Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

111–120 of 666 posts

Re: NordVPN confirms it was hacked

#112

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

They mean IPMI. All servers have IPMI and there’s remote root exploits against many versions of them.

Re: NordVPN confirms it was hacked

#113

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

Except this isn't their fault because their infrastructure provider messed up and didn't even disclose this possible backdoor. If anyone the provider should be named and shamed, not NVPN.

Re: NordVPN confirms it was hacked

#114

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

If they're going with a bottom-dollar host, it's possible that the out-of-band server management tools were exposed. It's less likely to be a software backdoor, and more likely to be Supermicro IPMI or other baseboard management controller.

Re: NordVPN confirms it was hacked

#115

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Yes. Dedicated servers generally have IPMI / ILO / IDRAC / whatever. It's the only way to scale out management of hosts and provisioning.

Re: NordVPN confirms it was hacked

#116

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

After reading their blog post about it [ https://nordvpn.com/blog/official-response-datacenter-breach... ], I'm not as concerned.

A compromise is a compromise, don't get me wrong, but it can happen to absolutely anyone. If you're paying ~$5/month for anonymous browsing with unlimited bandwidth, then you're probably not getting top tier security researchers running your servers.

Re: NordVPN confirms it was hacked

#117

I don't understand the obsession with VPN providers. Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me, especially if that entity's business is getting people to funnel all their traffic through, making them a juicy target for governments or hackers.

>Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me,

You're already doing that with DNS servers. At least VPN providers make the claim that they'll protect you.

Re: NordVPN confirms it was hacked

#118

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Of course you have to worry about all of that! When you don't self host you have to assume whoever you are renting from hirers the lowest paid employees they can get to manage infrastructure for you. That's how they get profitable. You are not outsourcing expertise.

Re: NordVPN confirms it was hacked

#119

The best thing NordVPN can do right now is make a statement that clearly and honestly describes how its users are affected. No bullshit marketing language, no trying to hide facts, just a short and simple explanation of what this means for users and what they should do next.

Linked article says:

> “The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”

> According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server.

> NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

Post reply on HN