Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

311–320 of 666 posts

Re: NordVPN confirms it was hacked

#312
post #250

Earlier quoted context omitted.

> Because a VPN in this sense is just a glorified proxy. The VPN provider can see all your traffic, and do with it what they want - including logging. So can my ISP and they have been confirmed to sell customer data and work directly with NSA. https://en.wikipedia.org/wiki/Room_641A https://www.theguardian.com/business/2016/oct/25/att-secretl...

Pick a cloud provider you trust. I was thinking of moving from Digital Ocean (US) to Hetzner (German) and setting my own VPN up through a normal server.

If you're in the US, how exactly does moving from a US host to a German host make you more secure?

At least there are a few shreds of controls remaining on US agency surveillance of US persons using US networks.

But there are absolutely zero controls on monitoring networks beyond US borders, so it's open season for non-US hosts.

Re: NordVPN confirms it was hacked

#314

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Within 72 hours According to GDPR I thought? “ The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible.” https://ico.org.uk/for-organisations/guide-to-data-protectio...

Maybe NordVPN would argue personal data wasn't breached?

It's a bad look in any case.

Re: NordVPN confirms it was hacked

#315

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers. Even a lot of VM/cloud systems have some kind of virtual management console (Linode has their LISH system that lets you SSH in to console and Vultr/Digital Ocean ha…

> Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers.

Power on/off should be done via APIs that issue commands to a PDU, like Atlantic.net started doing in the early 200s.

And there's nearly zero reason to access "console" - configure your server to always but off PXE and fall through to disk if that intercept is not needed.

Re: NordVPN confirms it was hacked

#316
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

I want to read my own email.

Re: NordVPN confirms it was hacked

#317

Earlier quoted context omitted.

> Nord falsely blames its server provider. I don't see anything in the article about those claims being false. Where did you get that?

From the article: "“One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell." I believe that would be the section they're referencing.

How does this quote demonstrate that the service provider was not at fault?

Re: NordVPN confirms it was hacked

#318
I remember last week's episode on Darknet Diaries where NordVPN was offering 3y plans for a hefty discount. My first reaction was "Are they going out of business ?"

This week's news lets me make sense of that ad.

Re: NordVPN confirms it was hacked

#319
I'm frankly blown away that the comments I'm seeing here don't suggest to just roll your own.

$5/mo is the typical price nowadays for a 1 GB VPS with 1TB upload. Cancel at any time. Save image, redeploy monthly/weekly/daily to protect from longer term IP address tracking. Use scheme of your choice (e.g., SOCKS proxy, VPN, standard HTTP port for everything, etc.)

Re: NordVPN confirms it was hacked

#320
post #250

Earlier quoted context omitted.

Pick a cloud provider you trust. I was thinking of moving from Digital Ocean (US) to Hetzner (German) and setting my own VPN up through a normal server.

If you're in the US, how exactly does moving from a US host to a German host make you more secure? At least there are a few shreds of controls remaining on US agency surveillance of US persons using US networks. But there are absolutely zero controls on monitoring networks beyond US borders, so it's open season for non-US hosts.

>If you're in the US,

not just US location or even US services .. it's hard to be secure when we know that the US gov is reading and storing everythign they can.

In comparison -- the EU is not. The EU has the opposite approach and takes data privacy very seriously. This is backed up with effective legislation.

Post reply on HN