then decides what to do. There is no automatic shutdown, especially not for multiple days.


This is not true. I've had automatic shutdown without warning. Had to send them some documentation/evidence of solving the issue before they would put me back online on a public IP address.


I had a server shut down after it started scanning other servers from other hosters for vulnerabilities. Taking it offline immediately is what I would expect any sane hoster to do.

Not being available for resolution is a different thing.


I don't see logic behind not powering off an abusive machine, no matter if it's saturday night at 3am. The internet doesn't run on your schedule. If your server has been compromised (or not, heck we all know there are baddies out there), and it's actively hosting a phishing site, taking part in a DoS attack, etc, why shouldn't a provider be allowed to take action to protect their network, other users in general, and at the end of the day, perhaps the reputation of your site as well?

Blaming providers for the inability to secure your server is incredibly irresponsible. Unless service was interrupted because Hetzner misread an abuse report for another server (which is highly improbable and most likely is not what you implied in your original statement), you shouldn't ever be pissed that your host took action to prevent abuse from occurring.


The problem is not that they cut off your (possibly rooted) server. Thats good practice and I don't blame them for that.

The problem is that relevant persons assisting you in resolving the problem (e.g. giving access using a secure connection) are not reachable over the weekend and take their time. That is a problem of the provider.


that is the biggest issue with unmanaged providers. people don't recognize what "unmanaged" means. You pay for a hosted server, you're not paying for an on-call admin to fix your joomla on turnkey ubuntu setup.


I am also not calling for that. They provide physical boxes, so I expect them to be on call when there is an issue with a physical box. Especially when talking about providers of hetzners size.


You assume a definitive definition of "abusive".


and you don't?

things that warrant disruption of service and are defined as abuse:

1) any type of DoS attack

2) phishing

3) malicious activity (ssh brute force, port scanning without consent, etc)

4) cp

5) anything that generates a court order with jurisdiction, including DMCA if you have anything to do with the US

6) spam/spamvertised site

there are more things that can be defined as abuse, but the others are more or less discretionary, imo.


Having worked an abuse desk for quite a while, I can tell you a non-trivial number of reports are clueless reporters or people trying to get competitors/enemies/etc. boxes shut off.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: