Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

201–210 of 666 posts

Re: NordVPN confirms it was hacked

#201
I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider".

Apparently the hacker was able to find out - so while it may be unknown, it's not an impossibility to detect it. Beyond whether or not sensitive information was accessed, what will NordVPN do in the future to eliminate or mitigate the possibility that this will occur again?

Re: NordVPN confirms it was hacked

#202

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

>> Is this common practice for data-center providers?

Absolutely. We had similar situation with one of the DC vendors.

Re: NordVPN confirms it was hacked

#203
post #113

Earlier quoted context omitted.

Except this isn't their fault because their infrastructure provider messed up and didn't even disclose this possible backdoor. If anyone the provider should be named and shamed, not NVPN.

> NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” Not acceptable.

What should they have done if they knew about a potential infrastructure weakpoint? How should they announce that to the public before fixing it?

Re: NordVPN confirms it was hacked

#204

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Within 72 hours According to GDPR I thought? “ The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible.” https://ico.org.uk/for-organisations/guide-to-data-protectio...

Re: NordVPN confirms it was hacked

#205

Earlier quoted context omitted.

Is the alternative actually worse than SSL? Why? And no, it doesn't break analytical by Facebook or Google in any substantial way. I know some people use them to evade Netflix region exceptions, and that's about all they're good for.

You can’t always ensure that all traffic goes over SSL. DNS traffic is an example. I always assume that hostile public networks like free WiFi have agents actively trying to man in the middle any connections they can. If your device has a known exploit and a single connection not going over SSL you drastically increase your exposure on a public WiFi, hence the one use case for VPN.

If your privacy concerns include your DNS requests then a commerical VPN isn't a realistic choice. And unlike some rando pseudo-bespoke brand-less coffee shop wifi, commerical VPNs are a big target.

> I always assume that hostile public networks like free WiFi have agents actively trying to man in the middle any connections they can.

And VPNs just move that problem. If you're not demanding and forcing SSL, you're not actually addressing this problem.

> If your device has a known exploit and a single connection not going over SSL you drastically increase your exposure on a public WiFi, hence the one use case for VPN.

I regret to inform you that none of these things you've described stop thise sort those attacks. Forcing SSL on your browser is a realistic option for most threat models. If you're at a level where you're actually being surveilled by a nation-state-level actor, a commercial VPN won't help you. Short of that scenario, forcing SSL will cover most cases.

Re: NordVPN confirms it was hacked

#206
post #61

Earlier quoted context omitted.

Any (large?) ISP will report your torrenting and/or terminate your internet usage if you torrent anything they deem copyrightable. Both Comcast and Spectrum do this, at least. Edit, to add: No VPNs do this.

They don't. What you're describing would take them out of common carrier status and make their business unworkable. What they do is respond to notices from copyright holders. https://arstechnica.com/tech-policy/2011/07/major-isps-agree...

My friend's VPN emailed him saying Comcast asked them for his info because he torrented something and the copyright holder contacted Comcast. The VPN provider didn't give Comcast any info.

Re: NordVPN confirms it was hacked

#207
post #94

Earlier quoted context omitted.

What exactly can they be doing with your data other than selling a list of which DNS queries you make and which IP addresses you connect to? (Which the VPN provider can also do.)

On the cellphone side, most carriers will sell your identity and real time location to websites that your visit. https://news.ycombinator.com/item?id=15477286

I'd like to see some evidence for "most carriers" and for "to websites that you visit".

Re: NordVPN confirms it was hacked

#208
post #61

Earlier quoted context omitted.

Any (large?) ISP will report your torrenting and/or terminate your internet usage if you torrent anything they deem copyrightable. Both Comcast and Spectrum do this, at least. Edit, to add: No VPNs do this.

They don't. What you're describing would take them out of common carrier status and make their business unworkable. What they do is respond to notices from copyright holders. https://arstechnica.com/tech-policy/2011/07/major-isps-agree...

Agreed - I was oversimplifying. A better way to put it would be to say that ISPs automatically participate in the reporting of alleged copyright infringement, as well as mete out punishment for alleged infringement when they decide it is appropriate, whereas (most?) VPNs do not.

Edit: spelling

Re: NordVPN confirms it was hacked

#209

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

> I wonder when that sort of thing will become a criminal offence.

If they have EU customers then article 33 of GDPR should see to that.

"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."

Unless the authorities in EU accept the explanation they are in trouble, but I think you shall report even if you think there has been a breach.

Re: NordVPN confirms it was hacked

#210

This is always topical: Don't use VPN Services https://gist.github.com/joepie91/5a9909939e6ce7d09e29

> Because a VPN in this sense is just a glorified proxy. The VPN provider can see all your traffic, and do with it what they want - including logging.

So can my ISP and they have been confirmed to sell customer data and work directly with NSA.

https://en.wikipedia.org/wiki/Room_641A

https://www.theguardian.com/business/2016/oct/25/att-secretl...

Post reply on HN