Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

151–160 of 666 posts

Re: NordVPN confirms it was hacked

#151

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

Buy a $5/month VPS and run your own VPN on that (popular setup script: https://github.com/StreisandEffect/streisand ). It'll cost you a little bit of time in setup and maintenance (mostly just upgrading packages), but it has many benefits: - Cheaper than most VPN providers - You won't be using a known VPN IP - VPN providers are more likely to snoop on your traffic or be targeted by snoopers (such as the government),…

But then your security rests on your ability to manage a server. I mostly agree with you, but, I don't run one because I'm not a seasoned Ops. At least, not enough that I want to put my security on the line.

In all but the most hostile networks I trust another VPN or my ISP more than I trust my ability to keep a server secure.

Thoughts?

Re: NordVPN confirms it was hacked

#152
post #113

Earlier quoted context omitted.

Except this isn't their fault because their infrastructure provider messed up and didn't even disclose this possible backdoor. If anyone the provider should be named and shamed, not NVPN.

> NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” Not acceptable.

Yes it is?

Giving realtime public status updates makes your attacker privvy to your actions and how much you know. Fix first, publicly announce when safe to do so.

Same reason why SWAT etc. don't want media crews covering their actions in real time. It's broadcasting your view of the situation and intent to the opponent.

Re: NordVPN confirms it was hacked

#153
post #37
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

I am surprised why isn’t anyone suggesting Cloudflare’s Warp VPN? Genuinely curious what is the difference. I guess Clodflare one is only for mobile?

> I guess Clodflare one is only for mobile?

Yes, unfortunately it's currently not possible to use Warp VPN on PC. Otherwise, quite good service.

https://airvpn.org/ is also worth mentioning.

Re: NordVPN confirms it was hacked

#155
post #55

Lots of talk here from highly technical folks but not one person brings up the fact that these are expired keys - as in not usable? I understand that the fact that these keys were obtained is concerning but the security of nord and etc prevailed at the end of the day. The question is: were they leaked before they expired or long after?

Depending on the web server configuration they could be used to decrypt past traffic.

Re: NordVPN confirms it was hacked

#156
post #80

Earlier quoted context omitted.

What does that have to do with them knowing what websites you visit?

The implication is that if they're doing shady shit, you can easily switch, in contrast to ISPs.

On the other hand you will have lesser knowledge of what shady things your VPN provider does.

Re: NordVPN confirms it was hacked

#157

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Sounds like an iDRAC exploit (assuming Dell servers). But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.

Depends on what kind. In case of idrac, yes; but it's weird that it was insecure by default in the first place. Usually credentials are configured and provided to the customer. Makes me think there might have been some other interface. Clarification is definitely needed.

Re: NordVPN confirms it was hacked

#158
post #126

NordVPN just posted this a few minutes ago: https://nordvpn.com/blog/official-response-datacenter-breach...

They wrote: > We […] started creating a process to move all of our servers to RAM, which is to be completed next year. What does "RAM" mean here?

I guess that all decryption keys are on ram. If the power is disconnected, then it would need a manual intervention to re-decrypt the data

Re: NordVPN confirms it was hacked

#159

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Sounds like an iDRAC exploit (assuming Dell servers). But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.

How the hell do you pwn a server with iDRAC?

Re: NordVPN confirms it was hacked

#160

NordVPN is being recommended a lot to people who don't know better by influencers on social media, especially on YouTube. This kind of endorsement is recklessly negligent and needs to stop. https://drewdevault.com/2019/04/19/Your-VPN-is-a-serious-cho... Edit: note that I don't blame these influencers for their ignorance on the risks of using a VPN; rather I blame the shady VPN providers for overselling the security v…

Snake oil salesmen have been around for centuries. When you have an audience of hundreds of thousands or even millions of viewers it's your moral responsibility to not betray their trust by recommending them bullshit. Unless you personally evaluated the claims of the product (definitely not the case as most of these people don't understand how a VPN works beyond "it somehow protects your privacy") and are happy to st…

> none of these VPN providers' business models are sustainable

You can fit like a hundred of VPN users into a single cheap VPS server. With current prices for VPN they are anything but unsustainable.

Post reply on HN