←back to thread

341 points hlandau | 1 comments | | HN request time: 0.208s | source
Show context
manxman ◴[] No.37963542[source]
A quick warning on hetzner. I needed a personal bare metal machine so signed up.

I was travelling and on an IP in a distant land so their sign up asked for secondary verification via PayPal. All passed and now it’s should get a server?

Nope - next day their support emailed telling me they would not approve my account without… no word of a lie here… either 1: a fax of my passport info page or 2: a scan and email containing the same.

I refused reminding them of GDPR and that email is at best opportunistically encrypted and at worst open to interception.

They replied stating they believed they were GDPR compliant because all they do is use the passport to verify the account and delete the document. They also said I could hide anything sensitive other than my name and date of birth!!

I suggested the process is not GDPR compliant as anyone could intercept unencrypted emails and that they should talk to a lawyer if they did not believe my assertion.

Within a short time the server was approved and online. I queried if they would revise their process in light of our interaction. They did not address the question.

replies(8): >>37963761 #>>37964297 #>>37964364 #>>37964823 #>>37965391 #>>37968710 #>>37970183 #>>37974389 #
1. immibis ◴[] No.37974389[source]
Fax is an accepted GDPR-compliant form of "secure" communication. Yes, many service providers need to ascertain your identity. In my experience, passport photo verification is normal at Hetzner, Hetzner is very aware that not everyone wants to meet the requirements for their service, and they will happily refund you if you decide not to proceed.

This passport verification is required in Germany for any Internet connection. You need to do the same if you sign up for a cellphone plan in Germany. It's a surveillance state.