Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

71–80 of 666 posts

Re: NordVPN confirms it was hacked

#71

Earlier quoted context omitted.

I don't understand being unhappy with your ISP knowing these things, but being fine with your VPN provider knowing them.

I can use a VPN provider outside the jurisdiction of my own country.

If you're doing something illegal in your own country, that seems like a good idea. If you're not, that would seem to achieve nothing other than making it much more difficult to enforce any action against the VPN provider for selling your private data.

Re: NordVPN confirms it was hacked

#72
post #59

Earlier quoted context omitted.

Because it's easy to change a VPN provider if you don't like their actions, but most of us are stuck with an ISP and have no control over what they do with our data?

What exactly can they be doing with your data other than selling a list of which DNS queries you make and which IP addresses you connect to? (Which the VPN provider can also do.)

Where did location history come into this? (IP addresses are generally not correlated to location at much more than city level.)

My point is simply that using a VPN provider doesn't change the fact that an actor has access to your DNS queries and which IPs you connect to (and where you connect from). It just changes that actor from your ISP to a VPN provider, and most VPN providers seem a hell of a lot more shady than any ISP I've dealt with.

Re: NordVPN confirms it was hacked

#73

Earlier quoted context omitted.

Because for certain types of things, like pirating movies, it's good enough.

It seems a bit strange to me that you'd want to hide your movie pirating from your ISP but are happy for your VPN provider to know about it.

Who said anything about being happy about a VPN provider knowing anything?

It's about choosing between the lesser of two evils.

Re: NordVPN confirms it was hacked

#74
post #37

Earlier quoted context omitted.

I am surprised why isn’t anyone suggesting Cloudflare’s Warp VPN? Genuinely curious what is the difference. I guess Clodflare one is only for mobile?

Cloudflare's Warp is not an anonymising VPN as far as I know. It is just a way to speed up Internet speeds, especially in poorly connected areas. They make no effort to hide the origin IP. So it is not in the same class as other VPN providers.

This is interesting to read that Cloudfare is suggested here... shows that the term VPN is still thought of as private. (I know it is Virtual Private Network - but the termination is almost never private).

Re: NordVPN confirms it was hacked

#75
post #61

Earlier quoted context omitted.

It seems a bit strange to me that you'd want to hide your movie pirating from your ISP but are happy for your VPN provider to know about it.

Any (large?) ISP will report your torrenting and/or terminate your internet usage if you torrent anything they deem copyrightable. Both Comcast and Spectrum do this, at least. Edit, to add: No VPNs do this.

> No VPNs do this

I got a nastygram from the hosting provider I used.

Re: NordVPN confirms it was hacked

#76
post #60
post #32

Earlier quoted context omitted.

ProtonVPN comes from the same people who run ProtonMail, a very well known security focused email provider.

ProtonVPN has a large history of being connected to TesoNet, a company providing among other things data mining(!). An extra cherry on top of that is the CEO of TesoNet also being the CEO of CloudVPN, which more or less controls NordVPN. Now that doesn't mean ProtonVPN is automatically compromised but I feel with stuff like no-log VPNs one should always err on the side of caution.

This has been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence.

ProtonVPN is 100% owned by the company behind ProtonMail, which in turn is funded by the European Union, so this has been verified by the European Commission. Details here: https://bit.ly/35RDKzB

Re: NordVPN confirms it was hacked

#77
post #59

Earlier quoted context omitted.

Because it's easy to change a VPN provider if you don't like their actions, but most of us are stuck with an ISP and have no control over what they do with our data?

What exactly can they be doing with your data other than selling a list of which DNS queries you make and which IP addresses you connect to? (Which the VPN provider can also do.)

I'm currently sitting on a plane. gogo wifi can read all my email if they so chose (and pass to a government). I'll use a VPN.

Re: NordVPN confirms it was hacked

#78
post #55

Lots of talk here from highly technical folks but not one person brings up the fact that these are expired keys - as in not usable? I understand that the fact that these keys were obtained is concerning but the security of nord and etc prevailed at the end of the day. The question is: were they leaked before they expired or long after?

They were leaked on March 2018 [0][1], and they expired on October 2018 [2].

[0] https://web.archive.org/web/20180504001844/https://8ch.net/b...

[1] https://nordvpn.com/fr/blog/official-response-datacenter-bre...

[2] https://crt.sh/?id=10031443

Re: NordVPN confirms it was hacked

#79
post #77

Earlier quoted context omitted.

What exactly can they be doing with your data other than selling a list of which DNS queries you make and which IP addresses you connect to? (Which the VPN provider can also do.)

I'm currently sitting on a plane. gogo wifi can read all my email if they so chose (and pass to a government). I'll use a VPN.

Any major email provider at this point should have SSL enabled when you check your email.

Re: NordVPN confirms it was hacked

#80

Earlier quoted context omitted.

It is much easier to change VPN provider than your ISP.

What does that have to do with them knowing what websites you visit?

The implication is that if they're doing shady shit, you can easily switch, in contrast to ISPs.
Post reply on HN