Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

My Hetzner account has been hacked, their security is really flawed.

2»

Comments

  • risharderisharde Host Rep, Veteran

    @DP said:

    Always enable 2FA, if and when available.

    This is good advice, I just wanted to add that there's been news that even this is not always enough (but there's very little on what can be done when this is not enough). I'm really surprised when I hear that hackers are bypassing even 2FA (in terms of how they are able to do it). I'm not surprised that there are hacks in general.

  • @rsk said:

    @lexiluna67 said:
    Experiencing a hacked Hetzner account is distressing. Reach out to Hetzner support immediately to report and resolve the issue. Security incidents can happen, but a swift response from the provider is crucial. Collaborating with their support team will help secure your account and shed light on any potential vulnerabilities for improvement.

    Why the sudden necro? Did your reply add any value?

    Leave the ChatGPT bot alone (-:

    Thanked by 2marcopolio Kebab
  • @JabJab said:

    @rsk said:

    @lexiluna67 said:
    Experiencing a hacked Hetzner account is distressing. Reach out to Hetzner support immediately to report and resolve the issue. Security incidents can happen, but a swift response from the provider is crucial. Collaborating with their support team will help secure your account and shed light on any potential vulnerabilities for improvement.

    Why the sudden necro? Did your reply add any value?

    Leave the ChatGPT bot alone (-:

  • @jenkki said:

    @Levi said: 2FA and common sense is more than enough to use any system securely.

    And if you lose it, what do you have to do to prove it, for example? A phone number that receives a confirmation SMS or something else? You'll never log in again. Or just the system will glitch and won't let you accept the confirmation code. These 2FA can cause more problems than good.

    Usually it requires to print out backup codes and keep it safely. Furthermore, you can contact support and initiate account recovery procedure (invoices, passport etc.). There is no problem without posibility to resolve it.

  • There is by default a limit 10 servers.. So that should be also by passed then..

  • @Levi said: Furthermore, you can contact support and initiate account recovery procedure (invoices, passport etc.)

    Yeah. And if someone doesn't want to give out their personal information, then what? Or an anonymous registrant? It's easier to recover your password via e-mail than to go to support and waste your time. Although if you lose your password to the mail, there may be problems too. But it is less likely.

  • @jenkki said:

    @Levi said: Furthermore, you can contact support and initiate account recovery procedure (invoices, passport etc.)

    Yeah. And if someone doesn't want to give out their personal information, then what? Or an anonymous registrant? It's easier to recover your password via e-mail than to go to support and waste your time. Although if you lose your password to the mail, there may be problems too. But it is less likely.

    If you use their services - you apply their terms. If not - look for another suitable company. No one forces you to use any service or tool you don't like. Wonderful freedom.

  • PulsedMediaPulsedMedia Member, Patron Provider

    TL;DR; OP's password either leaked or was weak, in combination with the email address used.

    Thanked by 1hcea520
  • PulsedMediaPulsedMedia Member, Patron Provider

    @emgh said: Just to note: I think Hetzner does 2fa email verification on suspicious logins, but obviously, not always

    You wouldn't believe how many people use intentionally and knowingly insecure e-mail accounts, judging from all the flame we got because we e-mailed service passwords just like every other provider out there.
    The demands for somehow magically, perhaps with telepathy to give users the passwords.

    This was not 1 or 2 instances. Then again it was that R named s**thole. Only place i've ever seen where that has happened, and also only place which would start a flame thread because ticket took 34 minutes to answer and resolve AND only place where a CAPITAL or non-capital letter would cause a bunch of flame (typo)

    @DP said:
    Security has layers and is everyone's responsibility.

    and is a process, not a project.

    @jar said:
    Pretty sure you could say much of the same of everyone using WHMCS and that's like every provider here. If that many are flawed, perhaps you'd be better off adjusting your expectations. It's generally best that expectations and likely reality stay fairly close to each other. Also in places where 2FA is implemented and not quickly bypassed, you generally want to have it on.

    WHMCS sends email when you create services and supports 2FA. We actually just enabled TOTP 2FA option for users. Probably will add Yubikey soonish too.

    @jenkki said:

    @Levi said: 2FA and common sense is more than enough to use any system securely.

    And if you lose it, what do you have to do to prove it, for example? A phone number that receives a confirmation SMS or something else? You'll never log in again. Or just the system will glitch and won't let you accept the confirmation code. These 2FA can cause more problems than good.

    This is true.
    and Call/SMS Based -> SIM cloning exists.

    Email -> if your PW leaked, probably your email is compromised too.

    etc.
    Not the silver bullet people think it is, and can cause issues.

    Snail Mailed paper OTP is quite secure tho, and usually easy to see if tampered with in the postal service.

    We dropped one supplier/wholesaler from our suppliers because they enforced Microsoft Authenticator 2FA; It just got way too annoying to even login.

  • yoursunnyyoursunny Member, IPv6 Advocate
    edited January 2024

    @emgh said:
    Obviously, 2fa based on a SECOND device is better, but still

    I turn off 2FA wherever I can and especially avoid device based 2FA.
    What if my house burns down and all my devices become ashes?
    The first thing I need after the house burns down is to renew my Advin chess special and VirmAche $8.88, because priorities.

  • @yoursunny said:

    @emgh said:
    Obviously, 2fa based on a SECOND device is better, but still

    I turn off 2FA wherever I can and especially avoid device based 2FA.
    What if my house burns down and all my devices become ashes?
    The first thing I need about after the house burns down is to renew my Advin chess special and VirmAche $8.88, because priorities.

    Thanks to reminding me to renew my Advin non-chess special

    Thanked by 1yoursunny
  • @yoursunny said: I turn off 2FA wherever I can and especially avoid device based 2FA. What if my house burns down and all my devices become ashes?

    That's what I'm talking about.

    I once traveled to another country and accidentally forgot my phone where I had to accept a password to log into Paypal.

    When I needed money, I couldn't log into my account. Paypal kept blocking me from logging in because the country I was trying to log in in didn't match my country where I opened the account. They just stupidly blocked me from logging in for accepting SMS to the number I forgot at home. As a result, I was left without money and asked my friends to send me money to borrow for the way back. In the end I was able to log in to my account only after my arrival.

    After that I really don't want to do it all again.

    I also recently lost an 8 year old account of a domain provider because the mail on which it was registered ceased to exist. And to log in you needed a confirmation.

    So really two-factor verification can do more harm than help.

  • PineappleMPineappleM Member
    edited January 2024

    @jenkki said:

    @yoursunny said: I turn off 2FA wherever I can and especially avoid device based 2FA. What if my house burns down and all my devices become ashes?

    That's what I'm talking about.

    I once traveled to another country and accidentally forgot my phone where I had to accept a password to log into Paypal.

    When I needed money, I couldn't log into my account. Paypal kept blocking me from logging in because the country I was trying to log in in didn't match my country where I opened the account. They just stupidly blocked me from logging in for accepting SMS to the number I forgot at home. As a result, I was left without money and asked my friends to send me money to borrow for the way back. In the end I was able to log in to my account only after my arrival.

    After that I really don't want to do it all again.

    I also recently lost an 8 year old account of a domain provider because the mail on which it was registered ceased to exist. And to log in you needed a confirmation.

    So really two-factor verification can do more harm than help.

    This has limited usefulness but what I normally do when traveling abroad is I always leave my home computer on with remote control access enabled. It has saved my ass perhaps more times than I want to admit.

  • Don’t blame their security if you don’t have 2fa enabled

  • Just enabled 2FA after seeing this post. Thanks OP

    Thanked by 1Erisa
  • lovelyserverlovelyserver Member
    edited January 2024

    @vivucloud said:

    @bench said: don't blame them, it's your fault

    It was my fault that the account was exposed, but the protection through steps to verify whether it was the right user or not was their vulnerability.

    That's true. It is your fault for not having activated 2fa. But is also true that Hetzner sucks at security level. They don't care if you get a bill, because they will make you pay it. So they can say and do anything they want because you'll have to pay anyway. And they will just blame you.

  • mgcAnamgcAna Member, Host Rep

    @vivucloud, did you talk to hetzner yet ?

  • @lexiluna67 said:
    Experiencing a hacked Hetzner account is distressing. Reach out to Hetzner support immediately to report and resolve the issue. Security incidents can happen, but a swift response from the provider is crucial. Collaborating with their support team will help secure your account and shed light on any potential vulnerabilities for improvement.

    Not always. Mine got hacked, i showed them proofs. They still requested me to pay that bill. So, it wasn't their fault for an insecure system. The customer has to pay anyway.

    Since then I buy just prepaid services. No hourly bills. Not paid, no service.

  • @lovelyserver said:

    @vivucloud said:

    @bench said: don't blame them, it's your fault

    It was my fault that the account was exposed, but the protection through steps to verify whether it was the right user or not was their vulnerability.

    That's true. It is your fault for not having activated 2fa. But is also true that Hetzner sucks at security level. They don't care if you get a bill, because they will make you pay it. So they can say and do anything they want because you'll have to pay anyway. And they will just blame you.

    Well it was your fault? Their systems aren't insecure, it's not their responsibility that you reused passwords or had your computer compromised.

  • @yoursunny said: The first thing I need after the house burns down is to renew my Advin chess special and VirmAche $8.88, because priorities.

    Cheers. Just renewed my Advin 32GB-RAM VPS.

    Thanked by 1yoursunny
Sign In or Register to comment.