Skip to content

Hetzner pulled my site over a bogus claim

Web Hosting by haroldgsm 24 replies 2.5K views
5 #1

Twenty years and I've watched DMCA turn into a performance art for lawyers.

Contabo used to pull whole servers on a single email back in '08. No questions, no receipts, just gone. Now Hetzner and the rest want development logs for text? That's a bar nobody can clear unless they're running git commits on WordPress drafts.

Your writer's payment and an affidavit should've been enough for any shop with half a spine. The timestamps you handed over are more than most folks bother collecting. But here's the rub—providers figured out that "process" means "delay until the complainant exhausts themselves." Cheaper than actual review, and the scraper keeps paying that monthly invoice.

I've seen this script with OVHcloud too. They'll stall through three rounds of "insufficient evidence," each time moving the goalposts another ten yards. By round two the infringer's ranking anyway, and you're out lawyer fees chasing wind.

The normal course? There isn't one anymore. Used to be DMCA meant something when hosts feared safe harbor loss. Now it's checkbox theater. Your real play is filing with the registrar or going upstream to whoever's feeding Hetzner their bandwidth. That, or accept that chasing scrapers is a second job with no paycheck.

Kids these days think a takedown notice is a magic button. Mark my words: it's a paper airplane into a hurricane.

IPv4, IRC, and irssi — fight me
1 #2

Actually, (and I say this with some sympathy), Hetzner's abuse pipeline has been (notoriously) trigger-happy since they pivoted from domain parking. Your "development logs" request is (almost certainly) a canned response from a tier-1 desk that outsources to a ticketing farm.

For context: OVHcloud pulled one of my LXC hosts last autumn over a (clearly) fraudulent report. Took eleven days to get a human who understood what WHOIS even meant. (maddening).

A $2/mo price band buys you automation, not adjudication. If you need a provider whose abuse desk can parse headers without escalating to "legal@", RackNerd's KVM line has (in my limited experience) actual engineers on rotation. Vultr too, though their network is (oddly) congested in EU evenings.

(seriously): move anything you care about to a box where "unlimited" isn't in the marketing copy.

4 #3

I have been on the Linux from 2012 and this is why I do not touch the shared hosting. The "unlimited" is the lie for the people who do not read.

Hetzner is doing the same what Contabo did to my friend in 2015. The server is gone because somebody sent the email. No proof, no looking, just click and delete. The development logs for the blog post is the funny question. What development logs. It is the WordPress.

I am using OVHcloud now for my things and the spreadsheet for the prices. The .io domain is what I used to pay for three months of server and now it is the one year of domain only. The prices are not stable and this is the other problem.

The affidavit is the good move but I am thinking they will ask for the blood sample next. The abuse desk at these places is the person who read the script one time and now is the expert.

apt-get install everything
4 #4

Going after the registrar is overkill unless you've got a trademark in play. Most registrars won't yank a domain over hosting disputes.

I've seen this dance before. Back when Contabo ran their abuse desk like a vending machine, the real play was always to lawyer up fast, not chase domain takedowns.

visit twice: install and decom
#5

Actually the Safe harbor protection is something that Hetzner does not want to lose because when they pivoted from domainparking they built the entire BusinessModel on cheapMassHosting and one Lawsuit about ignored DMCA would destroy the ProfitMargin completely.

Actually I have seen this at OVHcloud where they processed a BogusClaim within four Hours and the Site was down before the Owner even saw the Email notification. The Automation pipeline is the Problem because there is no HumanReview in the Loop and the False positive rate is going up and up.

Actually the $150000 is the theoretical Maximum but in Practice the Settlement is much lower and the AttorneyFees are eating the Remainder so the Small site owner is not getting anything from this Route. Actually the better Approach is to document everything and move to RackNerd where the AbuseDesk is actually staffed by People who read before they click Suspend.

3 #6

Lawyers are a luxury tax on the little guy. I've watched folks mortgage months of revenue chasing a principle.

Hetzner counts on that math working in their favor. They did the same pivot dance Contabo tried—bulk accounts, thin margins, automated enforcement.

Your real leverage is the cancellation churn hitting their dashboard. Nothing moves a provider faster than ten tickets in a row asking where the sites went.

IPv4, IRC, and irssi — fight me
4 #7

Actually, (and I say this as someone who's had to (gently) explain LXC networking to their own mother), the whole "forward it to your solicitor" posture only works if Hetzner hasn't already decided you're more trouble than your annual invoice.

I watched a mate go through something (vaguely) similar with OVHcloud last year. Filed a (perfectly valid) counter-notice, documented everything, and they still sat on it for six weeks because the complainant had a (marginally) higher ARPU. The protection racket logic isn't about legal merit. It's about whose churn hurts less.

What I'd actually want to know: did they suspend the account outright, or just yank DNS? Because if it's the latter, (and this is where it gets (mildly) technical), you can sometimes pivot faster than their abuse team can process a response. I've run a backup origin on RackNerd for a (particularly) litigious project and just repointed when the first host got skittish.

The DMCA safe harbour thing is real, (obviously), but plenty of these budget operations treat it as a suggestion rather than architecture. They'd rather eat a (small) chance of liability than staff a compliance desk properly.

Not saying roll over. Just saying measure your energy against whether you're fighting for the principle or for the site. (Sometimes those are different wars.)

Pat.

#8

I have seen this before with the cheap hosts. They hire the people who read from the script and the script has only one page.

Hetzner is not the worst, I had the OVHcloud do the same to my friend in 2019. He sends the proof, they ask for the proof again, he sends again, they say the case is closed. The loop is the feature, not the bug. They know you will give up because the server costs less than the bus ticket to the lawyer.

The India DC is the red flag for me. Many of these brands rent the rack and put the sticker with their name. The upstream does not know your name, only Hetzner. So you are trapped in the loop with the script readers.

My advice is the same since 2012. Own the hardware or rent the bare metal where you can point the IP to yourself. The shared hosting is the casino, the house always wins and the terms are the wall of text nobody reads.

I do not use the apostrophes because the key is the broken, but my server is the mine and nobody pulls it for the bogus claim.

apt-get install everything
#9

@OP — upstream escalation works, but only if you know who you're actually yelling at. India DCs get weird because a lot of those networks are white-label reselling bandwidth three layers deep. You traceroute out, hit some IP in Mumbai, and half the time that's just a cross-connect to a carrier hotel where Hetzner doesn't own the fiber.

I've chased this exact ghost with OVHcloud before. Thought I had their upstream nailed down, turns out I was yelling at a layer-2 transport provider who'd never even heard of them. Waste of a week.

If you're dead set on the upstream angle, look for the ASN in the whois, not just the netblock. Check if they're announcing their own space or if it's leased from someone like Contabo or RackNerd. That changes who actually has leverage over them.

Real talk though — the affidavit and payment proof should have ended this. DMCA doesn't require you to prove a negative, they need a *valid* takedown notice. Sounds like Hetzner's abuse team is treating every ticket like a negotiation, which tells me they've been sued before and got spooked, or they've never been sued and don't care.

Either way, documenting their runaround matters if you ever need to show a court they were willfully blind. Screenshot everything with timestamps. Their "investigate again" loop is practically an admission they don't know what they're doing.

Carl

visit twice: install and decom
#10

Actually the ASN lookup is the good advice but Hetzner is announcing the own Space from the RIPE allocation since 2003. They are not the reseller in Falkenstein or Nuremberg, they own the Building and the Fiber.

Actually I have checked this because I was thinking the same about the upstream. But Hetzner is the upstream. The white-label Problem is more at the Contabo India DC where they rent the Rack from the third Party and the local Carrier is doing the CrossConnect.

Actually for the OP I would suggest to look at the Vultr because their Abuse Desk is in the same Timezone as the US customers and the Bangalore DC is not the only Option. The Cloud Compute starts at $5 and the Block Storage is separate so you can snapshot before the Incident.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft