Earlier quoted context omitted.
Im using PIA for 2 years now - pretty happy with the service.
Yeah been on PIA myself for 5 years. Amazing speeds and service. No issues at all and they have been in court twice where they showed they have no logs.
NordVPN confirms it was hacked
131–140 of 666 posts
Re: NordVPN confirms it was hacked
#132This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable
- Cheaper than most VPN providers
- You won't be using a known VPN IP
- VPN providers are more likely to snoop on your traffic or be targeted by snoopers (such as the government), specifically because they seek out traffic from people trying to hide
- You get to pick the port/protocol/software you use, rather than being forced to accept the provider's ones
- You can run other small servers you may need on the VPS as well
Re: NordVPN confirms it was hacked
#133This is so well timed, I just bought a 3-year subscription to NordVPN and they have a 30 day refund policy.
Re: NordVPN confirms it was hacked
#134Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...
Apparently The Wirecutter now recommends TunnelBear and Mullvad because they post regular transparency reports and do third-party audits. https://thewirecutter.com/reviews/best-vpn-service/
Re: NordVPN confirms it was hacked
#135The best thing NordVPN can do right now is make a statement that clearly and honestly describes how its users are affected. No bullshit marketing language, no trying to hide facts, just a short and simple explanation of what this means for users and what they should do next.
Truth is - if hackers did a MIM attack and collected a bunch user traffic (for how long?) they could have everything.. banking info, emails, logins... at this point if i was a user of that VPN service - i'd be replacing all of my sensitive passwords, secret questions/answers to key accounts.
This would hypothetically be as bad as logging into my bank on a public wifi.
Am I paranoid enough to not log into my bank on a public wifi? Yes. So I should be concerned here. But, it's at least not immediately insecure.
Re: NordVPN confirms it was hacked
#136> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…
Re: NordVPN confirms it was hacked
#137So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully contained.
I wonder when that sort of thing will become a criminal offence.
Re: NordVPN confirms it was hacked
#138> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…
Re: NordVPN confirms it was hacked
#139This is so well timed, I just bought a 3-year subscription to NordVPN and they have a 30 day refund policy.
Commerical VPNs are, for the vast majority of cases, simply not a good bet for your privacy. You're changing your network traffic path from a diffuse and byzantine series of paths to once centralized collection point. The payoff for an attack on a VPN rises very quickly. Meanwhile, you're also conditioning yourself to say, "My traffic is secure while my VPN is on."
It's not a great combo.
Re: NordVPN confirms it was hacked
#140I don't understand the obsession with VPN providers. Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me, especially if that entity's business is getting people to funnel all their traffic through, making them a juicy target for governments or hackers.
My NAS device, uses a VPN - my other machines do not.
My laptop, uses a VPN when I am travelling and using wifi from unknown sources (i.e. coffee shops, airports, etc.)