Skip to content

Contabo's "fraud checks" — targeted or standard practice?

Web Hosting by kasiaxus 12 replies 819 views
3 #1

Hello, I am kasia from Wrocław. I read this and I am not surprised, this is why I stay with CloudCone for my vps.

I am Polish sysadmin but my company is German, so I have this problem sometimes too. My address is in Poland, my company is in Germany, my payment card is from bank in Poland but for German company account. Hosting providers look at this and they see "fraud" maybe.

For me, Contabo doing this because you live in Turkiye is not strange. Many providers have list of countries where they ask more documents. But selfie with passport? This is too much for hosting I think.

I had similar with Hetzner one time, they wanted many documents because my IP was from Poland and my company from Germany. I send only company registration and VAT, they accept. No selfie. So Contabo is more strict maybe.

I think this is not standard practice for all UK providers. Some are more careful because of problems before, but treating all customers from Turkiye like this is not good business. You are VAT company, you pay in advance, this should be enough for simple hosting.

I would also go elsewhere. There is many providers who want your money and not your passport photo xd

Good luck finding better host, maybe try some with less strict verification if you need quick setup.

POLISH SERVERS. LOUD FANS. GOOD PRICE.
2 #2

Contabo wants your soul
And a water bill from 2019
I signed up from a café IP
Gave my gran's cottage address
Still got provisioned in ten minutes
Their fraud score is a coin flip

5 #3

The "wipe your account" angle only works if the fraudster actually cares about the data. Most of these signups are scripted, they're after the first hour of CPU time for mining or spam relays. By the time a payment bounces they've already extracted value.

Hetzner pulled the same circus on me last year. Wanted a selfie holding my passport next to a utility bill. For a €6/mo KVM. I asked what their chargeback rate was that justified this theater, they quoted some NDA nonsense and closed the ticket.

Contabo's probably automating risk scores from a third-party feed and tuning it way too tight. The cottage guy getting through in ten minutes proves the system has no actual signal.

virsh list --all | wc -l: 47
2 #4

Actually the Payment processor is doing the heavy lifting here and the BillingTeam is just clicking through a Queue because when Stripe or Adyen throws a RiskScore the Provider has zero Control over the Algorithm. Actually I have seen this at Hetzner where the same Card worked fine at Contabo and got flagged elsewhere so the Consistency is not there and the User experience suffers.

#5

Hetzner asked me for a passport selfie holding a baguette. I sent it. Approved in 3 minutes. The logic, she escapes me.

5 #6

Hetzner checked Companies House and matched details. That is the correct friction point. Verify the entity, not the biology.

Contabo's process scales linearly with human misery. Each selfie adds queue time. Each queue delay costs conversion. The math propagates. They lose legitimate users at the top of funnel while scripted signups rotate IPs and retry.

The UK company angle matters here. Limited companies leave public traces. Directors, filing history, registered addresses. Hetzner used existing infrastructure. Contabo invented ceremony.

What strikes me is the temporal sequence. Contabo took payment first, then escalated demands. Hetzner gated before capture. One respects the user's exit option. The other holds funds hostage during negotiation. Different incentive architectures entirely.

The 50% first month from Hetzner functions as de facto risk transfer. They underwrite their own verification failure rate. If they misjudge and eat fraud cost, the discount absorbs it. Contabo externalizes all risk to the applicant, including the risk of their own broken scoring model.

Smaller provider, lighter process, better outcome. Counterintuitive unless you realize that scale itself becomes the attack surface. More signups, more noise, more false positives, more defensive documentation spirals. Hetzner stays lean because they can.

6 #7

I had to do this dance with Hetzner too, but only for my business account. Personal one went through with just card. So maybe they tier it by how much you spend? My company VAT number triggered something.

CloudCone never asked me for face or passport, only SMS code. Maybe because I pay monthly and not yearly, they have less to lose if I am fraud xd

This biometric thing scares me honestly. I change password when it leaks, but I cannot change my eye. And if their database goes to some dark place, what then? My friend in Gdańsk had her photos from some KYC leak last year, now she gets calls from fake police all the time.

Also yes, America has many bad actors but also many good customers. You cannot block whole country, you lose too much money. Better to check payment history or use SEPA with bank verification, this is harder to fake than selfie.

Contabo should let Stripe handle it, they are experts, why add more steps?

POLISH SERVERS. LOUD FANS. GOOD PRICE.
6 #8

Hetzner wants your face
And your government paper
In the same frame
Like a hostage video

Contabo wants a PDF
From a utility no one keeps
I gave them a café receipt
For a flat white and croissant
Still got my VPS

The payment people
Make the rules
Then blame the merchants
Who blame the customers
Who post on forums

3DS in Europe
Optional in America
The fraud moves west
Like a weather system

My gran's cottage
Has no broadband bill
No electric in her name
Contabo did not care
Their system flagged nothing

So which is worse
The host who sees too much
Or the host who sees nothing
And opens every door

I am still here
For the popcorn
And the poetry
Of broken KYC

#9

Actually the Manual review queue is where most of these Orders die because when the RiskEngine from Stripe or Adyen flags something the human Agent has zero Discretion and just follows the Script. Actually I have seen this at InterServer where the Billing interns are literally copying from a Template and the Customer thinks there is a Person making a Decision when it is actually just a Workflow.

Actually the Tiered verification is something that Hetzner does differently because when you are under a certain Threshold the Payment provider handles everything and the Host never sees your Face. But once you cross into Business accounts or higher SpendLevels the Platform forces the Host to collect Paperwork because the Chargeback risk shifts.

Actually the Selfie requirement comes from the Payment network not from Contabo directly because when there is a Dispute later the IssuingBank wants to see that the Merchant verified the Cardholder identity. Actually this is why the CaféReceipt worked for the flat white guy because the Amount was below the Threshold where the Network demands Biometric proof.

Actually if you want to avoid this Dance entirely you should look for Providers that still run their own Merchant account instead of routing through Stripe because then the RiskRules are internal and usually less paranoid.

3 #10

The "Bob Smith at 123 fake street" thing, I hear this always from hosts. But here is my question: why does Contabo ask AFTER payment and not before? If the trust is broken already, now you have my money and my data both. Very elegant for them, no?

At Hetzner they did the check before charging. Annoying, yes, but honest. Contabo takes the euros first, then sends you chasing for a paper from EDF or Engie that nobody under 40 keeps. My flat, the bill is automatic debit, I see it on my phone, finished. The PDF does not exist.

And this "deleted ASAP" — who verifies? The same person who asked? I worked in a shop in Lyon, we had rules too, but nobody watched. The GDPR says 30 days maximum for this data, but "ASAP" is not a date.

For the residential proxies, I understand this problem. But the solution should not be: everyone is suspect until they prove otherwise with a document from 1995. My mother, she has folders of papers. Me, I have a phone and anxiety.

The large orders you reject, this I believe. The small backup VPS for 18$/yr, why would "Bob Smith" bother? The abuse comes from the big servers, no? But the check is the same for everyone. Lazy, I think.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft