vps交流

Hetzner泄露部分用户的姓名及邮箱信息


本帖最后由 CloudRaft 于 2021-12-22 00:26 编辑

这问题说大不大,但是说小不小,目前官网还没看到通知啥的。

简单来说:
1. 版权投诉的人会直接拿到被投诉人的姓名和邮箱
2. 知道这个漏洞的人可以查询任意一个HZ机器IP的所有人姓名和邮箱

因为HZ的账户审核策略,泄露的姓名要么是通过护照验证的真实姓名或是Paypal付款人姓名…..

Dear Client

Unfortunately, we recently discovered a data protection incident. From
18 November 2021 to 16 December 2021, there has been an error that
occurred while we were sending abuse messages. While our abuse message
was being sent to you, your name and the email address saved on your
customer account were accidentally sent to the person who made the abuse
complaint.

The underlying cause was a faulty update with the abuse system. That led
to some incorrect data being used in some individual cases.

The data in this situation was sent to the person who created the abuse
complaint, and was only sent to an individual person in each occurrance.
For that reason, we estimate that there is a relatively small chance
that the data will be misused. We have nonetheless reported the incident
to the proper authority, within the required deadline. In this
situation, the proper authority is the Data Protection Supervision
Office for the German state of Bavaria ("Bayerische Landesamt für
Datenschutzaufsicht").

We are very sorry that this incident occurred, and we would like to take
this moment to send you our genuine and heartfelt apology.

Kind regards

Your Hetzner Team

德国佬也不靠谱啊,用GDPR条例起诉hz Hetzner泄露部分用户的姓名及邮箱信息
直接把滥用者的信息发送给了举报者,这不被顺着网线砍?Hetzner泄露部分用户的姓名及邮箱信息
猜猜里面有没有mjj,谨慎为妙
于是一堆mjj邮箱扒了出来
mjj都是假信息,不怕泄露的

watermelon 发表于 2021-12-21 23:55
mjj都是假信息,不怕泄露的

假信息怎么过验证

了解了 下一个

Mio 发表于 2021-12-22 00:01
直接把滥用者的信息发送给了举报者,这不被顺着网线砍?

大部分还是BT侵权,这下怕是版权方狂喜

一点都不关心,毕竟没用过这家机器Hetzner泄露部分用户的姓名及邮箱信息Hetzner泄露部分用户的姓名及邮箱信息