Live data from Hacker News

NordVPN sued by Torguard for blackmail [pdf]

torguard.net

41–50 of 164 posts

Re: NordVPN sued by Torguard for blackmail [pdf]

#41

NordVPN response https://nordvpn.com/blog/torguard-lawsuit/

"It all started when we received information that led us to finding a TorGuard server configuration file lying in the open on the internet... We hoped that after providing this vital assistance towards securing TorGuard’s infrastructure, they would also cease with their illegal defamation campaign."

So nord is shitty for digging up dirt on torguard because they were mean to them online and torguard is shitty for having these vulnerabilities in the first place. Are there any vpn services run by a company that is neither slimy nor incompetent?

Re: NordVPN sued by Torguard for blackmail [pdf]

#42

Had a quick skim; it seems at a glance like someone from TorGuard badmouthed NordVPN on a youtube comment ( sigh ), so NordVPN apparently in response threatened to disclose "trade secret information obtained by NordVPN regarding TorGuard’s systems" it obtained via a hosting provider TorGuard used which is owned by the NordVPN people. This apparently involved some pretty sketchy stuff like sending people to the house…

Reading the parent pdf vs Nord's response [0] I'm slightly more inclined to believe Nords version of events here... 0: https://nordvpn.com/blog/torguard-lawsuit/

Their response is certainly better written and does have something about the ring of truth to it.

Even taking into account the insanity of legalese that lawsuit was... wordy, at best. Poorly organized and repetitive would also apply.

Re: NordVPN sued by Torguard for blackmail [pdf]

#43

Earlier quoted context omitted.

> On or about May 17, 2019 an unknown individual appeared unannounced at the personal residence of a TorGuard contractor, asking to speak with him about his relationship with TorGuard and the VPN industry This whole thing sounds sketchy AF for NordVPN. While not technically illegal, just approaching a competitor's employee unsolicited at their home (!?) has red flags all over the place.

mind you telling about some privacy company that they have 'trade secrets' which should be exposed is a low blow under the belt... if you have some critical information for its users privacy, then share it... (being privacy advocates and a VPN service themselves.. it would be responsible.) with that in mind, it just sounds like someone with bad temper with too much responsibilities as usually these things turn out to…

They never mentioned that the secrets revolved around user's privacy

Re: NordVPN sued by Torguard for blackmail [pdf]

#44

Had a quick skim; it seems at a glance like someone from TorGuard badmouthed NordVPN on a youtube comment ( sigh ), so NordVPN apparently in response threatened to disclose "trade secret information obtained by NordVPN regarding TorGuard’s systems" it obtained via a hosting provider TorGuard used which is owned by the NordVPN people. This apparently involved some pretty sketchy stuff like sending people to the house…

> What kind of 'trade secret information' could a vpn provider be blackmailed with though? That's easy. A VPN provider has access to all kinds of juicy information, such as who their customers are and what they are up to online. They may have been compromised already, they may sell user data. There are all kinds of things that could be going on that would definitely be stuff they could be blackmailed with. Whether an…

They have definitely been compromised. You can buy lifetime accounts on the darknet for a dime a dozen with suspiciously not-real-person email addresses and passwords. Other VPN services and accounts for sale are much more expensive and you can usually tell at a glance that the credentials were stolen from a real user.

Edit: Perhaps the unimpeded sale of these "hacked" accounts leads indirectly/directly back to someone inside NordVPN? A dirty "trade secret" they wouldn't want revealed..? Seems farfetched but they have not proven themselves trustworthy in the past.

Re: NordVPN sued by Torguard for blackmail [pdf]

#45

Had a quick skim; it seems at a glance like someone from TorGuard badmouthed NordVPN on a youtube comment ( sigh ), so NordVPN apparently in response threatened to disclose "trade secret information obtained by NordVPN regarding TorGuard’s systems" it obtained via a hosting provider TorGuard used which is owned by the NordVPN people. This apparently involved some pretty sketchy stuff like sending people to the house…

Reading the parent pdf vs Nord's response [0] I'm slightly more inclined to believe Nords version of events here... 0: https://nordvpn.com/blog/torguard-lawsuit/

I'm not sure, their response could be fabricated too. I'm interested in if Torguard has any evidence of them physically approaching their employee.

> Within an hour of this in-person and unannounced visit, the same TorGuard contractor received unsolicited correspondence from an employee at NordVPN. This correspondence stated that NordVPN had received certain of TorGuard’s confidential and trade secret information and requested to set up an instant message chat to discuss this with TorGuard.

Also, according to both parties they communicated with each other with evidence. So all either party has to do to claim their innocence is submit the emails/communications they claimed to have.

---

The DDOS part I'm very weary about. What evidence does torguard have that NordVPN was the one carrying out the DDOS attacks? I'll admit I haven't thoroughly examined the entire document, but they don't really seem to state how they know NordVPN was behind the attacks, they just list the dates they were attacked. Given the nature of DDOS attacks, they could be from anyone.

