Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

91–100 of 666 posts

Re: NordVPN confirms it was hacked

#91

I don't understand the obsession with VPN providers. Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me, especially if that entity's business is getting people to funnel all their traffic through, making them a juicy target for governments or hackers.

I use one when I have to connect to a public access point, or really any network that's not owned by someone I know and trust. It's not a perfect privacy/security plan -- you're right that I can't completely trust the VPN provider either -- it's just better than the alternative.

Re: NordVPN confirms it was hacked

#92
post #84

Earlier quoted context omitted.

Any major email provider at this point should have SSL enabled when you check your email.

Shame they're (still) spoofing certs. https://slate.com/technology/2015/01/gogo-creates-fake-ssl-t... https://www.zdnet.com/article/gogo-in-flight-wi-fi-serving-s... https://arstechnica.com/tech-policy/2014/04/at-feds-request-...

The browser (as should your email client) appears to have rejected those certs.

Re: NordVPN confirms it was hacked

#93
post #82

It's odd that NordVPN, VikingVPN and Torguard all got their private keys leaked here. - Did the hackers use an SSH or a VPN service vulnerability? - Or maybe even a previously unknown vulnerability? - Was SSH access firewalled? If not, why? - Do they still have root access?

>It's odd that NordVPN, VikingVPN and Torguard all got their private keys leaked here. Good reminder to set up FDE and not give your host logins for your servers. Unexpected reboots are rare enough that they're worth switching hosts over.

For dedicated servers this would work, especially for VPN where data-loss is "acceptable".

But if it where based on containers like LXC or OpenVZ, then the host can force root access via a command without even changing the root password of the container.

Re: NordVPN confirms it was hacked

#94
post #59

Earlier quoted context omitted.

Because it's easy to change a VPN provider if you don't like their actions, but most of us are stuck with an ISP and have no control over what they do with our data?

What exactly can they be doing with your data other than selling a list of which DNS queries you make and which IP addresses you connect to? (Which the VPN provider can also do.)

On the cellphone side, most carriers will sell your identity and real time location to websites that your visit. https://news.ycombinator.com/item?id=15477286

Re: NordVPN confirms it was hacked

#95

It's odd that NordVPN, VikingVPN and Torguard all got their private keys leaked here. - Did the hackers use an SSH or a VPN service vulnerability? - Or maybe even a previously unknown vulnerability? - Was SSH access firewalled? If not, why? - Do they still have root access?

or it's the same company ;)

Re: NordVPN confirms it was hacked

#96
post #84

Earlier quoted context omitted.

Shame they're (still) spoofing certs. https://slate.com/technology/2015/01/gogo-creates-fake-ssl-t... https://www.zdnet.com/article/gogo-in-flight-wi-fi-serving-s... https://arstechnica.com/tech-policy/2014/04/at-feds-request-...

The browser (as should your email client) appears to have rejected those certs.

ok, so they have been rejected. Now what? I still would like to read my email... which is where VPN's come in handy.

Re: NordVPN confirms it was hacked

#97
post #33

Earlier quoted context omitted.

Yeah it's diffidently not being recommended, it is being advertised. I wonder how many money they have spend. Every freaking channel mention them at some point.

You start to wonder where their money is coming from - their retail prices are already cheap, the discounts the influencers offer make it basically free. How's that sustainable?

No idea.

Yesterday I saw a discount with an extremely cheap 3-year plan (under 30$ and no data limit, iirc). The price didn't offer confidence that the service would be available for all three years.

Re: NordVPN confirms it was hacked

#99
post #60

Earlier quoted context omitted.

ProtonVPN has a large history of being connected to TesoNet, a company providing among other things data mining(!). An extra cherry on top of that is the CEO of TesoNet also being the CEO of CloudVPN, which more or less controls NordVPN. Now that doesn't mean ProtonVPN is automatically compromised but I feel with stuff like no-log VPNs one should always err on the side of caution.

This has been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence. ProtonVPN is 100% owned by the company behind ProtonMail, which in turn is funded by the European Union, so this has been verified by the European Commission. Details here: https://bit.ly/35RDKzB

I mean this[1] is pretty convincing and not directly from the accused company's blog. The only thing it gets wrong is framing ProtonVPN Lithuania as the main ProtonVPN company instead of as a subsidiary.

Regardless of that, there is so much mud being slung I recommend anyone to just search for 'protonvpn nordvpn tesonet', read a few articles on the topic and form your own opinion. Like I said, you can decide if you want to err on the side of caution or if it's a risk you're willing to take.

In case anyone wants VPN recommendations, I have good experiences with TorGuard and Private Internet Access and can also recommend Mullvad. Other people (that I trust) say iVPN and Tunnelbear are also solid.

[1] https://vpnscam.com/nordvpn-protonvpn-proton-mail-owned-by-t...

Re: NordVPN confirms it was hacked

#100
post #28

Earlier quoted context omitted.

This. I can set up and connect to a new OpenVPN instance under my own control in less than seven minutes (5:59 last I clocked) from my phone. Anyone can do this, it’s not nearly as complicated to launch and secure as some would have us believe. ( https://github.com/jenh/sevenminutevpn ) You do lose anonymity with personal VPN, but it all depends on your use case.

But the problem remain the same. Whoever manages the network that hosts your instance will see your traffic...

Yes, it's not a perfect solution. You're basically deciding who you trust the least and avoiding just them.
Post reply on HN