Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

291–300 of 666 posts

Re: NordVPN confirms it was hacked

#291
post #230

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

> I find NordVPN's marketing reprehensible.

A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

Re: NordVPN confirms it was hacked

#293

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Sorry for posting under top comment, but I think it is very important.

Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa...

RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

Re: NordVPN confirms it was hacked

#294
post #56

Earlier quoted context omitted.

Apparently The Wirecutter now recommends TunnelBear and Mullvad because they post regular transparency reports and do third-party audits. https://thewirecutter.com/reviews/best-vpn-service/

I've been using Mullvad for a while now and I have nothing but praise for them. Only complaint is they're more expensive than some of their competitors.

What aspects of a VPN provider would you praise? Customer service, consistency of connection speed? Seems almost like a utility where it's hard to differentiate.

Re: NordVPN confirms it was hacked

#296

Earlier quoted context omitted.

I think that is pretty criminal already. Basically: 1- Nord falsely blames its server provider. 2- Nord hides it from their users. 3- Nord claims all will be well with an “audit” (again, since they were already “audited”) This is either criminal negligence, “security theater”, or both.

> Nord falsely blames its server provider. I don't see anything in the article about those claims being false. Where did you get that?

From the article: "“One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell."

I believe that would be the section they're referencing.

Re: NordVPN confirms it was hacked

#297

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

Also allowing historical sessions to be decrypted.

Re: NordVPN confirms it was hacked

#298

Earlier quoted context omitted.

HTTPs will not stop Google from logging your IP + activity on their services. I'm not convinced that ad-blockers are 100% effective in disabling trackers either. One of the appeals of VPNs is that you have multiple points of exit and they rotate.

Google can track you fairly effectively even if you’re behind a VPN. I’m not sure if they choose to at this time, but if a significant population switches to hiding behind VPNs, they will turn on the finer fingerprinting means.

>Google can track you fairly effectively even if you’re behind a VPN.

You don't know anything about my setup, so you have no basis for claiming this.

On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and look at basic HTTP logs.

Re: NordVPN confirms it was hacked

#299
post #269
post #250

Earlier quoted context omitted.

Pick a cloud provider you trust. I was thinking of moving from Digital Ocean (US) to Hetzner (German) and setting my own VPN up through a normal server.

I've pondered this before, but I don't see much advantage in having my traffic which currently comes from many IP addresses as I roam about the world, many of them shared and constantly changing, all come from one IP address that is absolutely only me. Plus browsing the web from a hosting provider is a worse web; you'll get more sites rejecting you or putting you through bad CAPTCHAs all the time because the same ser…

This worse web is literally Google bullying you unless you tell them everything about who you are.

Re: NordVPN confirms it was hacked

#300

If you're reading this and wondering which VPN service you should use to stay safe, start reading here: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w... (Spoiler: You're asking yourself the wrong question.)

Why does the linked suggestion say "Don't use an Android phone, use an iPhone instead."

Ask tptacek and idlewords?
Post reply on HN