Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

131–140 of 666 posts

Re: NordVPN confirms it was hacked

#131
post #109

Earlier quoted context omitted.

Im using PIA for 2 years now - pretty happy with the service.

Yeah been on PIA myself for 5 years. Amazing speeds and service. No issues at all and they have been in court twice where they showed they have no logs.

Its great - i use it on my work PC to reroute my personal traffic, on my families personal devices, when traveling abroad etc. That said, there is a no 100% guarantee so use it responsibly.

Re: NordVPN confirms it was hacked

#132

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

Buy a $5/month VPS and run your own VPN on that (popular setup script: https://github.com/StreisandEffect/streisand). It'll cost you a little bit of time in setup and maintenance (mostly just upgrading packages), but it has many benefits:

- Cheaper than most VPN providers

- You won't be using a known VPN IP

- VPN providers are more likely to snoop on your traffic or be targeted by snoopers (such as the government), specifically because they seek out traffic from people trying to hide

- You get to pick the port/protocol/software you use, rather than being forced to accept the provider's ones

- You can run other small servers you may need on the VPS as well

Re: NordVPN confirms it was hacked

#134
post #56
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

Apparently The Wirecutter now recommends TunnelBear and Mullvad because they post regular transparency reports and do third-party audits. https://thewirecutter.com/reviews/best-vpn-service/

I've been using Mullvad for a while now and I have nothing but praise for them. Only complaint is they're more expensive than some of their competitors.

Re: NordVPN confirms it was hacked

#135
post #125

The best thing NordVPN can do right now is make a statement that clearly and honestly describes how its users are affected. No bullshit marketing language, no trying to hide facts, just a short and simple explanation of what this means for users and what they should do next.

Truth is - if hackers did a MIM attack and collected a bunch user traffic (for how long?) they could have everything.. banking info, emails, logins... at this point if i was a user of that VPN service - i'd be replacing all of my sensitive passwords, secret questions/answers to key accounts.

While I agree with you - I do think it's slightly less bad than you make it out to be. For example, if I connected to my bank over this VPN I would only be as concerned as my HTTPS connection. So my VPN still doesn't know my bank login, assuming my TLS was sound, right?

This would hypothetically be as bad as logging into my bank on a public wifi.

Am I paranoid enough to not log into my bank on a public wifi? Yes. So I should be concerned here. But, it's at least not immediately insecure.

Re: NordVPN confirms it was hacked

#136

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

It doesn't make much sense to me, even with iDRAC/some other console access you don't really have access to OS unless you reboot & go to single user mode etc at which point they should be noticing their servers rebooting etc. would love more info

Re: NordVPN confirms it was hacked

#137
>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully contained.

I wonder when that sort of thing will become a criminal offence.

Re: NordVPN confirms it was hacked

#138

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Not sure if it is still the case but a while ago it was standard on OVH servers for them to put some public keys in their root-like's user authorized_keys. I think they used that to perform tasks requested from the web management system.

Re: NordVPN confirms it was hacked

#139

This is so well timed, I just bought a 3-year subscription to NordVPN and they have a 30 day refund policy.

You should probably ask for a refund, then set up your own VPN.

Commerical VPNs are, for the vast majority of cases, simply not a good bet for your privacy. You're changing your network traffic path from a diffuse and byzantine series of paths to once centralized collection point. The payoff for an attack on a VPN rises very quickly. Meanwhile, you're also conditioning yourself to say, "My traffic is secure while my VPN is on."

It's not a great combo.

Re: NordVPN confirms it was hacked

#140

I don't understand the obsession with VPN providers. Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me, especially if that entity's business is getting people to funnel all their traffic through, making them a juicy target for governments or hackers.

Sigh - just because one has a VPN, doesn't mean it has to be used all the time.

My NAS device, uses a VPN - my other machines do not.

My laptop, uses a VPN when I am travelling and using wifi from unknown sources (i.e. coffee shops, airports, etc.)

Post reply on HN