Re: NordVPN sued by Torguard for blackmail [pdf]

#46

Earlier quoted context omitted.

NordVPN has been known to suppress a lot of information about themselves - even the country in which they operate. Given C7 is involved as well I’m very confident it’s true.

And they are closely aligned with other vpn providers that all leveraged micfo (as is stated in this complaint).

C7’s owner is involved with quite a few VPN companies.

Re: NordVPN sued by Torguard for blackmail [pdf]

#47
post #41

NordVPN response https://nordvpn.com/blog/torguard-lawsuit/

"It all started when we received information that led us to finding a TorGuard server configuration file lying in the open on the internet... We hoped that after providing this vital assistance towards securing TorGuard’s infrastructure, they would also cease with their illegal defamation campaign." So nord is shitty for digging up dirt on torguard because they were mean to them online and torguard is shitty for havi…

To be fair this kind of vulnerability is kinda common. All it takes is some AWS bucket to be left public. Surely you've seen it on HN for years? MongoDB for company X found with no password, government AWS bucket left public, etc.

That said it would be a feasible yet simple story to fabricate. The details aren't that important, just saying "we found a file with ip addresses that had services open with no password" is plausible but also not that specific.

Seems like all they need to do is publish their communication now that the vulnerability has been fixed?

Re: NordVPN sued by Torguard for blackmail [pdf]

#48

Had a quick skim; it seems at a glance like someone from TorGuard badmouthed NordVPN on a youtube comment ( sigh ), so NordVPN apparently in response threatened to disclose "trade secret information obtained by NordVPN regarding TorGuard’s systems" it obtained via a hosting provider TorGuard used which is owned by the NordVPN people. This apparently involved some pretty sketchy stuff like sending people to the house…

Reading the parent pdf vs Nord's response [0] I'm slightly more inclined to believe Nords version of events here... 0: https://nordvpn.com/blog/torguard-lawsuit/

The NordVPN blog post leaves me with many questions.

1) Someone supposedly "gave" them the URL. They do not state how they found it, or how it was related to TorGuard. So who gave it to them? The Collective 7 hosting company? It appears Collective 7 was selling "Residential Solutions for VPN Providers":

http://web.archive.org/web/20171215024207/http://collectives...

2) Did they ask TorGuard to censor Youtuber "Tom spark reviews"? It seems he is critical of them: https://www.youtube.com/channel/UCXJWKuGh0qedrYviGEJmlWw

Tom Spark was also doxxed by the ProtonMail Reddit rep for posting videos they did not like: https://old.reddit.com/r/ProtonVPN/comments/96m5vc/is_it_tru...

Found the link here: https://medium.com/@gaetanosabin/did-nordvpn-and-protonmail-...

So it doesn't surprise me that NordVPN (Proton) wants this Youtube Streamer's videos and blog taken down.

Shouldn't NordVPN and Proton uphold user privacy and fight against internet censorship? They are doing the exact opposite here and that is very troubling.

Re: NordVPN sued by Torguard for blackmail [pdf]

#49

Earlier quoted context omitted.

Reading the parent pdf vs Nord's response [0] I'm slightly more inclined to believe Nords version of events here... 0: https://nordvpn.com/blog/torguard-lawsuit/

I'm not sure, their response could be fabricated too. I'm interested in if Torguard has any evidence of them physically approaching their employee. > Within an hour of this in-person and unannounced visit, the same TorGuard contractor received unsolicited correspondence from an employee at NordVPN. This correspondence stated that NordVPN had received certain of TorGuard’s confidential and trade secret information and…

What if I told you that a lot of these "VPN providers" were shell companies built to explicitly facilitate access and tools for crime / espionage with the premise of having users there as cover.

Re: NordVPN sued by Torguard for blackmail [pdf]

#50

Earlier quoted context omitted.

Reading the parent pdf vs Nord's response [0] I'm slightly more inclined to believe Nords version of events here... 0: https://nordvpn.com/blog/torguard-lawsuit/

I'm not sure, their response could be fabricated too. I'm interested in if Torguard has any evidence of them physically approaching their employee. > Within an hour of this in-person and unannounced visit, the same TorGuard contractor received unsolicited correspondence from an employee at NordVPN. This correspondence stated that NordVPN had received certain of TorGuard’s confidential and trade secret information and…

On the DDoS...

I'm more inclined to say they don't know who it was, but pointing fingers, and Black Friday to maximize the potential damages reward.

The legal case also says "unknown individual"; so they could be a run-of-the-mill reporter or something.

A lot of what Torguard is saying in the case is pretty benign. An email from header can be faked, trade secrets, if left on the open web... aren't really secret anymore.

Nord isnt in a clean place either. Their response is making claims that the legal case doesnt even touch.

Post reply on HN