Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

331–340 of 666 posts

Re: NordVPN confirms it was hacked

#332

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

"no one could know" is ridiculous. A proper security team vets all of its vendors and ultimately writes security issues like this into contracts.

Re: NordVPN confirms it was hacked

#333

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

What is the source of the gist you linked?

Re: NordVPN confirms it was hacked

#334

Earlier quoted context omitted.

> You are on a known-hostile network Which is precisely the use case I use a VPN for. I'd rather trust an at least somewhat trustworthy VPN provider with my data than a random coffee shop and clients who happen to be on the same network at the time.

I feel like that's crazy. There should be no traffic entering or leaving your machine that's not end-to-end encrypted already. Trusting some fly-by-night VPN provider because they buy a lot of YouTube ads is no substitute for proper end-to-end session level encryption.

Simply seeing what servers you connect to can reveal a lot about you. Where you work, what social media accounts you have, what apps you have installed, what you are interested in reading etc. HTTPS doesnt help you with that.

Re: NordVPN confirms it was hacked

#335
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

> No one was ever going to be able to read your emails.

Except for Google, Yahoo, Microsoft, and Apple of course, and whoever they have to answer to depending on where you live.

Re: NordVPN confirms it was hacked

#337
post #243
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

They’re also not based in a Nordic country, which I find misleading.

> They’re also not based in a Nordic country, which I find misleading.

Ironically, Lithuania is a part of Northern Europe, but because of the data retention laws they have to pretend that they are based somewhere else[1].

[1] https://vpnscam.com/wp-content/uploads/2018/08/2018-08-24-09...

Re: NordVPN confirms it was hacked

#338
post #320

Earlier quoted context omitted.

If you're in the US, how exactly does moving from a US host to a German host make you more secure? At least there are a few shreds of controls remaining on US agency surveillance of US persons using US networks. But there are absolutely zero controls on monitoring networks beyond US borders, so it's open season for non-US hosts.

>If you're in the US, not just US location or even US services .. it's hard to be secure when we know that the US gov is reading and storing everythign they can. In comparison -- the EU is not. The EU has the opposite approach and takes data privacy very seriously. This is backed up with effective legislation.

Just because the host is in the EU doesn't prevent the US from monitoring it.

EU hosts are almost certainly monitored even more by US agencies than US hosts.

GDPR doesn't fix any of this.

"Europe furious, 'shocked' by report of U.S. spying"

https://www.cnn.com/2013/06/30/world/europe/eu-nsa/index.htm...

Re: NordVPN confirms it was hacked

#339
People have been talking about using VPN's because of "dangerous" public wifi, but I have to admit, I don't understand the risks.

Let's say you go to a coffee house and sign-in to their wifi with their password and use it browse https websites, like gmail or you favorite social media... what's the main risk? What can happen? What does happen?

Re: NordVPN confirms it was hacked

#340
post #136

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

It doesn't make much sense to me, even with iDRAC/some other console access you don't really have access to OS unless you reboot & go to single user mode etc at which point they should be noticing their servers rebooting etc. would love more info

Just set up your code as a boot-once config and wait for the owner to reboot their machine. Make your code end by booting the installed OS (or even by just rebooting again, most people will just curse about the damn slow server boot process).
Post reply on HN